Is Direct Access safe?
Accès-Direct is medium risk. Direct Access GETs accesdirectapp.com/installation during install (HTTP 200) and merges returned JSON keys into local storage alongside defaults like the action-list URL and cookie-banner settings. The listing covers cookie automation only.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Installation request stores remote settings
Direct Access GETs accesdirectapp.com/installation during install (HTTP 200) and merges returned JSON keys into local storage alongside defaults like the action-list URL and cookie-banner settings.
The listing covers cookie automation only.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install Direct Access in Chrome.
The extension contacts an installation endpoint and stores the returned JSON for later automation.
The storage write combines built-in defaults with every key returned by the server.
HTTP 200 observed during dynamic analysis.
- Response approval flagtrue
Lets the remote response decide whether the extension stores the returned settings and continues loading action definitions.
- Action-list sourcehttps://raw.githubusercontent.com/accesdirect/app/main/actions.json
Controls where the extension downloads the website-specific rules it later applies while you browse.
- Stored install identifier7b6a0c34-8a84-4d4e-8ef2-0d6e880a0f24 (illustrative)
Can give the stored settings a per-install value if the server includes one in the JSON response.
- Default action choicerefuse
Controls whether the extension tries to refuse, accept, or skip cookie-banner choices on supported sites.
- Cookie-setting rulescookie_consent=refused (illustrative)
Can tell the page script to set a named browser cookie for a matching website.
The install handler stores the full JSON response
Deobfuscated install request and storage write
app/main/worker.jschrome.runtime.onInstalled.addListener(async (details) => { try { if (details.reason == "install") { const appSettings = { actionsURL: 'https://raw.githubusercontent.com/accesdirect/app/main/actions.json', actions: [], enabled: {}, selectedAction: 'refuse', acceptIfRefuseNotAvailable: true, }; const fetchResponse = await fetch("https://www.accesdirectapp.com/installation"); if (fetchResponse?.status === 200) { const json = await fetchResponse.json(); if (json && json.status) { chrome.storage.local.set({ ...appSettings, ...json }); fetchingActions(); } } } } catch (e) { console.error(e); }});Deobfuscated follow-up action-list fetch
app/main/worker.jsconst fetchingActions = () => { chrome.storage.local.get(['id', 'actionsURL'], async (storage) => { if (storage?.actionsURL) { const fetchResponse = await fetch(`${storage.actionsURL}`); if (fetchResponse?.status === 200) { const text = await fetchResponse.text(); const json = JSON.parse(text); if (json) { storage.actions = actionMerger(storage.actions, json.actions); } chrome.storage.local.set({ actions: storage.actions }); } } });}Stored settings are later used on visited pages
Deobfuscated content-script storage read
app/main/linker.jschrome.storage.local.get(['actions', 'selectedAction', 'acceptIfRefuseNotAvailable', 'cookies'], (storage) => { let added = false; if (window.self === window.top) { const addActionsHandler = () => { if (!added) { added = true; const s = document.createElement('script'); s.src = chrome.runtime.getURL('/app/web/actionsHandler.js'); document.body.appendChild(s); } }; const winHostname = window.location.hostname; const host = winHostname.indexOf('www.') === 0 ? winHostname.substring(4) : winHostname; if (storage.actions?.[host]) { addActionsHandler(); window.addEventListener('message', (m) => { if (m.data === 'waitForActions') { window.postMessage({ dataType: 'hostActions', host: host, actions: storage.actions?.[host].actions, cookies: storage.cookies?.[host], selectedAction: storage.selectedAction, enabled: storage.enabled, acceptIfRefuseNotAvailable: storage.acceptIfRefuseNotAvailable }, '*'); } }); } chrome.runtime.onMessage.addListener((message, sender, sendResponse) => { if (message.message === "add-user-action") { if (document.querySelectorAll(message.selector)?.[message.indexSelector]) { addActionsHandler(); sendResponse({ status: true }); } else { sendResponse({ status: false }); } } }); }});Deobfuscated page-script action handler
app/web/actionsHandler.jsconst actionHandler = (actionData) => { const host = actionData.host; const actions = actionData.actions; const userAction = actions.userAction; let selectedAction = userAction ? userAction : actions[actionData.selectedAction]; const acceptIfRefuseNotAvailable = actionData.acceptIfRefuseNotAvailable; if (acceptIfRefuseNotAvailable && !userAction && actionData.selectedAction === 'refuse' && selectedAction === null && actions.accept) { selectedAction = actions.accept; } const postClickHandler = selectedAction?.postClickHandler ? selectedAction?.postClickHandler : ''; const postClickHandlerRange = doc.createRange(); const index = selectedAction?.index !== undefined ? selectedAction?.index : 0; if ((actionData.enabled && actionData.enabled[host] !== undefined ? actionData.enabled[host] : true) || userAction) { switch (selectedAction?.type) { case 'scroll': const element = doc.querySelectorAll(selectedAction.selector)?.[index]; if (element) { element.scrollTo(selectedAction.scrollX, selectedAction.scrollY); } break; case 'click': clickAction(selectedAction.selector, index); doc.head.appendChild(postClickHandlerRange['createContextualFragment'](postClickHandler)); break; case 'multiple': for (const selectorData of selectedAction.selectors) { if (selectorData.type === 'click') { clickAction(selectorData.selector, index); } } break; } if (actionData.cookies?.name?.length > 0) { const name = actionData.cookies.name; const value = actionData.cookies.value; const days = 30; let expires = ''; if (days) { const date = new Date(); date.setTime(date.getTime() + (days * 24 * 60 * 60 * 1000)); expires = `; expires=${date.toUTCString()}`; } doc.cookie = name + "=" + (value || "") + expires + "; path=/"; } }}- www.accesdirectapp.com
Receives the installation request and returns JSON that the extension stores locally.
- raw.githubusercontent.com
Default source for action definitions loaded after the installation response is stored.
What it can do
Permissions this extension asks for, as declared in version 0.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Store data in your browser
storage
Schedule its own background tasks
alarms