Confirmed users
954
edits
No edit summary |
|||
Line 107: | Line 107: | ||
== Security Discussion Notes == | == Security Discussion Notes == | ||
'''From 4.7.2011:''' | |||
*possible changes to add-on dialogs and their impact | *possible changes to add-on dialogs and their impact | ||
Line 142: | Line 144: | ||
*AMO warnings (slows down firefox? has privacy policy?) | *AMO warnings (slows down firefox? has privacy policy?) | ||
'''From 5.25.2011:''' | |||
Add-On Features | |||
Items to be Reviewed: | |||
==Add-on Installation== | |||
Improve Add-on Installation: https://wiki.mozilla.org/Extension_Manager:Projects:Improve_Add-on_Installation | |||
Pri1: | |||
* move from modal to arrow panel | |||
* timer change | |||
- how is multiple at one being handled? | |||
* the dialogs will stack until a certain number then scoll (not z-index) | |||
** error handling still needs some work | |||
* Author not verified messaging changing for Add-ons from A.M.O | |||
** Need verificaiton that reviews have been done to a level that supports this security statement | |||
** too much reliance on automated scan for this check, more in depth analysis is needed | |||
** Concept is good | |||
Pri2: | |||
* download before install and ask -or- ask then download | |||
** old: ask then download, changed in FX4 to download then ask for several reasons (ie. compatiblity) | |||
* ask then download is the prefeered method from a security prespective | |||
Issues: | |||
* possible API changes to support messaging for reviewed, "good" add-ons | |||
Followups: | |||
* need a set of heuristics for making decisions on how the add-on experience flows | |||
* review error handling when complete | |||
==Third Party== | |||
Ensure user accepts add-ons installed by third-party apps: https://wiki.mozilla.org/Extension_Manager:Projects:Third_Party_Add-on_Warnings | |||
* if install w/o restart, tab closes | |||
* old style: continue changes to "you have to restart" | |||
* can also be enabled form add-ons manager | |||
== Designs == | == Designs == |