chore: repo hygiene — .gitattributes 與隱私聲明 - #1
Merged
Merged
Conversation
Measured before committing: `git add --renormalize .` is a zero diff and no tracked blob contains a CR, so this is insurance against a checkout on a machine without core.autocrlf, not a correction.
The README's permission table says what each permission is for; a user deciding whether to grant `cookies` and bilibili.com host access needs to know which cookie, which endpoints, and that nothing leaves the machine. Every claim points at the file that backs it, so the notice goes stale loudly rather than quietly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
套用
repo-hygieneskill 的分級清單,先量再加,本 PR 只做量出來成立的兩項。1.
.gitattributes(* text=auto)觸發條件:在 Windows 上開發 —— 成立。
先量的結果:
git add --renormalize .→ 零 diff(除了新增的.gitattributes本身)。所以這是純保險,不是修正:防的是未來在沒有
core.autocrlf=true的機器上 clone,而不是修現有檔案。沒有任何既有檔案被重新正規化。2.
PRIVACY.md觸發條件:manifest 的
permissions含cookies,且是裝在別人機器上的瀏覽器擴充 —— 成立。內容逐條對應程式碼,不寫程式碼沒說的話:
shared/api.js的chrome.cookies.get({ url: 'https://www.bilibili.com', name: 'DedeUserID' }),全庫唯一一處 cookie 讀取。shared/api.js的五個api.live.bilibili.com路徑,各自標明什麼時候會打。hdslb.com的頭像/封面(credentials: 'omit'+no-referrer),以及 hover 時嵌入的blackboard/live/live-activity-player.htmliframe。chrome.storage.local(全庫 0 處chrome.storage.sync),匯出是瀏覽器下載成本機檔案,且exportConfig只複製SETTINGS_KEYS白名單。sendBeacon/WebSocket/第三方 host;manifest 的host_permissions就只有*.bilibili.com與*.hdslb.com兩個。cookies權限 Chrome 不能單獨撤銷,所以照實說。README 的「Permissions」節與
README.zh-Hant.md的「權限」節各加一行連過去。驗證
npx eslint .通過;node --test "tests/**/*.mjs"21 pass / 0 fail。