diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx index 8bee12ca..dab93ac9 100644 --- a/browsers/chrome-policies.mdx +++ b/browsers/chrome-policies.mdx @@ -272,6 +272,10 @@ const browser = await kernel.browsers.create({ ``` +### Debug extensions added through enterprise policy + +Chrome blocks DevTools by default on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to enable it. See [Debugging with DevTools](/browsers/extensions#debugging-with-devtools). + ### Restrict navigation to specific URLs To lock a browser to an approved set of URLs, block everything with `URLBlocklist` and then allow back only the URLs you want with `URLAllowlist`. Entries match a whole domain (`chatgpt.com`) or a specific path (`en.wikipedia.org/wiki/Cat`), and more specific entries take precedence. This gates top-level navigation, so any other URL returns `ERR_BLOCKED_BY_ADMINISTRATOR`; it does not block resources or API calls a permitted page loads from other origins. diff --git a/browsers/extensions.mdx b/browsers/extensions.mdx index db419a0f..40d4eea2 100644 --- a/browsers/extensions.mdx +++ b/browsers/extensions.mdx @@ -134,6 +134,14 @@ kernel browsers extensions upload ./my-extension Loading an extension triggers a Chromium restart, which takes several seconds and may disrupt active CDP connections. +## Debugging your extensions + +You can open DevTools on your extension or attach to its service worker over CDP to read its console, set breakpoints, and inspect its storage. This works by default for most extensions. + + +If Kernel added your extension through enterprise policy, Chrome blocks DevTools on it by default. See [Debugging with DevTools](#debugging-with-devtools) to allow it. + + ## Extensions requiring enterprise policies For a complete list of available extension settings and policies, refer to the [Chrome Enterprise Policy documentation](https://chromeenterprise.google/policies/extension-settings/). @@ -184,3 +192,37 @@ Once you successfully upload an enterprise policy extension, Kernel handles the 5. **Installation** - Chrome installs the extension via enterprise policy when the browser starts No additional HTTP server or manual policy configuration is needed. The extension works seamlessly in any browser session that it's uploaded to. + +### Debugging with DevTools + +Chrome blocks DevTools on extensions added through enterprise policy by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool: + + +```python Python +from kernel import Kernel + +kernel = Kernel() + +browser = kernel.browsers.create( + extensions=[{"name": "request-signer"}], + chrome_policy={ + "DeveloperToolsAvailability": 1, + }, +) +``` + +```typescript Typescript/Javascript +import Kernel from '@onkernel/sdk'; + +const kernel = new Kernel(); + +const browser = await kernel.browsers.create({ + extensions: [{ name: 'request-signer' }], + chrome_policy: { + DeveloperToolsAvailability: 1, + }, +}); +``` + + +This applies to every extension added through enterprise policy in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.