Firefox 浏览器附加组件
  • 扩展
  • 主题
    • 适用于 Firefox
    • 字典和语言包
    • 其他浏览器网站
    • 适用于 Android 的附加组件
登录
Decloak Session Capture 预览

Decloak Session Capture 作者: Stephen Gray

Capture your logged-in session (cookies + storage) so Decloak can run an authenticated scan, including passkey/WebAuthn logins.

某些功能可能需要付费某些功能可能需要付费
0(0 条评价)0(0 条评价)
尚无用户尚无用户
下载 Firefox 并安装扩展
下载文件

扩展元数据

屏幕截图
关于此扩展
Decloak is an automated web security scanner. Paste any URL and get a free, instant report in about 15 seconds - no login required - covering HTTP/TLS posture, JavaScript vulnerabilities, third-party scripts and tag managers, and more.

Decloak's paid Enterprise tier goes further: an AI agent crawls your whole site, investigates what it finds, and produces audit-ready reports for teams tracking SOC2 or ISO 27001 compliance.

This extension is a companion for the Enterprise tier's authenticated scans - it does nothing on its own and requires a Decloak account already open to a "New scan" dialog.

Enterprise's authenticated scan mode crawls your site as a logged-in user, which means it needs your session. For most sites that's easy to script. For sites using passkeys or WebAuthn (Hanko, Face ID/Touch ID sign-in, security keys), there's no credential to script — the only way in is a session that already exists in your browser. This extension captures that session so Decloak can use it.

How it works
  1. Start a new Enterprise scan in your Decloak dashboard, choose "Authenticate as a logged-in user," and click "Get a capture code."
  2. Open the site you want scanned in a tab, log in normally, then click this extension's icon.
  3. Click "Capture session for Decloak" — it asks for permission on just that tab's site, nothing else.
  4. Paste the capture code from the dashboard and click "Send to Decloak."

What it captures

Cookies, localStorage, and sessionStorage for the one site you're currently on. Nothing else — no browsing history, no other tabs, no data from sites you haven't explicitly clicked "capture" on.

What it doesn't do
  • No install-time permissions. It asks for site access only when you click, only for that site.
  • No account or API key lives in the extension. The one-time capture code from your Decloak dashboard is the only credential involved, and it expires in 15 minutes whether you use it or not.
  • Nothing is stored by the extension itself. Closing the popup clears the capture. There's no storage permission in the manifest because there's nothing to persist.
  • The capture is single-use. Once Decloak's scan consumes it, the code is dead.

Why this needs the cookies permission

The entire purpose of this extension is capturing a session for your own authenticated security scan, scoped to the one site you click on. There's no other way to read cookies for a site from an extension. We don't request broad host permissions at install time - you grant access per-site, per-use, from the popup.

Full privacy policy: https://decloak.dev/privacy - see the "Browser extension (Session Capture)" section for exactly what's read, when it's transmitted, and how long anything is retained.
评分 0(1 位用户)
登录以评价此扩展
目前尚无评分

已保存星级评分

5
0
4
0
3
0
2
0
1
0
尚无评价
权限与数据

根据开发者所述,必要的数据收集:

  • 身份验证信息
详细了解
更多信息
附加组件链接
  • 主页
  • 用户支持网站
  • 支持邮箱
  • 复制附加组件 ID
版本
0.1.0
大小
21.07 KB
上次更新
1 个月前 (2026年7月14日)
相关分类
  • 网页开发
  • 隐私和安全
许可证
保留所有权利
隐私政策
阅读此附加组件的隐私政策
版本历史
  • 查看所有版本
标签
  • privacy
  • security
添加到收藏集
举报此附加组件
转至 Mozilla 主页

附加组件

  • 关于
  • Firefox 附加组件博客
  • 扩展工坊
  • 开发者中心
  • 开发者政策
  • 社区博客
  • 论坛
  • 报告缺陷
  • 评价指南

下载

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

最新版本

  • Nightly
  • Beta

Firefox for Business

  • Enterprise

社区

  • Connect
  • Contribute
  • Developer

关注

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • 隐私
  • Cookie
  • 法律

除非另有注明,否则本网站上的内容可按知识共享 署名-相同方式共享 3.0 或更新版本使用。