A Chrome extension (Manifest V3) that, on any Salesforce Lightning record page, shows whether a chosen user has Read/Edit/Delete access to that record and explains why: enumerating every sharing source that grants it.
No OAuth, no external services, no dependencies. It reuses your existing
browser session against Salesforce (the sid cookie) to call the REST API
directly.
chrome://extensions in Chrome.manifest.json).https://yourorg.lightning.force.com/lightning/r/Account/001XXXXXXXXXXXXXXX/viewUserRecordAccess.ViewAllRecords/ModifyAllRecords overrides, record ownership, manual
shares, sharing rules, teams, implicit sharing, territories, and Apex
managed sharing, each attributed to the specific share row and access
level.Id, Name FROM User WHERE Name LIKE ...). The default target is always
yourself.background.js (service worker) is the only place that reads the
httpOnly sid cookie, via chrome.cookies.get. It maps the Lightning
host to the API instance host (<mydomain>.lightning.force.com →
<mydomain>.my.salesforce.com) and calls
https://<instanceHost>/services/data/v63.0/... with
Authorization: Bearer <sid>.popup.js parses the active tab’s URL for /lightning/r/<Object>/<Id>/,
determines standard vs. custom object handling, and drives the queries by
messaging the service worker (chrome.runtime.sendMessage).common.js holds shared constants/helpers (API version, host mapping,
share-table naming, RowCause decoding) used by both the popup and the
service worker.AccountShare.AccountId /
AccountAccessLevel vs. Invoice__Share.ParentId / AccessLevel). Both
are built correctly per object.*Share query throws an invalid-sObject error.
This is caught and surfaced as a banner, not a crash; access is then
explained purely via object-level permissions.UserRecordAccess query fails for a non-self target, the popup shows a
clear banner instead of failing outright. Self-inspection always works.GroupMember membership checked and called out when confirmed.cookies: read the sid session cookie for the Salesforce instance host.activeTab: read the current tab’s URL to detect the record context.storage: reserved for future use (no persistent data is currently
stored).host_permissions for *.salesforce.com and *.force.com: call the
Salesforce REST API on the instance host..lightning.force.com → .my.salesforce.com replacement.