Skip to content

feat: browser extension store readiness — P0/P1 fixes + privacy policy - #28

Merged
pexatar merged 3 commits into
mainfrom
feat/browser-extension-store-readiness
May 10, 2026
Merged

pexatar merged 3 commits into
mainfrom
feat/browser-extension-store-readiness

Conversation

@pexatar

@pexatar pexatar commented May 10, 2026

Copy link
Copy Markdown
Owner

Summary

Prepares both browser extensions (Chrome + Firefox) for publication on Chrome Web Store and Firefox AMO. Resolves all P0 (blocking) and P1 (critical functional) issues identified in the pre-publication audit.

Chrome Extension — P0 fixes

  • Added content_security_policy (required by Chrome Web Store for MV3)
  • Added author, homepage_url, full-length description
  • Added "tabs" permission
  • Fixed content_scripts.matches to https/http only (was <all_urls>)
  • Replaced all innerHTML = svgString with DOMParser-based setSvgIcon() helper — innerHTML is blocked by the new CSP; 9 occurrences fixed in popup.js

Firefox Extension — P0 fixes

  • Added "tabs" permission (was causing silent runtime crash on browser.tabs.query())
  • Added host_permissions (required for content script injection in MV3)
  • Replaced development Gecko ID passkey@passkey.local with production UUID {3E08FACC-D43B-4B20-89E7-7888F6082E9D} required by AMO
  • Same SVG/CSP refactor as Chrome

Both extensions — P1 critical fixes

  • Stale tab ID bug: onFill() now re-queries the active tab at fill time instead of using a stale ID captured at popup open
  • parseResponse() validation: added to all 7 background.js message handlers (was defined but never called)
  • Hardcoded lang="it": removed from popup.html; dynamic document.documentElement.lang set from navigator.language
  • i18n fallback: changed from Italian to English for unsupported locales
  • French gender typo: Aucune identifiant → Aucun identifiant
  • Retry rate limiting: btnRetry disabled during reconnection attempt

Native Messaging host registration

  • NativeMessagingRegistrationService.cs: updated FirefoxExtensionId to match AMO UUID
  • com.passkey.host.firefox.json (dev manifest): same UUID update
  • build-installer.ps1: split single invalid combined manifest into two correct separate manifests (Chrome allowed_origins / Firefox allowed_extensions)

Privacy Policy

  • Added docs/privacy/index.html — standalone HTML page served at pexatar.github.io/PassKey/privacy
  • Updated docs/privacy-policy.md: added tabs permission, updated date to 2026-05-10

Test plan

  • Load Chrome extension in Developer Mode → verify SVG icons render correctly with CSP active
  • Load Firefox extension in about:debugging → verify no runtime crash on popup open
  • Test unlock flow: enter master password in popup → vault unlocks without leaving browser
  • Test fill after tab switch: switch tab, open popup, fill credentials → goes to correct tab
  • Test copy password → clipboard receives decrypted password
  • Verify pexatar.github.io/PassKey/privacy loads after PR merge

🤖 Generated with Claude Code

pexatar and others added 3 commits May 5, 2026 13:02
…XML docs

- CardTypeDetector: extract BinRanges nested class with 10 named constants
  for all BIN/IIN prefix ranges (MasterCard, Discover, JCB, Diners Club)
- PasswordStrengthAnalyzer: extract TimeConstants nested class (SecondsPerMinute
  through SecondsPerMillennium) replacing magic literals in EstimateCrackTime()
- PasswordGenerator: add MinPasswordLength=8 / MaxPasswordLength=128 constants
- MergeService: add NoteHashSnippetLength=256 constant; extract MergeCollection<T>()
  generic helper — eliminates 4 identical merge loops (~44 duplicated lines)
- Add Helpers/ListViewHelpers.cs with ShowSavedToast(TeachingTip, Action?)
  centralising identical toast boilerplate from 4 list-view code-behind files
- Rename _res → _resourceLoader in all 9 view files for naming clarity
- DashboardViewModel: add XML <summary> documentation to all 18 ObservableProperty
  declarations (greeting, stat cards, weekly activity, health, search)

Build: 0 errors, 0 warnings. Tests: 176/176 pass.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Chrome:
- Add CSP, author, homepage_url, full description, tabs permission
- Fix content_scripts matches (https/http only)
- Replace innerHTML SVG injection with DOMParser (CSP compliance)
- Fix stale tab ID in onFill() — re-query active tab at fill time
- Add rate limiting on Retry button
- Set document.lang dynamically from navigator.language

Firefox:
- Add tabs permission, host_permissions, Gecko UUID for AMO
- Same SVG/tab/retry/lang fixes as Chrome

Both:
- Add parseResponse() validation in all background.js handlers
- Fix French gender typo in i18n.js (Aucune → Aucun)
- Fix language fallback: Italian → English
- Remove hardcoded lang="it" from popup.html

Native Messaging:
- Update Firefox extension ID from dev placeholder to AMO UUID
- Split build-installer.ps1 into separate Chrome + Firefox manifests

Privacy Policy:
- Add docs/privacy/index.html (GitHub Pages: /PassKey/privacy)
- Update docs/privacy-policy.md: add tabs permission, update date

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant