Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 9 additions & 4 deletions docs/fr/security-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,7 +100,7 @@ La menace principale : une page malveillante conçoit un contenu qui, lorsqu'il
| **Exposition d'outils par niveau** | Les niveaux de fournisseur (`compact | mid | full`) limitent la surface d'agent navigateur normale pour les modèles plus petits. Compact obtient la surface d'action la plus petite ; Mid ajoute des outils de tâches courantes ; Full ajoute des solutions de repli UI/DOM avancées. Dev en Compact est bloqué. |
| **Plan avant Act** | Lorsqu'il est activé, les exécutions en mode action produisent d'abord un plan structuré et attendent l'approbation du panneau latéral avant que tout outil navigateur ne s'exécute. Les exécutions planifiées peuvent auto-approuver le plan uniquement via la politique du planificateur. |
| **Limite d'import de compétence** | Les compétences peuvent exposer des outils HTTP en lecture seule et des outils de téléchargement via un manifeste `webbrain-tools`. Importer ou garder la compétence activée est la décision de confiance pour le point de terminaison HTTPS déclaré ; les outils de compétence déclarés utilisent `credentials: "omit"` et doivent marquer les résultats tiers `resultPolicy: "untrusted"`. Les outils de compétence de téléchargement nécessitent toujours un mode action et la passerelle de permission Téléchargements normale avant d'enregistrer des fichiers. |
| **`/allow-api`** | Un indicateur `/allow-api` par conversation qui *supprime* la demande de permission pour les sorties réseau avec méthode d'écriture (`fetch_url`/`research_url` avec POST/PUT/PATCH/DELETE). Il ne supprime PAS la sortie GET ni aucune autre capacité. S'efface à la réinitialisation de la conversation. |
| **Dérogation de mutation API** | Un indicateur `/allow-api` par conversation, ou le réglage persistant désactivé par défaut sous Général → Avancé, *supprime* la demande de permission pour les sorties réseau avec méthode d'écriture (`fetch_url`/`research_url` avec POST/PUT/PATCH/DELETE). Aucun des deux ne supprime la sortie GET ni aucune autre capacité. La réinitialisation n'efface que la dérogation de la commande. |
| **Blocage `done()`** | Avant d'accepter la complétion, l'agent vérifie la présence de dialogues/formulaires ouverts. Si le résumé prétend "créé"/"sauvegardé" mais qu'une modale est encore ouverte, l'agent est forcé de continuer. |
| **Garde anti-soumission en double** | Les clics sur du texte de type soumission (créer/sauvegarder/soumettre/ajouter/poster/publier/envoyer/confirmer/s'inscrire/se connecter/payer/commander/checkout, etc.) sont bloqués pendant une fenêtre de 45 secondes par onglet+URL (Chrome). |
| **Test d'occlusion CLICK** | Avant de cliquer, le résolveur appelle `elementFromPoint()`. Si un autre élément est visuellement au-dessus, le clic est refusé. |
Expand All @@ -121,7 +121,11 @@ La menace principale : une page malveillante conçoit un contenu qui, lorsqu'il

## Indicateur `/allow-api`

Défini par conversation via la commande `/allow-api` dans le panneau latéral. Lorsqu'il est actif, il supprime la demande de permission pour **les sorties réseau avec méthode d'écriture uniquement** :
Défini par conversation via la commande `/allow-api` dans le panneau latéral,
ou de façon persistante avec **Toujours autoriser les mutations API** sous
**Paramètres → Général → Avancé**. Le réglage persistant est désactivé par
défaut. Lorsque l'une des options est active, elle supprime la demande de
permission pour **les sorties réseau avec méthode d'écriture uniquement** :

- `fetch_url` / `research_url` avec `method: POST/PUT/PATCH/DELETE`

Expand All @@ -137,10 +141,11 @@ Le prompt système ajoute un préambule indiquant au modèle de :
Les indices de raccourcis API de détection de boucle ne contournent pas cette politique. Ils peuvent exposer
la méthode et l'URL exactes que la page appelait déjà, y compris POST/PATCH/etc.,
mais les appels `fetch_url` / `research_url` avec méthode d'écriture nécessitent toujours
l'état `/allow-api` de la conversation. Les requêtes GET et les capacités non réseau
l'état `/allow-api` de la conversation ou le réglage persistant. Les requêtes GET et les capacités non réseau
passent toujours par la passerelle normale capacité × origine.

