Extension Manager:Addon Update Security: Difference between revisions

Jump to navigation Jump to search
(Rejigged security bits to hopefully make the requirements clearer)
Line 81: Line 81:


Add-ons that include a custom update URL and do not provide either of the previous methods of retrieving a secure update manifest must not mark themselves as compatible with Firefox 3. During install a check will be performed to ensure that it meets the requirements and Firefox will refuse to install any add-ons that do not. Add-ons that do not provide updates and so do not include and update URL, and add-ons that use the default URL for update from AMO will be allowed to install as normal.
Add-ons that include a custom update URL and do not provide either of the previous methods of retrieving a secure update manifest must not mark themselves as compatible with Firefox 3. During install a check will be performed to ensure that it meets the requirements and Firefox will refuse to install any add-ons that do not. Add-ons that do not provide updates and so do not include and update URL, and add-ons that use the default URL for update from AMO will be allowed to install as normal.
* How stringent do we be? Likely we cannot verify that the public key is valid without performing an update check there and then


When Firefox refuses to install such add-ons the error message will likely be very simple, quite probably the standard incompatible message. However extra information about the reasons for the installation failure will be logged from the extension manager in the usual way.
When Firefox refuses to install such add-ons the error message will likely be very simple, quite probably the standard incompatible message. However extra information about the reasons for the installation failure will be logged from the extension manager in the usual way.
canmove, Confirmed users
1,567

edits

Navigation menu