Skip to content

Browser extension

The browser extension is a Seald Healthcare Client of its own. It runs beside a dashboard page that it does not trust with plaintext. The extension:

  • answers only a page on the hostname it enrolled with
  • binds that page’s session beside its own with session.bindPage
  • renders every listing, record and file into its own surface, never into the page’s DOM
  • opens something only on a gesture inside that surface, never on the page’s request alone

Bind the page’s session

Call bindPage with the page’s session token on every call made for the page. The call carries both sessions. The SDK refuses the call if the two sessions name different people.

The samples use the allowed helper from Access decisions.

client.session.bindPage(pageSession);

Answer only the enrolled hostname, render in your own surface

Check the request’s origin against client.hostname before doing anything else. On a match, bind the page session and act on the page’s request. Render the result into the extension’s own surface, never back into the page.

async function onPageRequest(origin: string, message: { pageSession: string; folder: Locator }) {
if (origin !== `https://${client.hostname}`) return; // any other page gets nothing
client.session.bindPage(message.pageSession);
const listing = await allowed(await client.folders.list(message.folder));
if (listing) surface.renderListing(listing.entries); // the page cannot read the surface
}

Open only on a gesture inside the surface

The page can ask for a listing. Opening a record or a file needs a click on an entry inside the extension’s own surface. A request the page makes on its own never opens anything.

surface.onChoose(async (locator: Locator) => {
const opened = await allowed(await client.objects.open({ locator }));
if (opened) {
surface.render(opened);
page.tell({ locator, outcome: 'allow' }); // the page learns the outcome, never the plaintext
}
});

What the SDK does for you

  • Refuses a call bound to a page session naming a different person than the extension’s own.
  • Keeps plaintext inside the extension process. Nothing decrypted ever reaches the page’s DOM.
  • Records the same access events an open, a save or a share would record anywhere else.
  • Answers no origin other than the hostname this device enrolled with.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
denyThe policies refuse what the page asked for, the same as anywhere else.Show text in the extension’s own surface.
no-sessionThe extension has no open session of its own yet.Sign in through sessions before binding a page.

Next