Is Infinite Dashboard - New Tab like no other safe?
Infinite Dashboard is high risk. The ChatGPT feature's new-tab page asks the worker for an access token. If none stored, the worker reads all chat.openai.com cookies as a Cookie header to OpenAI and saves the token. Not seen live; needs a login and optional permission.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
OpenAI cookies used to retrieve an access token
The ChatGPT feature's new-tab page asks the worker for an access token.
If none stored, the worker reads all chat.openai.com cookies as a Cookie header to OpenAI and saves the token.
Not seen live; needs a login and optional permission.
You use the extension's ChatGPT feature from the new-tab page.
The flow starts when the feature initializes or when a question is submitted.
The extension reads OpenAI cookies, requests the OpenAI session endpoint, and stores any returned access token.
The source first reuses a stored token if one exists; otherwise it builds a Cookie header from chat.openai.com cookies.
| Field | Value | Why it matters | |
|---|---|---|---|
OpenAI web cookies | __Secure-next-auth.session-token=s%3Aabc123def456; cf_clearance=8fbd1c9a8e2b4f00 (illustrative) | These cookies can represent your logged-in OpenAI browser session. | |
Session lookup request | Cookie: __Secure-next-auth.session-token=s%3Aabc123def456; cf_clearance=8fbd1c9a8e2b4f00 (illustrative) | The cookies are sent together so the session endpoint can return details for the logged-in session. | |
OpenAI access token | eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTFhMmIzYyIsImV4cCI6MTc2Mjk5MjAwMH0.Kd8mVnH2yP0qR5tUaL6sW3xY9zAbC1dEfGhIjKlMnOp (illustrative) | A returned token can authorize requests as part of your OpenAI session while it remains valid. | |
Token save time | tokenSavedOn=1762992000123 (illustrative) | The extension records when the token was saved so it can reuse the token until its local expiry window passes. | |
OpenAI device cookie | oai-did=9d2d7e0c-9346-4c8c-8ee3-b0e16fb7a2ac (illustrative) | A related ChatGPT request path also reads a device cookie from openai.com and can attach it to later requests. |
| Cookie | __Secure-next-auth.session-token=s%3Aabc123def456; cf_clearance=8fbd1c9a8e2b4f00 (illustrative) |
The packaged service worker builds the cookie-backed session request and saves the token
key: "getChatGPTAccessToken",
value: function() {
return new Promise((function(resolve, reject) {
chrome.runtime.sendMessage({
action: "getChatGPTAccessToken"
}, (function(res) {
res.error ? reject(res) : resolve(res);
}));
}));
}
key: "getProvider",
value: function() {
var _this4 = this;
return new Promise((function(resolve, reject) {
_this4.getChatGPTAccessToken().then((function(res) {
_this4.setState({
error: null
}), _this4.setState({
authorized: !0
}), resolve(res);
})).catch((function(err) {
err.error && (err = err.error), _this4.setState({
error: err
}), _this4.setState({
authorized: !1
}), _this4.removeLoader(), reject(err);
})).finally((function(r) {
_this4.setState({
requested: !0
});
}));
}));
}key: "onMessage",
value: function() {
chrome.runtime.onMessage.addListener((function(msg, sender, response) {
switch (msg.action) {
case "getChatGPTAccessToken":
getChatGptAccessToken().then((function(res) {
response({
error: !1,
response: res
});
})).catch((function(err) {
err.message ? response({
error: err.message
}) : response({
error: "Error"
});
}));
