Badging API: How Web Apps Signal Updates
The Badging API lets installed web apps signal pending work without an intrusive notification. Learn how it works and what respectful badge design requires.
Thoughts on the web, privacy, faith, and how the browser fits into a thoughtful life.
The Badging API lets installed web apps signal pending work without an intrusive notification. Learn how it works and what respectful badge design requires.
A web app manifest gives websites an installable identity. Learn what changes after installation, what remains web-controlled, and how to judge the prompt.
Proximity Sensor API could let websites detect nearby objects. Learn what the draft exposes, why support is absent, and how privacy safeguards work.
Ambient Light Sensor API measures environmental brightness. Learn how rounded readings, permission, and policy controls limit privacy risk.
Device Orientation API exposes motion and rotation readings from phone sensors. Learn how permission, precision limits, and browser safeguards protect privacy.
Pointer Lock API lets sites hide the cursor and capture continuous mouse movement. Learn how activation, Escape, and raw input safeguards protect control.
The Window Management API supports multi-screen web apps. Learn what display details sites can request, why permission matters, and how placement risks are controlled.
The Screen Orientation API helps sites adapt and request rotation locks. Learn what it reveals, why background events are limited, and how accessibility stays protected.
The Gamepad API brings controller input to browser games. Learn what sites can read, why interaction is required, and how hardware details affect privacy.
The Fullscreen API lets sites expand video, games, and presentations. Learn why user activation matters, how spoofing risks arise, and how to exit safely.
Remote Playback lets a browser send media to TVs and speakers. See what a website can discover, how device selection works, and how to disconnect safely.
WebXR can power immersive VR and AR in a browser, but it also handles sensitive pose and spatial data. Learn what sites can sense and where user control begins.
WebTransport gives browser apps secure streams and low-latency datagrams. Learn what encryption protects, how sessions differ from WebSockets, and what remains visible.
Media Capabilities helps sites choose video and audio that should play smoothly and efficiently. Learn what it reveals and how capability checks affect privacy.
WebCodecs gives browser apps direct access to audio and video processing. Learn what it handles, where privacy risks appear, and why sandboxing matters.
Web Audio powers browser-based music, effects, and analysis. Learn how its audio graphs work, when microphone permission applies, and where fingerprinting enters.
Keyboard Lock helps fullscreen games and remote desktops receive special keys. Learn what changes, why permission matters, and how to get control back.
The EyeDropper API can return one color from anywhere on your screen. Here is what a website receives, what it cannot see, and when to cancel.
WebGPU helps websites render rich graphics and run computations. Here is what hardware information may be exposed, what it cannot access, and how to judge resource use.
Picture-in-Picture keeps a chosen video floating while you work elsewhere. Understand what a site can control, why the request needs interaction, and how to close it.
WebOTP can offer an origin-bound SMS code to a sign-in page on supported devices. Here is what a website can receive, what consent means, and where SMS security still falls short.
The Screen Wake Lock API can keep a useful page visible, but it is temporary and limited. Learn what it changes, when it ends, and how to stay in control.
The Contact Picker API lets people share selected contact details without exposing an entire address book. Here is how its one-off privacy model works.
Web NFC lets supported mobile browsers read and write nearby tags. Learn how permission, page visibility, and physical taps keep the feature under user control.
The Local Font Access API helps web design tools use installed fonts, but a font list can identify a device. Here is how permission and browser policy limit access.
The Battery Status API can reveal charging state, power level, and timing estimates. Here is why browsers limit that data and what the privacy tradeoff means.
Chrome’s Attribution Reporting API measured ad conversions without cross-site identifiers. Its retirement shows why private measurement needs more than clever code.
The Topics API tried to replace cross-site identifiers with broad browser-generated interests. Chrome is now retiring it. Here is what the experiment teaches.
Websites can estimate their own browser-storage usage and request stronger persistence. The numbers are useful, deliberately rough, and confined by origin.
The Cookie Store API replaces the old cookie string with asynchronous methods and service-worker events. Here is what changes—and what privacy rules remain.
The Network Information API gives some websites a rough view of connection speed and latency. Here is what that signal reveals and why context matters.
Some browsers share a rough device-memory tier with websites. Here is why the value is rounded, how sites use it, and how it can still aid fingerprinting.
Multiple tabs can race to update the same local data. The Web Locks API gives one site an orderly way to coordinate shared work without crossing origins.
Websites can tell when their own tab becomes visible or hidden. Here is what that signal reveals, what it cannot see, and why careful sites use it.
Learn what websites receive after camera permission, how active-use indicators work, and how to limit or revoke access after calls, scans, and verification.