Effacé à la réinitialisation de la conversation.
La réinitialisation de la conversation efface la dérogation de la commande, mais
ne modifie pas le réglage persistant, qui reste actif jusqu'à sa désactivation.

---

Expand Down
11 changes: 9 additions & 2 deletions docs/fr/slash-commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,8 +84,15 @@ leur navigateur est dédié à la tâche.
## `/allow-api`

`/allow-api` lève la restriction UI-d'abord pour la conversation en cours, afin
que l'agent puisse utiliser POST/PUT/PATCH/DELETE via `fetch_url` lorsque l'UI
échoue. Un badge apparaît pendant l'activation, et il s'efface au `/reset`.
que l'agent puisse utiliser POST/PUT/PATCH/DELETE via `fetch_url` ou
`research_url` lorsque l'UI échoue. Un badge apparaît pendant l'activation, et
il s'efface au `/reset`.

Pour conserver la même politique entre les conversations et les redémarrages
du navigateur, activez **Toujours autoriser les mutations API** sous
**Paramètres → Général → Avancé**. Ce réglage est désactivé par défaut et reste
actif jusqu'à sa désactivation. `/reset` efface toujours la dérogation
`/allow-api` de la conversation, mais ne modifie pas ce réglage persistant.

La règle UI-d'abord par défaut existe parce que les actions API sont invisibles
(vous ne voyez pas ce qui est envoyé), nécessitent souvent des jetons
Expand Down
16 changes: 10 additions & 6 deletions docs/security-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ The primary threat: a malicious page crafts content that, when read by the agent
| **Plan before Act** | When enabled, action-mode runs first produce a structured plan and wait for side-panel approval before any browser tool executes. In Try mode, planner JSON that remains invalid after repair degrades that turn to Ask/read-only; Strict stops. Scheduled runs can auto-approve the plan only through scheduler policy. |
| **Skill import boundary** | Skills can expose read-only HTTP tools and download-job tools through a `webbrain-tools` manifest. Importing or keeping the skill enabled is the trust decision for the declared HTTPS endpoint; declared skill tools use `credentials: "omit"` and should mark third-party results `resultPolicy: "untrusted"`. Download-job skill tools still require an action mode and the normal Downloads permission gate before saving files. |
| **WebMCP boundary** | Experimental WebMCP is off by default, so its tools and prompt guidance do not enter ordinary model requests unless the user opts in under Settings → General → Advanced. When enabled, Chrome page-registered names, descriptions, schemas, frame URLs, annotations, outputs, and errors are page-controlled and always use the untrusted-content wrapper. Calls use opaque IDs. Ask may list tools but cannot invoke them. Because a callback can run arbitrary page logic, every invocation requires Act/Dev, fresh per-call confirmation, and a permission grant for the actual registration-frame origin; a page-authored `readOnly` hint never bypasses those gates. Missing/opaque frame identity fails closed, and the frame plus effective HTTP(S) security origin are revalidated immediately before dispatch to prevent navigation races from borrowing an old grant. |
| **`/allow-api`** | A per-conversation `/allow-api` flag that *waives* the permission prompt for write-method network egress (`fetch_url`/`research_url` with POST/PUT/PATCH/DELETE). It does NOT waive GET egress or any other capability. Clears on conversation reset. |
| **API mutation override** | A per-conversation `/allow-api` flag, or the default-off persistent setting under General → Advanced, *waives* the permission prompt for write-method network egress (`fetch_url`/`research_url` with POST/PUT/PATCH/DELETE). Neither option waives GET egress or any other capability. Conversation reset clears only the slash-command override. |
| **`done()` blocking** | Before accepting completion, the agent probes for open dialogs/forms. If the summary claims "created"/"saved" but a modal is still open, the agent is forced to continue. |
| **Duplicate-submit guard** | Clicks on submit-like text (create/save/submit/add/post/publish/send/confirm/sign up/log in/pay/checkout/order, etc.) are blocked within a 45-second window per tab+URL (Chrome). |
| **CLICK occlusion test** | Before clicking, the resolver calls `elementFromPoint()`. If another element is visually on top, the click is refused. |
Expand All @@ -132,7 +132,10 @@ The primary threat: a malicious page crafts content that, when read by the agent

