Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The approval process differs for extensions published to the Firefox and Chrome stores.

When submitting to the Firefox store you need to send them your un-minified, un-obfuscated source, along with step by step instructions on how to build. If you get big enough they do review the code in surprising depth. The hash of the compressed file pushed for release, also needs to match that of the compressed file the reviewer can build.

When submitting to the Chrome store this is not the case. You can push up minified, obfuscated code and that's what the reviewers have to work with.

I'm not familiar with why WASM needs extra permissions for Chrome extensions. It might be that the increased complexity of reviewing bytecode does indeed introduce more risk for the user. The permission request might just be the Chrome store pushing acceptance of that risk to the user?



> You can push up minified, obfuscated code and that's what the reviewers have to work with.

Minified maybe, but obfuscated is against the rules, for over 2 years now: https://www.zdnet.com/article/google-to-no-longer-allow-chro...

Chrome also does check the code manually, not sure if it's on the same level as Firefox though.


yup, you're absolutely right [1]

  Code Readability Requirements:

  Developers must not obfuscate code or conceal functionality of their extension. This also applies to any external code or resource fetched by the extension package. Minification is allowed, including the following forms:

  - Removal of whitespace, newlines, code comments, and block delimiters
  - Shortening of variable and function names
  - Collapsing files together
[1]:https://developer.chrome.com/docs/webstore/program_policies/




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: