Browser extension
The browser extension is a Seald Healthcare Client of its own. It runs beside a dashboard page that it does not trust with plaintext. The extension:
- answers only a page on the hostname it enrolled with
- binds that page’s session beside its own with
session.bindPage - renders every listing, record and file into its own surface, never into the page’s DOM
- opens something only on a gesture inside that surface, never on the page’s request alone
Bind the page’s session
Call bindPage with the page’s session token on every call made for the page. The call carries both sessions. The SDK refuses the call if the two sessions name different people.
The samples use the allowed helper from Access decisions.
client.session.bindPage(pageSession);client.session.bindPage(pageSession)client.session.bindPage(pageSession)Answer only the enrolled hostname, render in your own surface
Check the request’s origin against client.hostname before doing anything else. On a match, bind the page session and act on the page’s request. Render the result into the extension’s own surface, never back into the page.
async function onPageRequest(origin: string, message: { pageSession: string; folder: Locator }) { if (origin !== `https://${client.hostname}`) return; // any other page gets nothing client.session.bindPage(message.pageSession); const listing = await allowed(await client.folders.list(message.folder)); if (listing) surface.renderListing(listing.entries); // the page cannot read the surface}func onPageRequest(origin: String, message: PageRequest) async throws { guard origin == "https://\(client.hostname)" else { return } client.session.bindPage(message.pageSession) if let listing = try await allowed(client.folders.list(message.folder)) { surface.renderListing(listing.entries) }}suspend fun onPageRequest(origin: String, message: PageRequest) { if (origin != "https://${client.hostname}") return client.session.bindPage(message.pageSession) allowed(client.folders.list(message.folder))?.let { surface.renderListing(it.entries) }}Open only on a gesture inside the surface
The page can ask for a listing. Opening a record or a file needs a click on an entry inside the extension’s own surface. A request the page makes on its own never opens anything.
surface.onChoose(async (locator: Locator) => { const opened = await allowed(await client.objects.open({ locator })); if (opened) { surface.render(opened); page.tell({ locator, outcome: 'allow' }); // the page learns the outcome, never the plaintext }});surface.onChoose { locator in if let opened = try await allowed(client.objects.open(ObjectRef(locator: locator))) { surface.render(opened) page.tell(locator: locator, outcome: .allow) }}surface.onChoose { locator -> allowed(client.objects.open(ObjectRef(locator)))?.let { opened -> surface.render(opened) page.tell(locator = locator, outcome = Outcome.ALLOW) }}What the SDK does for you
- Refuses a call bound to a page session naming a different person than the extension’s own.
- Keeps plaintext inside the extension process. Nothing decrypted ever reaches the page’s DOM.
- Records the same access events an open, a save or a share would record anywhere else.
- Answers no origin other than the hostname this device enrolled with.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
deny | The policies refuse what the page asked for, the same as anywhere else. | Show text in the extension’s own surface. |
no-session | The extension has no open session of its own yet. | Sign in through sessions before binding a page. |
Next
- Sessions for
signIn,resumeandsignOutbefore binding a page. - Open records and files for what the surface renders once a gesture opens something.
- What your application does for why plaintext stays inside your own surface everywhere, not only in the extension.