mirror of
https://git.zavage.net/Zavage-Software/search-with-chatgpt-powered-by-openai-extension.git
synced 2026-08-10 21:50:29 -06:00
Two verification passes, driving real Firefox 153.0.1 under Xvfb rather than reading docs, changed several load-bearing decisions. Added back: the keyboard shortcut now acts on selected text. activeTab adds no install-prompt line (confirmed by running Firefox's own formatPermissionStrings: ["activeTab","storage","menus"] yields msgs: []), and ext-commands.js grants activeTab before firing onCommand. Records the three failure shapes of executeScript, one of which resolves silently to [null] on parent-process about: pages, and that commands.getAll() reports a suggested_key as registered even when Firefox has silently overridden it. Rejected with evidence, in Appendix B: auto-submitting the prompt. The scheme authenticated navigation provenance when auto-submit needs text provenance, and a hostile page can smuggle ~16 KB of invisible instructions into info.selectionText. webNavigation.transitionType is not a security boundary either -- the marker is consumed on commit, so an uncommitted urlbar navigation leaves it armed for the next navigation to inherit (demonstrated at 10.47s), and its freshness guard is dead code. Prefill-only keeps the human checkpoint that makes the context menu safe. Also rejected: a bundled extension page as search_url (Firefox refuses to install), and browser.omnibox -- which works and needs no permissions, but moves the transmitter of search terms from Firefox to extension code, the change that puts data_collection_permissions ["none"] at risk. Declined to minimise AMO exposure. New Risk 6 records the residual AMO question and that it should be asked before submission, since a forced searchTerms declaration would add the install line this design exists to avoid. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| 2026-07-29-extension-options-design.md | ||