Enable new AOM restrictions on new weak signatures xpi installs on Nightly
Categories
(Toolkit :: Add-ons Manager, task, P2)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox127 | --- | verified |
People
(Reporter: rpl, Assigned: willdurand)
References
Details
Attachments
(1 file)
This bugzilla issue is tracking enabling the new AOM restrictions applied on install new xpi files signed only with weak algorithms in nigthly builds.
| Reporter | ||
Updated•1 year ago
|
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Updated•1 year ago
|
Comment 3•1 year ago
|
||
| bugherder | ||
| Assignee | ||
Comment 4•1 year ago
•
|
||
For QA: https://addons.mozilla.org/en-US/firefox/addon/colorzilla/ shouldn't be installable on Nightly between now and April 25.
Comment 5•1 year ago
|
||
Verified as Fixed. Tested on the latest Nightly (127.0a1/20240423214125) under Windows 10 x64, Ubuntu 22.04 LTS and macOS 11.3.1.
Attempting to install https://addons.mozilla.org/en-US/firefox/addon/colorzilla/ fails, confirming the fix.
addons.xpi WARN Download of https://addons.mozilla.org/firefox/downloads/file/595546/colorzilla-3.3.xpi failed: install rejected due to the package not including a strong cryptographic signature is logged to the browser console and AMO shows a banner stating Installation aborted because the add-on appears to be corrupt.
Description
•