Documentation & Manual

Detailed technical reference, security models, Plasmo build targets, and client-side cryptography.

Core Security Architecture

Zero-Server Security & Local Storage Model

LoginLens operates on a strict zero-server paradigm. All data operations, identity inferences, and cryptographic routines take place entirely inside your browser's local sandbox.

System Architecture Flow Diagram

Detailed Element Breakdown & Component Specifications

1. 🌐 Web Page / User Login

The active web page where credentials or OAuth redirect callbacks are submitted. LoginLens monitors password form fields and OAuth response headers without capturing plaintext data over network channels.

2. 🛡️ Content Script (injector.tsx)

Executes at document_start inside Chrome's isolated JS execution context. Injects main-world detection markers and monitors identity inputs.

3. ⚡ Background Service Worker

The central background process in Manifest V3. Monitors web request headers for OAuth redirect callbacks (e.g., Google/GitHub) and manages intra-extension IPC.

4. 💾 chrome.storage.local Sandbox

Chrome's sandboxed local disk storage. Stores saved_accounts, oauth_registry, and mfa_registry.