Chrome extension (ShortList)

apps/extension is an MV3 extension, named in one place (packages/shared/src/brand.ts).

pnpm dev:extension     # watch build → apps/extension/dist (points at http://localhost:5173)
pnpm build:extension   # production build (points at the Railway URL; no dev-only features)

Load apps/extension/dist via chrome://extensions → Developer mode → Load unpacked. Pair it in the web app under Settings → Browser extension → Pair a browser, then paste the code into the popup.

Reading pages: how and when (full detail in PRIVACY.md):

Install (GitHub Releases, Load unpacked)

Until it's on the Chrome Web Store, the extension is a zip attached to each GitHub release:

  1. Download shortlist-extension-<version>.zip from the latest release and unzip it into a folder you'll keep (Chrome loads it from there).
  2. Open chrome://extensions, switch on Developer mode (top right), click Load unpacked and choose that folder.
  3. Pin ShortList from the puzzle-piece menu. Open it, enter your ShortList's address (Chrome asks to allow that one site), then pair it from Settings → Browser extension in the web app.

To update: download the new zip, replace the folder's contents, and click the reload arrow on the extension's card in chrome://extensions. Your pairing and site switches are kept.

Building the release zip

Chrome Web Store (later)

The listing texts, permission justifications and data-use answers are ready in apps/extension/store/listing.md, with screenshots (1280×800) and the promo tile (440×280) in apps/extension/store/. Publishing needs a developer account (one-time fee): create the item, upload the same zip, paste the listing, and submit. The privacy policy is on the website at /privacy.html.

"Application submitted" detection

The extension only detects submissions on sites you switched on. Each detector requires the platform's own confirmation marker, never generic "thank you" text:

Site Marker
LinkedIn post-apply dialog ("Application sent"), or the job's "Applied … ago" state
Greenhouse …/jobs/<id>/confirmation page, or the legacy #application_confirmation
Lever …/<posting>/thanks page
Naukri the "Applied" state of the apply button
Workday Workday's post-submit dialog/page hooks

Adapter verification status (apps/extension/src/adapters/verification.ts). A capability, or for "submitted" each confirmation marker, is marked verified only together with a real captured fixture that proves it, and a test enforces this.

Site Job page Applications list
LinkedIn built, unverified (classic + newer layout; the real capture is a submitted page) built, unverified (My Jobs → Applied)
Naukri built, unverified built, unverified (My Applies)
Greenhouse built, unverified —
Lever built, unverified —
Workday built, unverified — (deferred)

Unverified readers are defensive. An applications-list row is read only when its job link, title, company and status are all found where the reader expects them. Incomplete rows are dropped and counted, never guessed. An unrecognised page reads nothing, and the popup says "Couldn't read this page". Portal sync from any reader only ever creates proposals for you to review.

"Submitted" marker Verified
LinkedIn: "Application status · Application submitted" card (newer layout) yes (real capture)
LinkedIn: Easy Apply "Application sent" dialog not yet
LinkedIn: "Applied … ago" state (classic layout) not yet
Greenhouse: confirmation page / legacy confirmation section not yet
Lever: thanks page not yet
Naukri: "Applied" button state not yet
Workday: post-submit dialog not yet