Skip to content

Add goose-2fa extension - #31286

Draft
eachann1024 wants to merge 7 commits into
raycast:mainfrom
eachann1024:ext/goose-2fa
Draft

eachann1024 wants to merge 7 commits into
raycast:mainfrom
eachann1024:ext/goose-2fa

Conversation

@eachann1024

@eachann1024 eachann1024 commented Sep 19, 2026 •

Copy link
Copy Markdown

Description

Goose 2FA: a single-command local 2FA vault with list/grid, copy/paste, QR scanning, JSON import/export, and an optional shared file. English is the default; Simplified Chinese is an opt-in preference.

Updates for review

  • Self-contained vendor source fixes missing imports in the earlier submission.
  • HOTP delivery rejects stale/concurrent counters and does not treat another writer's identical content as a successful save.
  • Shared-file corrections use version-checked writes; a new data source never overwrites an existing file.
  • Added an English README and an initial-release changelog.

Validation

  • npm run build and npm run lint pass locally on macOS.
  • 20 focused file/vault tests pass. Raycast UI and cross-device syncing were not exercised.

Security and review notes

Shared JSON and exported backups contain plaintext 2FA secrets; users choose their own trusted location. The Swift helper is built from included source. Custom language switching may need adjustment under the Store's English-only guidance. Store screenshots are not included yet.

@raycastbot raycastbot added new extension Label for PRs with new extensions platform: macOS labels Sep 19, 2026
@raycastbot

Copy link
Copy Markdown
Collaborator

Congratulations on your new Raycast extension! 🚀

We're currently experiencing a high volume of incoming requests. As a result, the initial review may take up to 15 business days.

Once the PR is approved and merged, the extension will be available on our Store.

@eachann1024
eachann1024 marked this pull request as ready for review September 19, 2026 05:10
@greptile-apps

greptile-apps Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Medium risk] New two-factor authentication extension with local secret storage.

The PR is not ready to merge until the view command has the required screenshots.

Findings

  1. P2 This repository requires every extension with a view command to include a metadata/ folder with Raycast-style screenshots. All three new commands use mode "view" , but this extension has no metadata/ folder. Add the required screenshots. ▶
Fix with agent prompt
### Issue 1
extensions/goose-2fa/package.json:18-22
This repository requires every extension with a view command to include a `metadata/` folder with Raycast-style screenshots. All three new commands use `mode: "view"`, but this extension has no `metadata/` folder. Add the required screenshots.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

Goose 2FA adds a Raycast command for generating and delivering one-time codes, managing accounts, and importing or exporting authenticator data. An optional shared JSON file lets people use the same vault across devices, with controls for outside edits and file creation.

  • Adds searchable TOTP and HOTP codes with list or grid views and copy, paste, and typing actions.
  • Adds account and group management, trash and restore, QR scanning, and import previews.
  • Adds optional shared-file storage alongside Raycast LocalStorage, with conflict handling and version-checked writes.
  • Includes extension setup, vendor code, tests, a README, and an initial changelog.

Reviews (6) · Last reviewed commit: "Clarify standalone Raycast workflow and ..."

Comment thread extensions/goose-2fa/src/codes.tsx Outdated
Comment thread extensions/goose-2fa/src/lib/vault-store.ts Outdated
Comment thread extensions/goose-2fa/src/lib/vault-store.ts Outdated
Comment thread extensions/goose-2fa/src/manage-data.tsx Outdated
Comment thread extensions/goose-2fa/src/scan-qr.tsx Outdated
Comment thread extensions/goose-2fa/src/manage-data.tsx Outdated
Comment on lines +18 to +22
"name": "codes",
"title": "验证码",
"subtitle": "Goose 2FA",
"description": "搜索账户,复制、粘贴或真实输入动态验证码",
"mode": "view",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 This repository requires every extension with a view command to include a metadata/ folder with Raycast-style screenshots. All three new commands use mode: "view", but this extension has no metadata/ folder. Add the required screenshots.

Rule Used: What: Extensions with view-type commands must include a metadata/ folder containing Raycast-styled screenshots. Why: Professional metadata images ensure extensions appear polished and consistent in the Raycast store. Good: ``` my-extension/ ├── m... (source)

Prompt To Fix With AI
This is a comment left during a code review.
Path: extensions/goose-2fa/package.json
Line: 18-22

Comment:
This repository requires every extension with a view command to include a `metadata/` folder with Raycast-style screenshots. All three new commands use `mode: "view"`, but this extension has no `metadata/` folder. Add the required screenshots.

**Rule Used:** What: Extensions with view-type commands must include a `metadata/` folder containing Raycast-styled screenshots.  Why: Professional metadata images ensure extensions appear polished and consistent in the Raycast store.  Good: ``` my-extension/ ├── m... ([source](https://app.greptile.com/raycast/-/custom-context?memory=87059ac1-c601-487f-9f1c-bce8a3cb6209))

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Comment thread extensions/goose-2fa/package.json Outdated
Comment thread extensions/goose-2fa/src/lib/i18n.ts Outdated
@0xdhrv 0xdhrv added the difficulty:hard Review effort suggested by Review Hub (hard). label Sep 28, 2026

@0xdhrv 0xdhrv left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution 🔥 The shared-file sync design and the careful conflict / HOTP handling look thoughtfully built.

We already have extensions in the Store that cover a local two-factor code vault (search accounts, copy/paste codes):

Both let users keep OTP accounts locally and pull codes from Raycast. What this PR adds on top is shared JSON sync with uTools, QR screenshot scanning, HOTP, groups/trash, and direct typing via a Swift helper.

Could these land in one of the existing extensions instead? That keeps users in one place and makes them easier to discover. If there's a workflow that can't fit there (for example the uTools shared-file protocol), tell me which one and I'll decide quickly.

This would help avoid duplication and keep local 2FA vaults consolidated in one extension.
As mentioned in our extension guidelines here ↗

@0xdhrv
0xdhrv marked this pull request as draft October 1, 2026 05:01
@0xdhrv 0xdhrv self-assigned this Oct 1, 2026
- Add metadata/ Store screenshots (simulated renderings with mock data)
- Add eslint config, prettier config and dev dependencies so 'ray lint' passes
- Apply Prettier formatting; fix unused-variable and Title Case lint findings

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

difficulty:hard Review effort suggested by Review Hub (hard). new extension Label for PRs with new extensions platform: macOS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants