惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
Security Archives - TechRepublic
Security Archives - TechRepublic
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Proofpoint News Feed
G
GRAHAM CLULEY
P
Privacy International News Feed
The Hacker News
The Hacker News
Forbes - Security
Forbes - Security
U
Unit 42
N
News and Events Feed by Topic
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cyber Attacks, Cyber Crime and Cyber Security
C
Cisco Blogs
A
About on SuperTechFans
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
Docker
I
Intezer
Spread Privacy
Spread Privacy
The Last Watchdog
The Last Watchdog
V2EX - 技术
V2EX - 技术
S
Security @ Cisco Blogs
F
Full Disclosure
S
Secure Thoughts
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Project Zero
Project Zero
Recorded Future
Recorded Future
Cyberwarzone
Cyberwarzone
S
Security Affairs
AWS News Blog
AWS News Blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
Hacker News: Ask HN
Hacker News: Ask HN
Vercel News
Vercel News
P
Proofpoint News Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Register - Security
The Register - Security
S
Schneier on Security
F
Fortinet All Blogs
C
CERT Recently Published Vulnerability Notes
L
LINUX DO - 最新话题
T
Tor Project blog
T
The Exploit Database - CXSecurity.com
MongoDB | Blog
MongoDB | Blog
Webroot Blog
Webroot Blog

软件

图片浏览器 Honeyview 可能比 Bandivew 更好用 - V2EX 一些常用笔记软件迁移到 Obsidian 的方法总结 - V2EX lodop 的打印原理是什么 - V2EX OMMWriter - V2EX 苹果 AI 无缘中国大陆 自做小软件共享 「网速小软件」共享 1password 目前有什么低价订阅渠道吗 WPS 表格今天好多崩溃的? joplin 换 obsdian 使用求教 vibe 了一个轻量 mac 状态栏显示工具,支持 clash verge 显示 58 元买断的软件,希望可以终生维护,为什么 58 元买的衣服,吃的快餐,没有同样的要求呢? N 年 1password 老用户,又续费了 今天第一次用 obsidian 一个本地密码管理软件,数据都在本地 opencode + OMO,用起来如何?费 token? MuMu AI 自动化新玩法 如何应对 '换 WIFI 就取消授权' 的软件 MuMu AI 自动化 各位, AI 时代求推荐一款多端同步的文档记录软件? Notion 和 Obsidian? 不想要广告和算法推荐,我做了一款本地优先、极致纯粹的 RSS&播客聚合 app: AurioClub - V2EX 换了 N 个笔记工具,最终我还是选择了 Obsidian - V2EX 世界上怎么有那么完美的 APP! - V2EX ToDesk 为什么需要「完全磁盘访问权限」? - V2EX 有了 AI 以后,有哪些想 Vibe Coding 的软件? - V2EX 2026 年了, todo 应用烂大街了,仍然没有一个符合我要求的 - V2EX 遗憾, 1Capture 也从几十 M 涨到 200 M 了, - V2EX 求推荐图片管理软件,可以按照图片的分类/标签/日期导出虚拟文件系统,可在电脑中挂载 - V2EX 吐槽一下“高德地图” - V2EX 鱼跃 CRM & 财务管理系统 - V2EX 自建 Rustdesk 连接时总爱报错 “连接被对方关闭” - V2EX Obsidian Vim 模式的输入法状态 - V2EX 各位都是如何备份自己的 obsidian 的呢 - V2EX 大家用 ATV 来 播放/投屏 互联网上下载的视频文件通常用什么软件? - V2EX 请问笔记大佬 Notion 和 Obsidian 对比 - V2EX 为什么 AI 应用的“最后一公里”,总是卡在聊天窗口上? - V2EX Obsidian ios 版不同步文件夹变化 - V2EX 求安卓能设置每月第 1 个工作日的提醒应用 - V2EX android 是否有可以语音添加待办事项的 app? - V2EX WeTab 和 Infinity 重新上架 edge 商店了 - V2EX 受不了 Evernote 一直涨价,求替代 - V2EX 大家能推荐一个记账软件嘛? - V2EX 你们用豆包输入法了吗 - V2EX 垃圾向日葵 大家不要买 - V2EX 讯飞输入法的 Windows 端没有测试吗,这也太搞了 - V2EX 请教 Syncthing 问题:同步不同的目录结构 - V2EX 现在反而不敢买买断制 app 了 - V2EX UU 远程现在支持 mac 被控了 - V2EX 有什么好用的记录待办事项的软件 - V2EX 离谱 钉钉无故后台偷偷把我们的商旅系统整个换了 - V2EX What Capabilities Should You Look for in a Cross-Platform SDK for Enterprise Mobility — and How FinClip Makes It Happen - V2EX 远程控制工具 todesk 怎么样,用过的朋友给说说呗 - V2EX todesk 简直是我用过的软件中最恶心,最垃圾的没有之一 - V2EX 安卓好用的记账软件推荐 - V2EX 有什么卸载软件可以很干净的卸掉 QQ 吗 - V2EX 滴答清单被 Gooogle play 识别成有害应用 Beyond Compare 在 Linux 平台上有办法禁用光标闪烁吗? 起兴试用了一下圆周 xx 钱迹用了 1968 天了,今天开了终身会员,开心 现在国产的好多软件广告真的恶心坏了,工具类的已经是会员了还一直有广告 Onenote 迁移至 Obsidian 的尝试(及遇到的坑) windows 中轻量级 FTP 服务器软件推荐 todesk 开始收割了,连接一会断开了提示 vip [破解] GitKraken 解除私有仓库限制 baidu 真是垃圾公司, 2025 年了还在搞流氓软件这一套! 大家有哪些 todo 的 app 推荐, Android 版本的。 Mac 的 ChatGPT 客户端最新版每次聊天之后会自动把窗口高度撑满整个屏幕高度 用 Just My Socks 好几年了,最近快到期了,想问问还有其他好用又稳定的产品吗? 大家有没有特别推荐使用的 obsidian 插件?能不能简单介绍一下核心功能于上手难度?
还有人坚持用 1Password 6 吗?我把 1password chrome classic 扩展改成 MV3 了 - V2EX
wowh · 2026-01-06 · via 软件

