7 ms·
Cannot read clipboard from service worker in a MV3 chrome extension (2020)
- dotproto 4y agoHi, Simeon from the Chrome Extensions team here. Clipboard access is one of the browser capabilities that currently requires a document to use. We're planning to address this use case (and others that require DOM) by introducing a new capability called offscreen documents[1]. In short, an offscreen document is a temporary headless page that is instantiated for a given reason that requires DOM access. It is not meant as a long-lived background context. [1]: https://bugs.chromium.org/p/chromium/issues/detail?id=1339382 https://bugs.chromium.org/p/chromium/issues/detail?id=133938...
- encryptluks2 4y agoIf I'm reading this correctly, extension developers want a way to read the user clipboard with a separate permission dialog than having to also request the ability to inject scripts into pages? If that is the case I can partially see why this is the way it is. The clipboard reading permission is part of the privacy controls built into the browser. So with page injection, the extension would have to request permission for sites that it wants to read the clipboard from. Otherwise, a separate dialog would give unhindered access to read from the clipboard. Am I understanding that correctly?
- fosefx 4y agoI came across this because I wanted to port an addon over to MV3. It simply used navigator.clipboard.writeText(). That by itself only works as a reaction to a user interaction (so not in bg scripts), unless you declare the "writeClipboard" permission in the manifest. I don't know if there is a readClipboard permission as well.
- gnicholas 4y agoDoes any one have a sense of the likelihood that Google extends the original timeline for this changeover? How can you force everyone to update their software (in some cases overhaul) to a new system that isn't fully built yet? My company has two Chrome extensions, one of which is partly updated, and the other of which we haven't started yet. We have no idea what we'll discover when we begin the process of updating the second one, and we've been burned by Google's 'upgrades' in the past (Google Docs canvas-based rendering comes to mind). The worst-case scenario is that it is either impossible to migrate, or that it would cost so much that it would wipe out years of revenue. I've talked with others in the accessibility space, and they are concerned about how this forced migration will impact the market for 'niche' tools like accessibility extensions. They may simply cease to exist. Hopefully Brave or other Chromium browsers will continue to allow legacy extensions.
- userbinator 4y agoHow can you force everyone to update their software (in some cases overhaul) to a new system that isn't fully built yet? Big Tech has been behaving like this for a while now. It's clear that they only care about their own interests (partly $$$, partly ideological), not yours.
- desindol 4y agoIt's google the graveyard and 69 chat apps memes are real. If you have the chance don't build anything on google services. Remember AMP? There were like AMP agencies popping up when it was introduced lol
- SquareWheel 4y agoI'm not sure where this idea came from, but AMP hasn't been discontinued. It also hasn't strictly been a Google project for quite some time.
- desindol 4y agoNobody is asking for it anymore and most corps that implemented it are getting rid of it.
- wvenable 4y agoFirefox did it. It's extension market never fully recovered. I don't expect the same to happen to Chrome though -- different situation.
- hombre_fatal 4y ago> Thanks for the issue.... > Thanks..... Aside: Do people know that trailing "..." tends to communicate annoyance or sarcasm? I think the people writing it think it means something else, like some sort of intermission before the next thing they write, but I wouldn't include it in professional comms at all.
- mmmpop 4y agoMy otherwise high-EQ boss does this all the time and it drives me bonkers.
- worble 4y agoI definitely think it's a generational thing, my mum loves ending sentences with '...' and honestly O don't know why. Reading it makes it seems like annoyance but I know that it isn't, so I don't know if it was just something they were taught?
- withinboredom 4y agoNo, I don’t think people think that… because that isn’t what it means. People aren’t annoyed or sarcastic towards you… they are just pausing for a second.
- Jcowell 4y agoI feel as though a comma and the end communicates a pause better. Especially since it use in formal English is similar.
- withinboredom 4y agoAnother name for ellipses (…) is “suspension point” and doesn’t have any true grammatical purposes, unlike a comma. A comma doesn’t necessarily indicate a pause and makes no sense to insert randomly… wherever you’d like the reader to pause.
