postulo-firefox: the browser extension for Firefox and its forks #18

Closed
opened 2026-09-05 12:29:17 +00:00 by tiagoagueda · 0 comments
Owner

Observation

postulo-firefox - webextension to firefox based browsers

Shape

Everything in #17 applies — same code, same options page, same capture flow, same privacy statement — and Firefox adds what follows. Firefox has supported Manifest V3 since version 109, with differences that are exactly the kind of thing that costs a day if nobody wrote them down:

  • Background. Firefox does not run a service-worker background; it runs an event page (background.scripts). Current Chromium tolerates a manifest that lists both keys, so one manifest can serve both if checked at build time; otherwise web-ext builds one per target from a shared source.
  • Identity. browser_specific_settings.gecko.id is required for a Manifest V3 extension to be signed and to keep its storage across updates.
  • Namespace. browser.* with promises. Chromium's chrome.* returns promises in Manifest V3 as well, so globalThis.browser ?? chrome covers both without a polyfill.
  • Host permissions are opt-in. In Firefox's Manifest V3 the origins in host_permissions are not granted at install; the person grants them in the extension's permission panel or the extension requests them at run time. The instance-origin request at configuration time from #17 is therefore not optional here, and the extension must behave when it is refused — say what it needs and why, and do nothing else.
  • Signing is mandatory. Release Firefox refuses unsigned extensions. Signing goes through addons.mozilla.org, listed or unlisted ("self-distributed"), at no cost; only Developer Edition and Nightly can load unsigned builds, which is fine for development and useless for anyone else.
  • Android. Firefox for Android installs extensions from addons.mozilla.org, so a capture from a phone — where a lot of job browsing happens — comes almost free once the listing exists. Worth testing the popup at phone width.
  • Forks. LibreWolf, Zen, Waterfox and Floorp install from the same listing.

Classification

Enhancement. A separate build (or repository); changes nothing in Postulo. Not breaking.

Depends on

#17 for the shared code. #12 for the read features, as there.

Open questions

  1. Listed on addons.mozilla.org (findable, reviewed) or unlisted (signed, distributed from the project's own pages)? Proposal: listed; the review is a feature for the person installing it.
  2. Is Android a supported target from the first release, or "works if it works"?
## Observation > postulo-firefox - webextension to firefox based browsers ## Shape Everything in #17 applies — same code, same options page, same capture flow, same privacy statement — and Firefox adds what follows. Firefox has supported Manifest V3 since version 109, with differences that are exactly the kind of thing that costs a day if nobody wrote them down: - **Background.** Firefox does not run a service-worker background; it runs an event page (`background.scripts`). Current Chromium tolerates a manifest that lists both keys, so one manifest can serve both if checked at build time; otherwise `web-ext` builds one per target from a shared source. - **Identity.** `browser_specific_settings.gecko.id` is required for a Manifest V3 extension to be signed and to keep its storage across updates. - **Namespace.** `browser.*` with promises. Chromium's `chrome.*` returns promises in Manifest V3 as well, so `globalThis.browser ?? chrome` covers both without a polyfill. - **Host permissions are opt-in.** In Firefox's Manifest V3 the origins in `host_permissions` are *not* granted at install; the person grants them in the extension's permission panel or the extension requests them at run time. The instance-origin request at configuration time from #17 is therefore not optional here, and the extension must behave when it is refused — say what it needs and why, and do nothing else. - **Signing is mandatory.** Release Firefox refuses unsigned extensions. Signing goes through addons.mozilla.org, listed or unlisted ("self-distributed"), at no cost; only Developer Edition and Nightly can load unsigned builds, which is fine for development and useless for anyone else. - **Android.** Firefox for Android installs extensions from addons.mozilla.org, so a capture from a phone — where a lot of job browsing happens — comes almost free once the listing exists. Worth testing the popup at phone width. - **Forks.** LibreWolf, Zen, Waterfox and Floorp install from the same listing. ## Classification Enhancement. A separate build (or repository); changes nothing in Postulo. Not breaking. ## Depends on #17 for the shared code. #12 for the read features, as there. ## Open questions 1. Listed on addons.mozilla.org (findable, reviewed) or unlisted (signed, distributed from the project's own pages)? Proposal: listed; the review is a feature for the person installing it. 2. Is Android a supported target from the first release, or "works if it works"?
tiagoagueda added this to the 0.2.0 milestone 2026-09-05 12:29:17 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Postulo/postulo#18
No description provided.