Reveal URLs sürüm geçmişi - 14 sürüm
Reveal URLs geliştiren: Magentron
Eski sürümlere dikkat edin! Bu sürümler yalnızca test veya referans amacıyla sunulmaktadır.Her zaman eklentilerin son sürümlerini kullanmalısınız.
Son sürüm
Sürüm 0.1.27
25 Tem 2026 tarihinde çıktı - 230 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.27 — 2026-07-24
Changed
- The options page now places its help links below the master Enable switch. Browser
targets also offer an accessible "Suggest mail website" link for unsupported
mail services; Thunderbird omits that browser-only link at build and runtime.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Eski sürümler
Sürüm 0.1.26
24 Tem 2026 tarihinde çıktı - 227,86 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.26 — 2026-07-24
Changed- The options page "Active sites" dropdown now lists its sites alphabetically by their visible label, so the list is easier to scan. The ordering is presentation-only: the default selection and the stored rule order are unchanged.
- The built-in Outlook Live and Outlook 365 rules now target the message body via [role="document"] instead of the previous [aria-label="Message body"] selector. Existing installs still carrying the old default selector have their effective configuration migrated to the new one immediately when it is next read (persisted on the following normal save/write); a deliberately customised Outlook selector is preserved.
Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.25
23 Tem 2026 tarihinde çıktı - 227,52 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.25 — 2026-07-23
Added
- The browser extension's inline annotation now reveals links that use schemes other than http/https — mailto: (email), tel:/sms: (phone) and opaque schemes such as javascript:, data:, blob: and file: — and flags them when the visible text names a different destination than the link actually points to. A mailto: is checked against every recipient it sends to (including hidden cc/bcc query recipients, RFC 6068-decoded), a tel:/ sms: against its dialled number(s) (RFC 3966 parameters/phone-context handled, extensions ignored, and the +/00 international-prefix notations of the same number treated as equal; a trunk-local number is not equated with an arbitrary country code, so a possible cross-country difference is warned rather than masked), and a script/data-capable scheme (javascript:, data:, vbscript:) is always flagged. The mismatch is computed from the full href, so a truncated reveal never hides a warning. The native Outlook and Gmail add-on findings panels remain http/https only for now.
Changed
- The mismatch warning badge label is now the more general "⚠ Destination mismatch" (previously "⚠ URL mismatch"), since a mismatch can now be an email, phone or opaque-scheme destination as well as a URL.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.23
21 Tem 2026 tarihinde çıktı - 225,77 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.23 — 2026-07-21
Added
- The browser toolbar icon now shows a per-tab badge while the extension is enabled:
the number of mismatching (look-alike) links on the current page in red, or (when
the page has links but none mismatch) the total number of analysed links in grey.
A page with no analysable links shows no count, and the globalOFFbadge still
covers every tab while the extension is disabled. Counts sum across a tab's frames
(so a body-in-iframe page such as Proton Mail is included), reflect the shared core
analysis (independent of the reveal/highlight display settings), survive a
service-worker restart viastorage.session, and clear on navigation or tab close.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.22
15 Tem 2026 tarihinde çıktı - 220,02 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.22 — 2026-07-15
Fixed
- Shared locale resolution now maps the Norwegian Bokmal aliasesnband
nb-NOonto the shippednocatalogue before base-language fallback, so the
browser options UI and the Outlook task pane select the correct runtime
catalogue.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.21
14 Tem 2026 tarihinde çıktı - 211,08 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.21 — 2026-07-14
- The shared runtime catalogues (
_locales/<code>/messages.json) that localise
the WebExtension options UI, the Gmail add-on and the Outlook add-in are now
corrected in the five affected locales:caandeuno longer carry Spanish
option/settings copy,glno longer carries Portuguese,sris normalised to
Serbian Latin script, andbsno longer carries the repaired Croatian option
and settings strings. The shared_localesparity checks now catch those
known neighbour-language copy regressions and enforce Latin script for Serbian
runtime messages. Translations remain machine-generated and pending human
review. - The website chrome dictionaries (
site/i18n/<code>.json) whose values were
machine-translated into the wrong language are now in their own language:ca
andeucarried Castilian Spanish,glcarried European Portuguese, andsr
andbscarried Croatian.sris rewritten in Serbian (Latin, ekavian),
transliterating its previously-Cyrillic phishing captions and dropping Croatian
ijekavian/vocabulary per the documented Srpski/Latin standard;bsis rewritten
in idiomatic Bosnian. The browser pills that had been localised (Chrome→"Krom",
Edge→"Rub") inbs,hrandsr, and a sharedEkrađucorruption in their
landingWhyBodylink text, are corrected. Separately, the outdated short
landingIntro2/landingPrivacyNotecopy — which predated the Outlook add-in and
Gmail add-on and wrongly implied "no server, everything on your device" — is
refreshed from the current English base across all affected locales (ca, da, de,
es, eu, fr, gl, it, nl, no, pl, sv). Translations remain machine-quality and
pending human review.
Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
- The shared runtime catalogues (
Sürüm 0.1.20
13 Tem 2026 tarihinde çıktı - 211,42 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.20 — 2026-07-12
Changed
- The built-in Yahoo Mail rule now covershttps://*.mail.yahoo.com/*instead of
the single hosthttps://mail.yahoo.com/*, so the extension annotates Yahoo on
the bare host and on its sub-domains (e.g.e1.mail.yahoo.com). The static
browser manifests grant the wildcard host, and the built-in's message-body
selector is updated to.msg-bodyto match Yahoo's current markup.
- A stored copy of a superseded built-in rule is now migrated onto its
replacement during config normalisation (a reusable migration ledger). On
upgrade the old exact-host Yahoo rule is rewritten to the new wildcard built-in,
preserving the user's enabled toggle and name while resetting the dead selector,
so it can neither shadow the replacement nor appear as a duplicate.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.19
9 Tem 2026 tarihinde çıktı - 210,52 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.19 — 2026-07-09
Added
- The browser content controller now annotates message bodies rendered inside an
open shadow root. Tuta's built-inbody #mail-bodyrule now upgrades to the
host's openshadowRoot, injects the shared stylesheet there once, observes
shadow-internal mutations, and prunes disconnected shadow observers during
long-lived SPA churn.
- The built-in browser provider set now also ships FastMail, Tuta, Yahoo and
Zoho alongside Gmail, Outlook Live, Outlook 365 and Proton. The static
manifests now grant all sixteen built-in origins, the options/config layers
now expose the Tuta selector, and the browser/manual/store docs now describe
the full shipped provider set consistently.
- Built-in host coverage now also includes Tuta's current app host
https://app.tuta.com/*alongsidehttps://mail.tutanota.com/*, plus Zoho's
standard multi-DC mail hostshttps://mail.zoho.com/*,
https://mail.zoho.com.au/*,https://mail.zoho.com.cn/*,
https://mail.zoho.eu/*,https://mail.zoho.in/*,
https://mail.zoho.jp/*,https://mail.zoho.sa/*and
https://mail.zohocloud.ca/*.
- The README, manuals and rendered manual pages now add a privacy note under the
mismatch and Gmail screenshots explaining that email addresses, URLs and names
in those screenshots are masked with asterisks. The rendered manual pages now
reuse the shared.figure-disclaimerpresentation for those notes, and the
website catalogue gains the translatedscreenshotMaskDisclaimerkey across
every locale.
Changed
- The options page now keeps its "Active sites" editor compact by showing one
"Active site" dropdown plus one selected-site editor instead of a long stacked
list. Built-in rules now carry curated names, user-added rules can carry an
optional name, the dropdown falls back to the match URL when unnamed, and
shared names such as Tuta and Zoho are disambiguated with(host). Site
names can be edited in the selected-site editor (clearing a built-in name
restores its curated default), while the match pattern stays read-only as the
rule's identity.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.18
8 Tem 2026 tarihinde çıktı - 206,85 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.18 — 2026-07-08
Added
- Bunny deploy loads the three non-secret settings from a repo-root .env (process-env precedence); access keys stay in the environment, unknown/secret keys in .env are rejected, and python3 is required.
- Dry-run mode (--dry-run, DRY_RUN, make site-deploy-bunny-dry-run) previews uploads/deletes/purge without mutating.
- Documented the pull-zone edge rules (www redirect, /privacy→/privacy.html, .mjs content-type) with manual HTTP checks.
- Branded custom error pages: 404.html (site chrome) and a standalone 50x.html (inline CSS/SVG, literal Bunny {{…}} variables).
- Root favicon.ico generated and linked beside favicon.svg/favicon-128.png.
Changed
- Bunny deploy is now incremental: uploads only changed files, strips the storage-zone-name prefix from listing paths, prunes stale files/dirs, purges last; safe re-upload when checksum metadata is missing.
- Site-wide sticky footer; 404.html keeps the full nav minus the language selector; 50x.html uses a hero layout, Source-only header, shared footer, data-URI favicon and a progressive-enhancement "Try again" link.
- Inline reveal now gets a leading line break after inline content (e.g. Gmail's wrapped <span>s).
0.1.17 — 2026-07-07
Added
- Host-run make site-deploy-bunny flow (POSIX sh, shellcheck-clean, fail-fast) uploads site/public/ to Bunny and purges the pull zone.
Changed
- Canonical homepage moved to https://www.reveal-urls.eu/ (from Codeberg Pages) across package.json, the site generator, Outlook manifests, options page, localised chrome and docs.