- 4y ago
- madeofpalk 4y agoI think Chrome's reasoning for this is completely fair: > navigator.clipboard is only intended to be used in a focused document, which is not possible for service workers. Therefore, I don't anticipate any intended support for navigator.clipboard.read on service workers I don't think a browser extension, which I personally consider it sit in between "native app" and "website" in terms of privilege hierarchy, should be able to arbitrarily read the operating system clipboard silently in the background.
- cobertos 4y agoRead farther > historically when I've tried using navigator.clipboard from the MV2 background page, it would pop up a separate permissions dialog (presumably the one that would appear for standard non-extension contexts that are requesting clipboard access), despite the extension having clipboard permissions.
- fosefx 4y agoMy use case: A background script, sorry, Service Worker registers a Context Menu Entry. When the user clicks on it it fetches some stuff an copies a link to clipboard. Using MV3 as it is this is not possible. As someone in the thread said, it is not really feasible to try to find all ways that user interaction can trigger code that requires clipboard access. If that is the route Google want to go down it will take years of people reporting new ways the system does not work until it is usable imo.
- madeofpalk 4y ago"User interaction to perform an action" im pretty sure is a part of the HTML/JS spec. For example, browsers on iOS will not let you play a video unless in response to a "user action".
- nightpool 4y agoI know there are a lot of valid complaints about Manifest v3, but I don't understand this one. You're telling me that browser extensions should be able to read and write to my clipboard silently at all times, with no user activation or notification? Honestly, that's kind of horrifying, and I'm shocked to hear it existed on v2 extensions. It sounds like a great way to build a keylogger for user passwords. What are some valid usecases for this permission? I guess "syncing clipboards between two operating systems" is one of them? But why build that as a browser extension? It seems like the wrong tool for the job.
- unknownaccount 4y ago>with no user activation or notification What? By choosing to install the extension you are activating it.
- wnevets 4y agoDo you also apply this logic to all other forms of hardware and software? For example TVs that spy on what you're watching.
- unknownaccount 4y agoWhen I install any piece of software I assume it could do anything and everything on the system.
- madeofpalk 4y agoI don't think most people operate under this assumption, or do not reckon with this.
- deleted 4y ago[deleted]
- xg15 4y agoWe all do. A native app you install on a phone or desktop can do all sorts of things.
- cobertos 4y agoThis bug hasn't received a comment from another @chromium.org in >1 yr. Feels like so many of Google's bugs related to functionality many users relied on
- aeharding 4y agoIt's extremely frustrating how some chrome extension apis such as chrome.tabCapture simply are no longer background context compatible, since they aren't in service workers. And they're just completely silent, don't even acknowledge the shortcomings. Just a hugely frustrating developer experience. Shame on Google, and this whole MV3 fiasco has permanently soured my view on Chrome developer Relations.
- deleted 4y ago[deleted]
- joecot 4y agoMy company had a chrome extension they used for making twilio phone calls. V3's service worker focus made that a complete nonstarter. Ended up writing a thing to make phone calls in a background tab, use the Broadcast channel Api to communicate between the background tab and the active tab, and wrote instructions on the background tab for allowing sound permissions explicitly. The plus side is that we likely won't be dependent on chrome anymore, but I expect I'm not at the only company who got a rude awakening from the v3 transition. And yes, you can use v2 extensions with chrome enterprise, which I have no interest in doing.
- zzo38computer 4y agoWhat I think is that what should be needing for browser extensions is to be able to write extensions in C, and available only for manual install by advanced users (so that it is not available to the official catalog of extensions). However, additional capabilities to interact with the browser are also needed, including to implement new and intercept existing: protocols, MIME types, character encodings, HTML commands, CSS commands, JavaScripts in web pages (and the API they have access to), ARIA, menus, user interface elements, etc. (I think things will need to be rewritten to make this work efficiently, including moving many features to extensions which are then included by default, instead of being core features.) Making C APIs for purposes would be helpful, although even if the existing API are with JavaScripts, JavaScript functions can be accessed by C codes by implementing N-API, I suppose.