break;
case "login":
login().then((function() {
response({
error: !1
});
})).catch((function(err) {
err.message ? response({
error: err.message
}) : response({
error: "Error"
});
}));
}
return !0;
}));
}function getChatGptAccessToken() {
return _getChatGptAccessToken.apply(this, arguments);
}
function _getChatGptAccessToken() {
return (_getChatGptAccessToken = _babel_runtime_helpers_asyncToGenerator__WEBPACK_IMPORTED_MODULE_3___default()(_babel_runtime_regenerator__WEBPACK_IMPORTED_MODULE_4___default.a.mark((function _callee7() {
var userConfig, cookie, resp, data;
return _babel_runtime_regenerator__WEBPACK_IMPORTED_MODULE_4___default.a.wrap((function(_context7) {
for (;;) switch (_context7.prev = _context7.next) {
case 0:
return _context7.next = 2, Object(app_background_modules_config_index_js__WEBPACK_IMPORTED_MODULE_10__.clearOldAccessToken)();
case 2:
return _context7.next = 4, Object(app_background_modules_config_index_js__WEBPACK_IMPORTED_MODULE_10__.getUserConfig)();
case 4:
if (!(userConfig = _context7.sent).accessToken) {
_context7.next = 9;
break;
}
return _context7.abrupt("return", userConfig.accessToken);
case 9:
return _context7.next = 11, chrome.cookies.getAll({
url: "https://chat.openai.com/"
});
case 11:
return cookie = _context7.sent.map((function(cookie) {
return "".concat(cookie.name, "=").concat(cookie.value);
})).join("; "), _context7.next = 14, fetch("https://chat.openai.com/api/auth/session", {
headers: {
Cookie: cookie
}
});
case 14:
if (403 !== (resp = _context7.sent).status) {
_context7.next = 17;
break;
}
throw new Error("CLOUDFLARE");
case 17:
return _context7.next = 19, resp.json().catch((function() {
return {};
}));
case 19:
if ((data = _context7.sent).accessToken) {
_context7.next = 22;
break;
}
throw new Error("UNAUTHORIZED");
case 22:
return _context7.next = 24, Object(app_background_modules_config_index_js__WEBPACK_IMPORTED_MODULE_10__.setAccessToken)(data.accessToken);
case 24:
return _context7.abrupt("return", data.accessToken);
case 25:
case "end":
return _context7.stop();
}
}), _callee7);
})))).apply(this, arguments);
}function setAccessToken(_x2) {
return _setAccessToken.apply(this, arguments);
}
function _setAccessToken() {
return (_setAccessToken = _babel_runtime_helpers_asyncToGenerator__WEBPACK_IMPORTED_MODULE_0___default()(_babel_runtime_regenerator__WEBPACK_IMPORTED_MODULE_1___default.a.mark((function _callee4(accessToken) {
return _babel_runtime_regenerator__WEBPACK_IMPORTED_MODULE_1___default.a.wrap((function(_context4) {
for (;;) switch (_context4.prev = _context4.next) {
case 0:
return _context4.next = 2, setUserConfig({
accessToken: accessToken,
tokenSavedOn: Date.now()
});
case 2:
case "end":
return _context4.stop();
}
}), _callee4);
})))).apply(this, arguments);
}- chat.openai.com
Receives the cookie-backed GET request to /api/auth/session so the extension can retrieve a session access token.
- openai.com
The related ChatGPT web request path reads the oai-did cookie for later OpenAI API headers.
Content scripts run on every website
The manifest declares two content scripts matching every URL, loading sidebar and search-helper code as you browse ordinary sites.
Dynamic analysis confirmed content-script activity but no scraping or transmission for this claim.
You open a website in Chrome.
The extension can load its sidebar and search-helper scripts on the page.
The manifest grants both scripts access to all URL patterns.