- Options-page online-manual path is now root-hosted (e.g. /nl/handleiding.html).
0.1.16 — 2026-07-07
Added
- Translated per-screenshot store captions (Edge, AMO, ATN).
- Thunderbird toolbar toggle icon with an "OFF" badge, matching the browsers.
- Inline mode mirrors the destination URL into the anchor title (hover) on mismatch/hidden-honest links.
Changed
- Manual documents the Thunderbird toggle in every locale.
- Inline reveal now sits on its own line (leading break mid-line).
- Store-listing copy realigned to the English source; localisable "Also see" blog link.
Fixed
- Thunderbird button is icon-only with the "OFF" badge.
- Fixed-size phishing store screenshots now match their filename dimensions.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.15
7 Tem 2026 tarihinde çıktı - 206,43 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.15 — 2026-07-05
Added
- Locale-specific phishing screenshots for every supported website/manual locale.
- Click any screenshot on the website to open it in a popup with native zoom
(pinch- and double-tap-zoom on mobile); without JavaScript a click opens the
image full-size. Built on the native<dialog>element, so Escape, a backdrop
click or the close button dismisses it and returns focus to the screenshot,
while a tap on the image itself is left inert so native zoom stays usable.
Fixed
- The website's lead phishing screenshot now follows a runtime language change
on the landing page.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.13
30 Haz 2026 tarihinde çıktı - 139,23 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.13 — 2026-06-30
Added
- The published website is now fully per-locale and discoverable.
Changed- The published website now localises each per-locale page's filename, not just its
folder: every non-English page is emitted under its own-language filename. - Reframed the phishing intro so the paypal.com/paypa1.com look-alike is presented
as one example, alongside the subtler case of a link routed through a tracker or
redirector that hides the target URL. Reworded the product claim from "shows you the
real destination of links" to "shows you the URL each link points to" — the extension
shows the URL a link points to as written (the full URL, not just the host, and not
the final page behind a redirect) — and broadened "webmail" to "mail" so it covers
the Thunderbird/Outlook/Gmail forms too. - Opera now points to the Chrome Web Store. The landing page's Opera pill links to the
Chrome Web Store, the Install entry names Opera up front (the Chrome build runs in
Opera), and the manual lists Opera as a supported browser with the Chrome-build
install detail in its install steps; a dedicated Opera listing stays marked coming
soon.
Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
- The published website now localises each per-locale page's filename, not just its
Sürüm 0.1.12
26 Haz 2026 tarihinde çıktı - 138,61 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır0.1.12 — 2026-06-26
Added
- Live store-listing links for the four published targets. The website landing
page's Install section and the user manual (docs/MANUAL.md) now link straight
to the Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons (AMO) and
Thunderbird Add-ons (ATN) listings, mirrored across all ten translated locale
catalogues (site/i18n/<code>.json) and manuals (docs/<code>/MANUAL.md). The
Opera, Gmail and Outlook listings stay marked "coming soon" until they go live.
The published URLs are also recorded per store indocs/store-submission.mdand
in the README's Publishing section.
- The landing page's "Supported browsers, mail client and email add-ons" pills are
now clickable for the published targets, each linking to its store listing
(Chrome, Edge, Firefox, Thunderbird); the still-pending pills (Opera, Gmail,
Outlook) stay plain. The label keeps itsdata-i18nannotation on the anchor, so
the runtime language switcher still localises it in place.
Changed
- The revealed-URL chip (.reveal-urls-url) now carries a fixed white
background (background: #ffffff) baked into the injected stylesheet and is
rendered fully opaque (opacity: 1), so the actual link shown always sits on
a solid white background regardless of the host page's colours. The chip's
default stylesheet weight isfont-weight: normal, so an honest link's
revealed URL is not bold unless aurlFontWeightoverride is configured; a
text-vs-href mismatch adds bold emphasis on top of that default. The runtime
contrast backdrop (applyContrastBackdrop) now samples the chip's OWN
effective background, so it still adds a white backdrop when a host page
overrides the chip's white with a darker, more specific rule.
Fixed
- The ten translated privacy policies (docs/<code>/PRIVACY.md) were stale: they
predated the multi-form rewrite and were missing the entire per-form Permissions
structure — theBrowser extension,Outlook add-inandGmail add-on
sub-sections — and with it the two Gmail OAuth scope identifiers
(gmail.addons.current.message.readonlyandgmail.addons.execute). All ten have
been regenerated from the current Englishdocs/PRIVACY.md(machine-translated,
pending human review), restoring the missing sections and scope URLs.