我用 Gemini 把 https://github.com/wowh/1password
和之前的代码 https://github.com/scramblr/1password 做了比对

大家可以参考一下

While they are both versions of the Stanford JavaScript Crypto Library (SJCL) and share about 99% of the same logic, Code 2 contains environment-safety modifications that are missing in Code 1.

Specifically, Code 2 has been updated to be more "environment-aware" (likely to prevent crashes in Node.js or Server-Side Rendering environments), whereas Code 1 is a more traditional browser-only minification.

Key Logical Differences
Here are the specific areas where the logic differs beyond simple formatting:

1. Environment Safety Checks (window and document)
In the sjcl.random.startCollectors and stopCollectors functions, Code 2 adds checks to see if window or document are defined before accessing them.

Code 1:

JavaScript

if(window.addEventListener){ ... }
else if(document.attachEvent){ ... }
Logic: This will throw a ReferenceError in environments like Node.js because window is not defined.

Code 2:

JavaScript

if (typeof window !== "undefined" && window.addEventListener) { ... }
else if (typeof document !== "undefined" && document.attachEvent) { ... }
Logic: This is safe. It checks the type first, so it won't crash in non-browser environments.

2. Error Handling Removal
In the startCollectors function, Code 1 has a fallback error that Code 2 has removed.

Code 1:

JavaScript

else throw new sjcl.exception.bug("can't attach event");
Code 2: The else block is entirely removed. If it can't find window or document, it simply does nothing rather than throwing an exception.

3. Stop Collectors Logic
A similar change exists in stopCollectors:

Code 1: Directly checks window.removeEventListener.

Code 2: Checks typeof window !== "undefined" before attempting to access window.removeEventListener.

While they share the same core cryptographic libraries (SJCL) and general business logic, Code 2 is a significantly modified version of Code 1, specifically updated to be compatible with Chrome Extension Manifest V3 (MV3). Code 1 is written for the older Manifest V2 (MV2) standard.

Here are the specific logical and functional differences:

1. Global Scope Reference (window vs. self)
Since Manifest V3 uses Service Workers (which do not have access to the window object), the global scope references have been changed.

Code 1: Uses window (e.g., n='undefined'!=typeof window&&window===this?this... and window.OnePassword=r).

Code 2: Uses self or globalThis (e.g., n = 'undefined' != typeof self && self.self === self ? self... and self.OnePassword = r).

2. Browser Action API
Chrome changed the "Browser Action" API to a generic "Action" API in Manifest V3.

Code 1: Uses chrome.browserAction (e.g., chrome.browserAction.onClicked... and chrome.browserAction.enable()).

Code 2: Uses chrome.action (e.g., chrome.action.onClicked... and chrome.action.enable()).

3. Navigation Interception (webRequest vs. tabs)
This is the most significant logical rewrite. Manifest V3 restricts the use of blocking webRequest.

Code 1: Uses chrome.webRequest.onBeforeRequest with the ['blocking'] attribute to intercept URLs containing onepasswdfill.

Code 2: Completely removes the webRequest logic and replaces it with a chrome.tabs.onUpdated listener. It now watches for tab updates to detect those specific URLs instead of intercepting the network request.

4. Context Menus Implementation
Code 1: Uses the onclick property directly inside the chrome.contextMenus.create object.

Code 2: Removes the onclick property from the creation object (as it's forbidden in MV3) and implements a centralized listener using chrome.contextMenus.onClicked.addListener. It also adds a mandatory id to the menu item.

5. URL API Modernization
Code 1: Accesses the URL constructor via window.URL || window.webkitURL.

Code 2: Accesses it via globalThis.URL || URL.