Firefox 浏览器附加组件
  • 扩展
  • 主题
    • 适用于 Firefox
    • 字典和语言包
    • 其他浏览器网站
    • 适用于 Android 的附加组件
登录
tardisec 预览

tardisec 作者: tardisec.com

Browse your own site with its recommended security headers applied, one domain at a time. See what breaks before you enforce it.

可在 Android™ 版 Firefox 上使用可在 Android™ 版 Firefox 上使用
0(0 条评价)0(0 条评价)
下载 Firefox 并安装扩展
下载文件
扫码在 Android 版 Firefox 中打开此扩展

扩展元数据

关于此扩展
Apply stricter security headers to your own site as you browse it, and read the
violation reports the browser raises. One domain at a time, and only the domains
you switch on.

While a domain is switched on, the toolbar icon carries a badge: i (blue) while
it is only monitoring, ! (red) while it is enforcing a policy that can break the
page.
  • Report-Only (default) applies the report-only twins of the recommended
    headers. Additive monitoring, it cannot break the page.
  • Enforce strict applies the enforcing headers, so you can see exactly how the
    site would break under the real policy. What gets enforced depends on whether
    you are signed in.
  • Violations appear in the page's own DevTools console (opt-in per site) and in a
    log you can download as JSON.


Nothing to sign up for. A built-in strict baseline is applied in Report-Only, and
every violation it raises is logged in your browser.

Enforce strict applies your custom header overrides and nothing else. The built-in
baseline is a monitoring tool: enforcing it is a decision about your site.


Signed in at https://app.tardisec.com, it fetches that domain's recommended
security headers from your account and applies them in both modes. That set names
a reporting endpoint, so the browser delivers violation reports to your account as
well as to the in-browser log.


By default:
  • Does nothing until you switch monitoring on for a domain. Installing it changes
    no page, and there is no default-on list.
  • Does not log to the page console. You can turn that on per site.
  • A domain's settings are discarded once every tab for it is closed. Tick
    "Remember these settings for this domain" and they persist until you switch the
    site off. The report log is held in memory for the browser session, and the
    popup can clear it at any time.

Violation reports are produced by the browser's own Reporting API, not by this
extension. They go to whatever endpoint the headers being applied name: your
account's collector when signed in, and no endpoint at all on the built-in
baseline, where reports never leave the browser. No analytics, no telemetry.
评分 0(1 位用户)
登录以评价此扩展
目前尚无评分

已保存星级评分

5
0
4
0
3
0
2
0
1
0
尚无评价
权限与数据

必要权限:

  • 获取浏览器标签页
  • 访问您在 app.tardisec.com 的数据

可选权限:

  • 访问您在 app.tardisec.com 的数据

根据开发者所述,必要的数据收集:

  • 网站活动
  • 网站内容
详细了解
更多信息
附加组件链接
  • 用户支持网站
  • 支持邮箱
  • 复制附加组件 ID
版本
0.0.1
大小
70.92 KB
上次更新
9 天前 (2026年8月15日)
相关分类
  • 网页开发
  • 隐私和安全
许可证
保留所有权利
版本历史
  • 查看所有版本
添加到收藏集
举报此附加组件
转至 Mozilla 主页

附加组件

  • 关于
  • Firefox 附加组件博客
  • 扩展工坊
  • 开发者中心
  • 开发者政策
  • 社区博客
  • 论坛
  • 报告缺陷
  • 评价指南

下载

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

最新版本

  • Nightly
  • Beta

商用版 Firefox

  • Enterprise

社区

  • Connect
  • Contribute
  • Developer

关注

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • 隐私
  • Cookie
  • 法律

本站内容以知识共享署名-相同方式共享 v3.0 或任何更新版本授权(除非另有注明)。Android 系 Google LLC 的商标。