Gelişmiş İzinleri Anlama
`activeTab`, `scripting` ve ana makine izinleri gibi hassas izinleri inceleyin; bunların ne zaman ve nasıl isteneceğini öğrenin.
Gelişmiş İzinleri Anlama, CoddyKit'te ücretsiz bir Browser Extensions Development (Chrome & Edge) dersidir. Bu, 4 dersinin 1. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Browser Extensions Development (Chrome & Edge) öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Browser Extensions Development (Chrome & Edge) kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Beyond Basic Permissions
Welcome! In this lesson, we'll dive into advanced browser extension permissions. These permissions grant powerful capabilities, allowing your extension to interact more deeply with web content and user data.
Understanding them is crucial for building robust extensions while maintaining user trust and security.
We'll cover:
- Host Permissions
activeTabPermissionscriptingPermission
Granting Web Access
Host permissions are fundamental. They define which websites your extension can interact with. This includes reading data, modifying content, or making network requests on those specific sites.
Think of them as "keys" that unlock access to certain web domains.
Manifesting Host Access
You declare host permissions in your manifest.json file under the host_permissions key. Each string is a URL pattern.
For instance, to allow access to all pages on google.com, you'd specify:
{
"name": "My Extension",
"version": "1.0",
"manifest_version": 3,
"host_permissions": [
"https://www.google.com/*"
]
}Broad Access with Wildcards
You can use wildcards (*) for broader access. For example, "<all_urls>" (or "*://*/*") grants access to all URLs, on all schemes (HTTP, HTTPS).
While powerful, using broad wildcards should be done with extreme caution, as it grants your extension significant control over the user's browsing experience on any site.
{
"name": "My Extension",
"version": "1.0",
"manifest_version": 3,
"host_permissions": [
"<all_urls>"
]
}Temporary Tab Privileges
The activeTab permission is a safer alternative to broad host permissions for one-off actions on the current page.
When the user invokes your extension (e.g., clicks its icon), activeTab grants your extension temporary host permissions to the currently active tab. These permissions last until the user navigates away or closes the tab.
{
"name": "My Extension",
"version": "1.0",
"manifest_version": 3,
"permissions": [
"activeTab"
]
}Getting Current Tab URL
With activeTab, your extension can access information about the current tab, like its URL or title, without needing permanent host permissions.
Try running this example. Imagine this code is in your extension's popup script:
// This script runs when the extension popup opens.
document.addEventListener('DOMContentLoaded', function() {
chrome.tabs.query({ active: true, currentWindow: true }, function(tabs) {
if (tabs.length > 0) {
const activeTab = tabs[0];
console.log('Active tab URL:', activeTab.url);
// Display in popup for demonstration
document.body.innerHTML = `<p>Current URL: ${activeTab.url}</p>`;
} else {
document.body.innerHTML = `<p>No active tab.</p>`;
}
});
});Programmatic Code Injection
The scripting permission allows your extension to programmatically inject JavaScript and CSS into web pages. This is how you modify a page's content or behavior.
It's an essential permission for content scripts, replacing the Manifest V2 tabs.executeScript API.
{
"name": "My Extension",
"version": "1.0",
"manifest_version": 3,
"permissions": [
"scripting"
],
"host_permissions": [
"https://www.example.com/*"
]
}Modifying a Page
Once you have scripting permission (and host permission for the target tab), you can inject code. This example injects a simple script to change the background color of the active tab.
Imagine this running in your background script or popup:
// This code would typically run from a background script
// or popup after a user action.
chrome.tabs.query({ active: true, currentWindow: true }, function(tabs) {
if (tabs.length > 0) {
const activeTabId = tabs[0].id;
chrome.scripting.executeScript({
target: { tabId: activeTabId },
function: () => {
// This function runs in the context of the web page
document.body.style.backgroundColor = 'lightblue';
console.log('CoddyKit: Page background changed!');
}
});
}
});Least Privilege Principle
Always follow the Principle of Least Privilege: request only the permissions your extension absolutely needs.
- Required Permissions: Declared in
manifest.jsonand requested at install. - Optional Permissions: Can be requested at runtime using
chrome.permissions.request()only when the user needs that specific feature. This gives users more control and builds trust.
Permission Scenarios
Which permission(s) would you need for an extension that, when its icon is clicked, reads the current page's title and then injects a custom CSS file into that same page?
Advanced Permissions Summary
Great job! You've learned about powerful advanced permissions:
- Host Permissions: Grant access to specific websites.
activeTab: Provides temporary host permissions to the active tab upon user invocation, ideal for one-off actions.scripting: Enables programmatic injection of JavaScript and CSS.
Always use the least privileged approach to ensure security and user trust. Next, we'll explore secure coding practices!
Sıkça Sorulan Sorular
“Gelişmiş İzinleri Anlama” dersi ücretsiz mi?
Evet — “Gelişmiş İzinleri Anlama” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Browser Extensions Development (Chrome & Edge) kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Browser Extensions Development (Chrome & Edge) kursu toplamda 4 dersten oluşur.
“Gelişmiş İzinleri Anlama” dersinde ne öğreneceğim?
`activeTab`, `scripting` ve ana makine izinleri gibi hassas izinleri inceleyin; bunların ne zaman ve nasıl isteneceğini öğrenin. Browser Extensions Development (Chrome & Edge) ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Browser Extensions Development (Chrome & Edge) öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Browser Extensions Development (Chrome & Edge), başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 1. dersidir.
“Gelişmiş İzinleri Anlama” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Browser Extensions Development (Chrome & Edge) dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Browser Extensions Development (Chrome & Edge) dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Gelişmiş İzinleri Anlama
- Güvenli Kodlama Uygulamaları
- İçerik Güvenliği Politikası (CSP)
- İsteğe Bağlı İzinler ve Çalışma Zamanı İstekleri