| Field | Value | Why it matters | |
|---|---|---|---|
Visited page URL | https://www.google.com/search?q=weather | Shows which website and page you opened, including search terms when they appear in the address. | |
Page body content | A search-results page with a right-side results panel | Lets the extension add elements to the page and read visible page structure while the script is running. | |
Stored bookmark list | Bookmark title and URL shown in the page sidebar | Lets the sidebar render saved bookmark titles and URLs into websites where the sidebar appears. |
Manifest and content scripts show all-site page access
content_scripts: [
{ css: ["css/content.css"], matches: ["<all_urls>"], js: ["js/content.js"] },
{ matches: ["<all_urls>"], js: ["js/search-helper.js"] }
],
host_permissions: ["<all_urls>"]function initSidebar() {
sidebar = document.createElement("div");
sidebar.id = "new-tab-sidebar";
sidebar.innerHTML = `<div class="wrap">\n <img class="new-tab-logo" src="${chrome.runtime.getURL("img/128x128.png")}">\n \n </div>`;
sidebar.children[0].appendChild(generateBookmarksList());
document.body.appendChild(sidebar);
}
function getBookmarks() {
return new Promise(resolve => {
chrome.storage.local.get(["bookmarks"], res => {
bookmarks = res.bookmarks;
resolve(res.bookmarks);
});
});
}function getQuery() {
var urlSearchParams = new URLSearchParams(window.location.search);
var params = Object.fromEntries(urlSearchParams.entries());
return document.location.hostname.match(domains.google) ? params.q :
document.location.hostname.match(domains.yahoo) ? params.p :
document.location.hostname.match(domains.bing) || document.location.hostname.match(domains.duckduckgo) ? params.q : null;
}Bookmark preview URLs sent to mini.s-shot.ru
Generating a bookmark thumbnail sends the page's URL to `mini.s-shot.ru` in a screenshot request.
Dynamic analysis captured a GET for `https://www.youtube.com/`; background and new-tab code build these URLs by appending the URL after `?`.
You add or use a bookmark that needs a thumbnail preview.
The extension requests a screenshot from mini.s-shot.ru and includes the bookmarked page URL.
The observed request included `https://www.youtube.com/` after the question mark.
| Field | Value | Why it matters | |
|---|---|---|---|
Bookmarked page URL | https://www.youtube.com/ | Shows the remote screenshot service which page you saved or previewed. | |
Saved bookmark context | http://chatgpt.com/ | Connects the request to a bookmark record that the extension stores locally for its preview feature. | |
Screenshot service | mini.s-shot.ru | Identifies the outside service that receives the bookmarked URL and returns the preview image. |
Bookmark preview code appends page URLs to mini.s-shot.ru
function initBookmarks(callback) {
chrome.topSites.get(function(data) {
var bookmarks = data.filter(function(item) {
return item.url.slice(0, 6) !== "chrome" && !item.url.includes("localhost");
}).slice(0, 10).map(function(item, id) {
return { id: id, url: item.url, title: item.title || "", img: "" };
});
chrome.storage.local.set({ bookmarks: bookmarks });
var promises = bookmarks.map(function(item) {
var url = item.url;
return new Promise(function(resolve) {
fetch("https://mini.s-shot.ru/1366x890/400/jpeg/?" + url)
.then(function(r) { return r.blob(); })
.then(function(r) {
var reader = new FileReader();
reader.readAsDataURL(r);
reader.onload = function() { resolve(reader.result); };
reader.onerror = function() { resolve(null); };
})
.catch(function(e) { resolve(null); });
});
});
Promise.all(promises).then(function(previews) {
bookmarks = bookmarks.map(function(b, i) {
b.img = previews[i];
return b;
});
chrome.storage.local.set({ bookmarks: bookmarks });
chrome.runtime.sendMessage({ action: "reload-storage" }, function() {
chrome.runtime.lastError;
});
if (callback) callback();
});
});
}function getPreview(url) {
var _this4 = this;
if (url && !this.state.previewLoading) {
this.setState({ previewLoading: true });
var img = new Image();
img.src = "https://mini.s-shot.ru/1366x890/400/jpeg/?" + url;
img.onload = function() {
var canvas = document.createElement("canvas");
canvas.width = img.width;
canvas.height = img.height;
canvas.getContext("2d").drawImage(img, 0, 0, canvas.width, canvas.height);
_this4.state.item.img = canvas.toDataURL("image/png");
_this4.setState({ previewLoading: false });
};
img.onerror = function() {
_this4.setState({ previewLoading: false });
};
}
}- mini.s-shot.ru
Screenshot service used to generate bookmark thumbnail images from supplied page URLs.
+1 more finding not shown