feat: browser extension store readiness — P0/P1 fixes + privacy policy - #28
Merged
Merged
Conversation
…XML docs - CardTypeDetector: extract BinRanges nested class with 10 named constants for all BIN/IIN prefix ranges (MasterCard, Discover, JCB, Diners Club) - PasswordStrengthAnalyzer: extract TimeConstants nested class (SecondsPerMinute through SecondsPerMillennium) replacing magic literals in EstimateCrackTime() - PasswordGenerator: add MinPasswordLength=8 / MaxPasswordLength=128 constants - MergeService: add NoteHashSnippetLength=256 constant; extract MergeCollection<T>() generic helper — eliminates 4 identical merge loops (~44 duplicated lines) - Add Helpers/ListViewHelpers.cs with ShowSavedToast(TeachingTip, Action?) centralising identical toast boilerplate from 4 list-view code-behind files - Rename _res → _resourceLoader in all 9 view files for naming clarity - DashboardViewModel: add XML <summary> documentation to all 18 ObservableProperty declarations (greeting, stat cards, weekly activity, health, search) Build: 0 errors, 0 warnings. Tests: 176/176 pass. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Chrome: - Add CSP, author, homepage_url, full description, tabs permission - Fix content_scripts matches (https/http only) - Replace innerHTML SVG injection with DOMParser (CSP compliance) - Fix stale tab ID in onFill() — re-query active tab at fill time - Add rate limiting on Retry button - Set document.lang dynamically from navigator.language Firefox: - Add tabs permission, host_permissions, Gecko UUID for AMO - Same SVG/tab/retry/lang fixes as Chrome Both: - Add parseResponse() validation in all background.js handlers - Fix French gender typo in i18n.js (Aucune → Aucun) - Fix language fallback: Italian → English - Remove hardcoded lang="it" from popup.html Native Messaging: - Update Firefox extension ID from dev placeholder to AMO UUID - Split build-installer.ps1 into separate Chrome + Firefox manifests Privacy Policy: - Add docs/privacy/index.html (GitHub Pages: /PassKey/privacy) - Update docs/privacy-policy.md: add tabs permission, update date Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This was referenced May 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepares both browser extensions (Chrome + Firefox) for publication on Chrome Web Store and Firefox AMO. Resolves all P0 (blocking) and P1 (critical functional) issues identified in the pre-publication audit.
Chrome Extension — P0 fixes
content_security_policy(required by Chrome Web Store for MV3)author,homepage_url, full-lengthdescription"tabs"permissioncontent_scripts.matchestohttps/httponly (was<all_urls>)innerHTML = svgStringwithDOMParser-basedsetSvgIcon()helper —innerHTMLis blocked by the new CSP; 9 occurrences fixed in popup.jsFirefox Extension — P0 fixes
"tabs"permission (was causing silent runtime crash onbrowser.tabs.query())host_permissions(required for content script injection in MV3)passkey@passkey.localwith production UUID{3E08FACC-D43B-4B20-89E7-7888F6082E9D}required by AMOBoth extensions — P1 critical fixes
onFill()now re-queries the active tab at fill time instead of using a stale ID captured at popup openparseResponse()validation: added to all 7background.jsmessage handlers (was defined but never called)lang="it": removed frompopup.html; dynamicdocument.documentElement.langset fromnavigator.languageAucune identifiant→Aucun identifiantbtnRetrydisabled during reconnection attemptNative Messaging host registration
NativeMessagingRegistrationService.cs: updatedFirefoxExtensionIdto match AMO UUIDcom.passkey.host.firefox.json(dev manifest): same UUID updatebuild-installer.ps1: split single invalid combined manifest into two correct separate manifests (Chromeallowed_origins/ Firefoxallowed_extensions)Privacy Policy
docs/privacy/index.html— standalone HTML page served atpexatar.github.io/PassKey/privacydocs/privacy-policy.md: addedtabspermission, updated date to 2026-05-10Test plan
about:debugging→ verify no runtime crash on popup openpexatar.github.io/PassKey/privacyloads after PR merge🤖 Generated with Claude Code