Skip to content

feat(store): expose a listing's CRX public key to its owner - #46

Merged
ralyodio merged 1 commit into
mainfrom
feat/expose-signing-public-key
Jul 25, 2026
Merged

feat(store): expose a listing's CRX public key to its owner#46
ralyodio merged 1 commit into
mainfrom
feat/expose-signing-public-key

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Follow-up to #45.

The store holds the signing key and returned only the derived extension id. The public half is what a publisher needs in manifest.json's "key" field — without it, an unpacked install gets a per-machine id, so a locally-loaded copy and the store-packed .crx resolve to different extensions.

That blocks anything keyed off the id. The immediate case: an OAuth redirect URI (https://<id>.chromiumapp.org/), which coinpayportal validates by exact match (src/lib/oauth/client.ts:53), so the id must be pinned before a client can be registered at all.

Returned from the generate response, and on the listing for the owner only. Public keys aren't secret, but there's no reason to hand every visitor a listing's signing material.

tsc clean, 47/47 store tests.

🤖 Generated with Claude Code

The store generates and holds the signing key, and returned only the
derived extension id. But the public half is what a publisher needs in
manifest.json's "key" field — without it an unpacked install gets a
per-machine id, so a locally-loaded copy and the store-packed .crx
resolve to different extensions.

That matters for anything keyed off the id. The immediate case is an
OAuth redirect URI (https://<id>.chromiumapp.org/), which coinpayportal
validates by exact match, so the id has to be pinned before a client can
be registered at all.

Public keys are not secret; this returns it from the generate response
and on the listing for the owner only.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 7ab2dab into main Jul 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant