Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Task]: Extensions on AMO should display the verified email or domain associated with the developer account #15260

Open
1 task
hafta opened this issue Dec 20, 2024 · 0 comments
Labels
needs:info repository:addons-frontend Issue relating to addons-frontend repository:addons-server Issue relating to addons-server

Comments

@hafta
Copy link

hafta commented Dec 20, 2024

Description

This enhancement is filed to address the difficulty users have when wanting to confirm that an extension listed on https://addons.mozilla.org/ is from the identity/organization/company it lists. As an example, with the addon for Firefox iCloud password integration, it is difficult for users to have confidence this addon is from Apple. At present, our review process implicitly must be careful that an addon advertised as from company A is from an email address we know is from company A or is verified to be from company A in some way. Showing the verified email address or domain (caveats below) would add transparency to that effort and give users more confidence to install addons.

Caveats:

  • Showing the verified email address or domain would add transparency to the auditing/review task. It could be 1) opt-in so that individuals not wishing to display an email address on AMO would not have to OR 2) limited to the domain of the verified email address so as not to show the complete address.
  • There is some risk of confusion with email accounts. For example, @icloud.com email addresses are freely available and some might confuse an @icloud.com email address as conveying the account holder has an association with Apple.

VSCode example:
With the Microsoft VSCode editor extension library, some extensions are reported as having a verified domain. For example hovering over the blue checkmark on the extension page displays a popup message "LLVM has verified ownership for the domain llvm.org".

Acceptance Criteria

Milestones/checkpoints

Preview Give feedback

Checks

  • If I have identified that the work is specific to a repository, I have removed "repository:addons-server" or "repository:addons-frontend"

┆Issue is synchronized with this Jira Task

@hafta hafta added needs:info repository:addons-server Issue relating to addons-server repository:addons-frontend Issue relating to addons-frontend labels Dec 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs:info repository:addons-frontend Issue relating to addons-frontend repository:addons-server Issue relating to addons-server
Projects
None yet
Development

No branches or pull requests

1 participant