A practical guide to what browser geolocation reveals, how one-time and continuous access differ, and when to deny or revoke location permission.
Passkeys feel personal, but websites do not receive your fingerprint or private key. Here is what stays on your device, what gets shared, and where sync changes the picture.
DNS over HTTPS closes a real privacy gap, but it does not make browsing anonymous. Understand what it encrypts, who still sees metadata, and where trust moves.
Voice search and dictation can make the web faster, more accessible, and easier to use. But the moment a microphone becomes part of a browser task, a privacy question follows: where does the audio…
A website that edits a photo, opens a project folder, or saves a document directly to your computer can feel almost like a desktop app. That convenience often comes from the File System Access API…
Web push can reach a browser after its tab is closed. Learn how subscriptions, service workers, encryption, and notification permission shape the privacy boundary.
FedCM puts the browser between a website and an identity provider. Learn what changes, what each party learns, and where consent still matters.
The Payment Request API creates a browser-controlled handoff at checkout. Learn what merchants can request, what users approve, and where privacy responsibility shifts.
Passkeys replace shared passwords with domain-bound cryptographic proof. Learn what stays on your device, what a website receives, and how to plan recovery.
The Idle Detection API can tell a permitted website when your device is active, idle, locked, or unlocked. The signal is coarse, but its timing can still reveal routines.
Web MIDI connects browser-based music tools to instruments and controllers. Learn what ordinary access and SysEx permission allow before connecting your gear.
Web Serial lets a browser read from and write to development boards, instruments, and other hardware. Here is how to use that access with care.
WebHID can connect a browser tab to controllers, remotes, and specialist equipment. Learn what the permission allows and how to keep device access deliberate.
From heart-rate monitors and smart lamps to sensors and small controllers, many nearby devices speak Bluetooth. Web Bluetooth allows a compatible website to communicate with some of them directly…
A browser tab usually feels separated from the hardware on your desk. WebUSB narrows that distance. On a supporting browser, a website can ask to communicate directly with a compatible USB device…
A website normally communicates with servers on the internet. Yet a page can also try to reach devices much closer to you: a home router, network printer, smart television, media receiver, or service…
Blocking third-party cookies sounds simple until a useful embedded service stops recognizing you. A sign-in panel, subscription widget, customer-support tool, or saved-preferences component may be…
Some pages seem to open the instant you click. That speed may come from more than a fast connection. A site can give the browser a set of hints about where you are likely to navigate next, allowing…
A modern webpage is rarely one self-contained document. Video players, maps, payment widgets, advertisements, and social embeds can all sit inside frames supplied by other companies. Some of those…
A share button on a website can look deceptively simple. Press it and your phone or computer opens a familiar panel of messaging apps, contacts, nearby devices, and other destinations. Behind that…
A message composed on a patchy connection, a form submitted just as Wi-Fi drops, or a photo upload interrupted by a train tunnel all create the same problem: the page has work to finish, but the…
When a website fails to load, its operator may see nothing. The request might have stopped during DNS lookup, connection setup, TLS negotiation, or response delivery—before the application's own…
Websites can store cookies, cached files, databases, service workers, and other local state in your browser. Usually, a site removes individual items with the same APIs that created them. The web…
Websites sometimes need to know which browser or device is visiting. A download page may offer the correct installer, a service may avoid a known browser bug, and a layout may adapt to mobile…
Closing a tab does not always end a page's network activity immediately. A website can ask the browser to queue a small data transfer just as the page moves into the background. The web feature…
Privacy choices often repeat from site to site. One page asks whether personal information may be sold or shared, another hides the choice behind several menus, and a third uses different…
Clicking a link usually feels like one clean action: you leave one page and arrive at another. Behind the interface, the browser may make more than the navigation request. A link can carry a ping…
Your browser carries a short list of language preferences into many web visits. That list helps sites choose readable content, spellings, date formats, and translations before you click a language…
A website does not need your location permission to learn something about where your computer is set up. Modern browsers expose a time-zone setting so pages can show appointments, deadlines, travel…
Your clipboard may hold more than the sentence you meant to paste. Understand when a website receives copied content and why read and write access differ.
Sharing a tab is not the same as sharing your desktop. A few choices before a call can keep unrelated messages, documents, and audio out of the stream.
Cross-Origin Resource Policy lets a server restrict where browsers deliver images, scripts, and other resources loaded without CORS.
OCSP stapling delivers fresh certificate-status evidence inside the TLS handshake, reducing extra network requests and direct responder lookups.
Cross-Origin Opener Policy controls whether tabs retain scripting connections. Learn how COOP isolates windows and where popup compatibility can break.
