Closed Bug 1141068 Opened 9 years ago Closed 9 years ago

bogus File.can_be_signed method returns True for each xpi file

Categories

(addons.mozilla.org Graveyard :: Admin/Editor Tools, defect)

x86
macOS
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED
2015-04

People

(Reporter: magopian, Assigned: magopian)

Details

(Whiteboard: [qa-])

We only want to sign extensions, not all the files that have a ".xpi" extension. For example, complete themes also use the ".xpi" extension, but shouldn't be signed.

STR:
1/ submit a complete theme
2/ grant it a review (full or preliminary)
3/ download the file, unzip it
4/ verify that it's signed (but it shouldn't): there's the three files zigbert.sf, zigbert.rsa and manifest.mf in the META-INF folder
PR: https://github.com/mozilla/olympia/pull/471
Assignee: nobody → mathieu
Fixed in https://github.com/mozilla/olympia/commit/2845a406ae393a4c14a7c71dc82fe6ccafdc2294
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Whiteboard: [qa-]
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.