## `/allow-api` Flag

Set per-conversation via the `/allow-api` slash command in the side panel. When active, it waives the permission prompt for **write-method network egress only**:
Set per-conversation via the `/allow-api` slash command in the side panel, or
persistently with **Always allow API mutations** under **Settings → General →
Advanced**. The persistent setting is off by default. When either option is
active, it waives the permission prompt for **write-method network egress only**:

- `fetch_url` / `research_url` with `method: POST/PUT/PATCH/DELETE`

Expand All @@ -147,11 +150,12 @@ The system prompt adds a preamble telling the model to:

Loop-detection API shortcut hints do not bypass this policy. They can expose
the exact method and URL the page was already calling, including POST/PATCH/etc.,
but write-method `fetch_url` / `research_url` calls still require the
conversation's `/allow-api` state. GET requests and non-network capabilities
still go through the normal capability × origin gate.
but write-method `fetch_url` / `research_url` calls still require either the
conversation's `/allow-api` state or the persistent setting. GET requests and
non-network capabilities still go through the normal capability × origin gate.

Cleared on conversation reset.
Conversation reset clears the slash-command override. It does not change the
persistent setting, which remains active until the user turns it off.

---

Expand Down
10 changes: 8 additions & 2 deletions docs/slash-commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,8 +81,14 @@ browser is dedicated to the task.
## `/allow-api`

`/allow-api` lifts the UI-first restriction for the current conversation so the
agent may use POST/PUT/PATCH/DELETE via `fetch_url` when the UI is failing. A
badge appears while it is active, and it clears on `/reset`.
agent may use POST/PUT/PATCH/DELETE via `fetch_url` or `research_url` when the UI
is failing. A badge appears while it is active, and it clears on `/reset`.

To keep the same policy active across conversations and browser restarts, turn
on **Always allow API mutations** under **Settings → General → Advanced**. The
setting is off by default and remains active until you turn it off. `/reset`
still clears the conversation-only `/allow-api` override, but does not change
the persistent setting.

The default UI-first rule exists because API actions are invisible (you don't
see what's being sent), often require separate auth tokens you may not have
Expand Down
10 changes: 6 additions & 4 deletions docs/zh-CN/security-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@
| **分层工具暴露** | 提供商层级(`compact | mid | full`)限制较小模型的普通浏览器智能体操作面。Compact 获得最小的操作面;Mid 添加常见任务工具;Full 添加高级 UI/DOM 回退。Compact Dev 被阻止。 |
| **行动前规划** | 启用时,行动模式的运行首先生成结构化计划,并等待侧面板批准后才执行任何浏览器工具。定时运行仅通过调度器策略可自动批准计划。 |
| **技能导入边界** | 技能可通过 `webbrain-tools` 清单暴露只读 HTTP 工具和下载任务工具。导入或保持技能启用是对声明的 HTTPS 端点的信任决策;声明的技能工具使用 `credentials: "omit"` 并应将第三方结果标记为 `resultPolicy: "untrusted"`。下载任务技能工具在保存文件前仍需行动模式和正常的下载权限门。 |
| **`/allow-api`** | 每个对话的 `/allow-api` 标记,*免除*写方法网络出口(`fetch_url`/`research_url` 的 POST/PUT/PATCH/DELETE)的权限提示。不免除 GET 出口或任何其他能力。对话重置时清除。 |
| **API 变更覆盖** | 每个对话的 `/allow-api` 标记,或“常规 → 高级”中默认关闭的持久设置,都会*免除*写方法网络出口(`fetch_url`/`research_url` 的 POST/PUT/PATCH/DELETE)的权限提示。两者都不免除 GET 出口或任何其他能力。对话重置仅清除斜杠命令覆盖。 |
| **`done()` 阻塞** | 在接受完成前,智能体探测是否有打开的对话框/表单。如果摘要声称"已创建"/"已保存"但模态框仍打开,则强制智能体继续。 |
| **重复提交防护** | 在 45 秒窗口内,每个标签页+URL 阻止对类似提交文本(create/save/submit/add/post/publish/send/confirm/sign up/log in/pay/checkout/order 等)的点击(Chrome)。 |
| **CLICK 遮挡测试** | 在点击前,解析器调用 `elementFromPoint()`。如果另一个元素视觉上位于上方,则拒绝点击。 |
Expand All @@ -117,7 +117,9 @@

## `/allow-api` 标记

通过侧面板中的 `/allow-api` 斜杠命令为每个对话设置。激活时,它仅免除**写方法网络出口**的权限提示:
可通过侧面板中的 `/allow-api` 斜杠命令为每个对话设置,也可在**设置 → 常规 → 高级**中
开启**始终允许 API 变更**使其持久生效。持久设置默认关闭。任一选项激活时,都仅免除
**写方法网络出口**的权限提示:

- `fetch_url` / `research_url` 使用 `method: POST/PUT/PATCH/DELETE`

Expand All @@ -127,9 +129,9 @@
- 在任何破坏性 API 调用前以纯文本说明 URL、方法和载荷
- 默认优先使用 UI,仅在 UI 确实失败时才使用 API

循环检测 API 快捷提示不会绕过此策略。它们可以暴露页面已在调用的确切方法和 URL,包括 POST/PATCH 等,但写方法的 `fetch_url` / `research_url` 调用仍需要对话的 `/allow-api` 状态。GET 请求和非网络能力仍通过正常的能力 × 来源门。
循环检测 API 快捷提示不会绕过此策略。它们可以暴露页面已在调用的确切方法和 URL,包括 POST/PATCH 等,但写方法的 `fetch_url` / `research_url` 调用仍需要对话的 `/allow-api` 状态或持久设置。GET 请求和非网络能力仍通过正常的能力 × 来源门。

对话重置时清除。
对话重置会清除斜杠命令覆盖,但不会更改持久设置;后者会一直生效到用户手动关闭。

---

Expand Down
6 changes: 5 additions & 1 deletion docs/zh-CN/slash-commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,11 @@ CDP 截图,并仅在该次运行期间模拟焦点;Firefox 使用 `tabs.capt
## `/allow-api`

`/allow-api` 会为当前对话解除 UI 优先限制,使智能体在 UI 失败时可通过 `fetch_url`
使用 POST/PUT/PATCH/DELETE。激活期间会显示徽章,并在 `/reset` 时清除。
或 `research_url` 使用 POST/PUT/PATCH/DELETE。激活期间会显示徽章,并在 `/reset` 时清除。

若要让相同策略在不同对话和浏览器重启后继续生效,请在**设置 → 常规 → 高级**中开启
**始终允许 API 变更**。该设置默认关闭,并会一直生效到你手动关闭。`/reset` 仍会清除
当前对话的 `/allow-api` 覆盖,但不会更改此持久设置。

默认的 UI 优先规则之所以存在,是因为 API 操作是不可见的(你看不到发送了什么内容),
通常需要你可能尚未配置的独立认证令牌,并且其影响范围可能比一次可见的误点击大得多。
Expand Down
Loading
Loading