Files
KoalaSync/extension/README.md
T
MacBook f7829bbebb security: harden server relay + documentation audit
Server Security (S-1 through S-8):
- S-1: Type-check and clamp peerId, protocolVersion, password
- S-2: Validate numeric/boolean/enum fields in relay peerData
- S-3: Construct explicit relay payload (stop spreading raw data)
- S-4: Type-check targetId and actionTimestamp in EVENT_ACK
- S-5: Restrict room IDs to [a-zA-Z0-9-] only
- S-7: Add eventCounts periodic cleanup alongside connectionCounts
- S-8: Guard version parsing against NaN bypass

Documentation (P-1, R-1 through R-6):
- P-1: Fix PRIVACY.md typo, document all in-memory data maps
- R-1/R-5: Fix stale sync-constants.bat references in shared/
- R-2: Fix stale lastTargetState ref in ARCHITECTURE.md
- R-3: Extension README title reflects cross-browser support
- R-6: Document content injection markers in scripts/README.md
2026-05-04 05:19:18 +02:00

2.0 KiB

KoalaSync Browser Extension

A Manifest V3 Browser Extension (Chrome & Firefox) for synchronized video playback across any website.

Key Features

  • Manifest V3: Optimized Service Worker architecture with session persistence.
  • Pure Vanilla JS: No external dependencies or heavy libraries.
  • Smart Peer IDs: Hexadecimal IDs combined with customizable Usernames for easy identification.
  • Dual Heartbeat: Advanced session tracking (Background) and video synchronization (Content) to prevent ghost sessions.
  • Live Diagnostics: Built-in "Dev" tab for real-time video state debugging (ReadyState, CurrentTime, etc.).

Tab Overview

  1. Room: Manage connections, view active peers, and share invitation links.
  2. Sync: Control video playback (Play/Pause/Force Sync) and view recent activity.
  3. Settings: Customize your Username and toggle domain-based Noise Filtering.
  4. Dev: Monitor connection status and view real-time video element metadata for debugging.

Privacy & Permissions

KoalaSync requires <all_urls> permission to detect and interact with video elements (<video>) on websites.

  • No Browsing History: We do not track or store your browsing history.
  • State Management: Sensitive data (Room Passwords) is stored locally using chrome.storage.
  • Zero Telemetry: No analytics or external tracking scripts.
  • Zero Runtime Dependencies: The extension is built with pure Vanilla JS and contains no external libraries or tracking scripts, ensuring maximum performance and privacy.

Installation

  1. Prepare Extension: From the repository root, run:
    node scripts/build-extension.js
    
  2. Open Chrome and go to chrome://extensions/.
  3. Enable Developer mode (top right).
  4. Click Load unpacked and select the dist/chrome folder.

Development

If you modify shared/constants.js, you must synchronize the changes by running the build script from the root:

node scripts/build-extension.js

This ensures that the extension/shared folder is updated with the latest protocol constants.