- The ten translated user manuals (docs/<code>/MANUAL.md) were stale the same way,
each missing theThe Outlook and Gmail add-onsandLanguagessections (16
headings vs the English manual's 18). All ten have been regenerated from the current
Englishdocs/MANUAL.md(machine-translated, pending human review), with their
table-of-contents and in-page anchors verified to resolve against the translated
heading slugs.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.11
24 Haz 2026 tarihinde çıktı - 138,61 KBfirefox 142.0 ve üstü, android 142.0 ve üstü ile çalışır[0.1.11] — 2026-06-17
Added
- A source-code archive (web-ext-artifacts/reveal-urls-<version>-source.zip) for
the Firefox (AMO) and Thunderbird (ATN) stores, which require the original sources
whenever an add-on ships esbuild-bundled code.make packagenow emits it
alongside the per-target zips, and a newmake sourcetarget builds it on its own
(make source REF=<tag>back-fills a past release, e.g.v0.1.10). The archive
carries reviewer build instructions indocs/mozilla-reviewer-build.md. Generation
is a host script (tooling/source-archive.sh) since the build image carries no git;
it skips gracefully (leaving the per-target zips) when hostgitorzipis
absent. AREF=<tag>back-fill archives a tag verbatim when that release ships its
own reviewer doc, and folds in the current instructions only for releases that
predate it — printing a warning in that case, since the authoritative toolchain is
whatever the archive's ownDockerfile/pnpm-lock.yamlpin (the doc says as
much) rather than an unverifiable "build process is unchanged" assumption. The
release workflow asserts the source archive exists before uploading, so a
silently-skipped archive cannot pass unnoticed. Covered bymake testsmoke tests
(tooling/test/source-archive.test.mjs, including the back-fill warning path) and
@source-archiveGherkin scenarios (features/source-archive.feature), both
skipped where the host tools are absent.
Changed
- The default colour of the revealed URL on honest (non-mismatch) links is now a
neutral very dark grey (#1a1a1a) instead of green, in both the browser
extension/Thunderbird add-on (matchColour) and the Gmail add-on card. A green
honest link could be read as a signal that the link had been checked or was
safe, which Reveal URLs does not claim; a neutral colour avoids that false
reassurance while the mismatch colour stays red. Users who saved a custom match
colour keep their choice; the new default applies where nothing was stored. (The
bundled screenshots still show the previous green and should be re-captured.)
- The Outlook add-in manifests (manifest.jsonandmanifest.xml) now stamp a
1.0.xversion, decoupled from the0.xbrowser extensions, because AppSource
rejects an add-in manifest version below1.0. The version stamper pins the
Outlook target'sMAJOR.MINORbase (TARGET_VERSION_BASE) while keeping the
build number shared, so every shipped manifest still moves in lockstep.
Fixed
- The Outlook add-in XML manifest now passes Microsoft AppSource package
validation. ItsVersionOverridesdeclaredVersionOverridesV1_0, but the
ribbon and mobile command surfaces it carries areV1_1-only; that schema
failure made the validator unable to identify the add-in type, surfacing as
the misleading "manifest product ID could not be parsed", "package type not
identified" and "wrong package" errors.Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
Sürüm 0.1.10
16 Haz 2026 tarihinde çıktı - 138,59 KBfirefox 142.0 ve üstü ile çalışır[0.1.10] — 2026-06-16
Added- Native email add-ons for Microsoft Outlook (Office.js task pane and
command surface) and Gmail (Google Apps Script card service), so the
link-destination reveal now works inside the desktop and web mail clients,
not only in the browser extension. Each add-on ships its own manifest, icons,
localisation, per-user/roaming settings storage, build pipeline and test
suite. - A shared
findingsmodule inpackages/core, consumed by both new add-ons,
that derives the displayable link findings (including mismatch highlighting)
from parsed anchors, keeping the reveal logic identical across surfaces. - Make targets and a containerised
claspworkflow for creating, building and
deploying the Gmail Apps Script project, including minimal-scope login and a
bind-mounted token. - Gherkin scenarios and step definitions covering the Gmail card and Outlook
task pane, plus an add-on panel test harness and a CardService double.
Changed- The Gmail add-on resolves link destinations through a bundled
URL
polyfill, brands its card with the project logo and colours the revealed link
destinations; its OAuth request covers both thegmail.addons.executeand
gmail.message.readonlyscopes. - Screenshots no longer mask sensitive data with solid black boxes; the store
and documentation assets were regenerated accordingly.
Fixed- Addressed review findings across the Gmail and Outlook add-ons, the website
and the documentation (manifestAppDomains, privacy dates, icon scope,
remote-code declarations and permission naming).
Kaynak kodu Yalnızca GNU Affero Genel Kamu Lisansı v3.0 lisansıyla yayımlandı
- Native email add-ons for Microsoft Outlook (Office.js task pane and