Salesforce FLS Comparator Expanded bởi Jacob Crandall
Compare Salesforce Field Level Security settings across fields and orgs
Có sẵn trên Firefox dành cho Android™Có sẵn trên Firefox dành cho Android™
1 người dùng1 người dùng
Quét mã QR để mở tiện ích mở rộng này trong Firefox dành cho Android
Siêu dữ liệu mở rộng
Ảnh chụp màn hình
Quyền hạn và dữ liệu
Quyền hạn bắt buộc:
- Truy cập các thẻ trên trình duyệt
- Truy cập dữ liệu của bạn cho các trang web trong tên miền salesforce.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền lightning.force.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền my.salesforce.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền sandbox.my.salesforce.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền develop.my.salesforce.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền salesforce-setup.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền my.salesforce-setup.com
- Truy cập dữ liệu của bạn cho các trang web trong tên miền sandbox.my.salesforce-setup.com
Thu thập dữ liệu:
- Nhà phát triển cho biết tiện ích mở rộng này không yêu cầu thu thập dữ liệu.
Thêm thông tin
- Liên kết tiện ích
- Phiên bản
- 1.0.5
- Kích cỡ
- 166,6 KB
- Cập nhật gần nhất
- một tháng trước (11 Thg 06 2026)
- Thể loại có liên quan
- Giấy phép
- Giấy phép MIT
- Lịch sử các phiên bản
- Thêm vào bộ sưu tập
PERMISSIONS
storage — persists FLS snapshots and apply-history in browser.storage.local only. Nothing is sent remotely.
tabs — identifies which tab holds an active Salesforce session to retrieve the correct instance URL.
cookies — Salesforce marks its session token ("sid") HttpOnly, so document.cookie in a content script cannot read it. The background service worker reads it via browser.cookies.get() on the Salesforce host, uses it as a Bearer token for REST/Tooling API calls back to that same org, and never stores or transmits it elsewhere.
host_permissions (.salesforce.com, .lightning.force.com, .my.salesforce.com, .sandbox.my.salesforce.com, .develop.my.salesforce.com, .salesforce-setup.com variants) — required for the background worker to make authenticated fetch() calls to the Salesforce REST and Tooling APIs. The wildcard is necessary because orgs use unpredictable customer-specific subdomains.
CONTENT SCRIPT
salesforce-bridge.content.ts runs on Salesforce domains only. It detects Set Field-Level Security pages via URL pattern and injects a launch button. It reads nothing beyond what is already in the page URL. The background worker rejects any message from a content script whose sender tab is not a recognised Salesforce hostname.
HOW TO TEST
Requires a free Salesforce Developer Edition org (developer.salesforce.com/signup).
1. Open any page in the org after logging in.
2. Open the FLS Comparator sidebar (View → Sidebar → FLS Comparator).
3. Select an object (e.g. Contact) and field (e.g. Email), then click Fetch FLS.
4. The table shows Read/Edit access for every Profile and Permission Set in the org.
No eval(), no remote scripts, no telemetry. All network traffic goes only to the user's own Salesforce org.