Certificate Transparency makes public TLS issuance auditable. Learn how browser checks and append-only logs expose certificates that should not exist.
Fetch Metadata headers describe request context so servers can reject suspicious cross-site traffic before it reaches sensitive logic.
Subresource Integrity lets browsers verify third-party scripts and styles before using them, reducing silent supply-chain changes.
Site isolation places different websites in separate renderer processes. Learn how that architecture reinforces the same-origin policy and browser sandbox.
Service workers sit between a website and the network. Learn how they enable offline pages, manage caches, update quietly, and affect troubleshooting.
Storage partitioning gives embedded services separate data spaces on different sites. It limits cross-site tracking while preserving useful integrations.
Content Security Policy gives browsers a rulebook for scripts and resources. Learn how CSP limits injected code without replacing secure development.
Extensions keep changing after installation. Learn how automatic updates, permissions, ownership changes, and signing affect the trust you place in them.
A link can tell its destination where you came from. Learn what referrer headers reveal, how browsers limit them, and where privacy risks remain.
Browsers can fetch likely next pages before you click. The result can feel instant, but it also creates tradeoffs in privacy, bandwidth, and control.
WebRTC can expose network information while connecting calls. Here is what browsers actually reveal, what a VPN changes, and which protections matter.
Understand how browsers separate website data by origin and how controlled mechanisms such as CORS allow safe cross-site communication.
Learn how browsers distinguish useful new windows and redirects from intrusive or deceptive navigation, and how to manage exceptions safely.
History, cookies, cache, passwords, and permissions are separate categories. Here is what clearing each one removes—and what remains elsewhere.
An HTTPS page can still request insecure HTTP resources. Here is why browsers upgrade or block mixed content and what those protections preserve.
An IP address is necessary for internet routing, but it also exposes network and approximate location clues. Here is what websites can—and cannot—infer.
Downloads move files beyond the browser’s usual boundaries. Here is how reputation checks, file types, signatures, and careful review reduce risk.
Query parameters can preserve useful page options—or identify campaigns and clicks. Here is how to recognize tracking fields and share cleaner links.
Browser password managers make unique logins practical. Here is how storage, domain matching, synchronization, and account security work together.
Browser sync moves bookmarks, settings, tabs, and sometimes passwords between devices. Here is how to use that convenience with clearer privacy boundaries.
Encrypted DNS protects domain lookups from observers on the network path. Here is what it hides, what remains visible, and why resolver choice matters.
Browser sandboxing limits what untrusted web content can reach. Here is how process separation and site isolation contain attacks.
Autofill makes forms faster, but it also handles personal information. Here is when websites receive filled data and how to keep control.
Browser caching reuses files you already downloaded, helping repeat visits feel faster. Here is how freshness, validation, and cache clearing work.
Third-party cookies can connect activity across websites. Here is how they work, why sites used them, and what modern browser protections change.
HTTPS secures the connection between your browser and a website. Its protection is vital—but more specific than many people assume.
Browser extensions can be genuinely useful—and unusually powerful. Here is how to read their permissions and decide what deserves access.
A fast, practical method for finding the collection, sharing, retention, deletion, and security terms that matter.
A look at how Noorani converts, localizes, updates, and presents the Hijri date across the browser.
Camera, microphone, location, and notifications should not become permanent approvals by accident. Here is how to review them with less friction.
Offline Quran access is more than caching a page. Noorani keeps verified text, search, translations, and selected audio close to the device.
Private browsing creates a disposable local session, not invisibility. Here is what disappears when it closes—and who can still see the activity.
Qibla direction is a local geometry problem, not an account service. Here is how Noorani calculates the bearing and handles location with restraint.
A browser can communicate without building another stream to check. Noorani separates essential alerts from engagement prompts—and leaves attention alone.
Tracker blocking changes more than advertising. It reduces invisible third-party requests, limits exposure, and can make ordinary pages feel calmer.
A page receives useful—and revealing—signals before it appears. Here is what travels in the first request and what those details mean for privacy.
Move the essentials without recreating years of browser clutter. Here is the careful way to bring bookmarks, passwords, and trusted tools into Noorani.
Why Noorani builds on Chromium—and how compatibility, security, and open source leave room for a more private, intentional browser.
A practical guide to browser fingerprinting, the signals websites combine, and the steps that reduce tracking beyond cookies.
Prayer times need a location, a date, and a calculation method. Noorani turns those inputs into a private, offline daily schedule—without sending your location to a server.
For most of the internet's history, software built "for Muslims" has meant a mediocre product with religious functionality bolted on. We built Noorani because that bar was set too low for too long. This is what we're making, and why we're writing about it.
Scheduled for the past — cron should publish me.