Skip to content

fix(release): a Web Store zip beside the GitHub one, and one extension ID for both - #402

Merged
gololdf1sh merged 1 commit into
mainfrom
fix/391-webstore-zip-one-id
Sep 30, 2026
Merged

gololdf1sh merged 1 commit into
mainfrom
fix/391-webstore-zip-one-id

Conversation

@gololdf1sh

Copy link
Copy Markdown
Collaborator

Closes #391

…n ID for both

The Web Store refuses a manifest with a `key` ("key field is not allowed in
manifest"), and the release packed extension/ as it is, so no release could go
to the store. It also packed whatever sat in the folder — a host's handoff.json,
with its credentials, included.

The release now publishes two zips from the same tree: testomat-io-<v>.zip as
before, and testomat-io-<v>-webstore.zip, whose manifest has no key. Neither
takes handoff.json. Before Publish, a new step opens both and fails the run
unless they hold the same files, byte for byte, apart from the key.

The key in the repo becomes the store item's public key, so a GitHub copy
answers to the store's ID, amcnjlghmkkjfaajanfeghpgbjakdcka, instead of
mdjanaamdkpmnobcmoedleaiaifpnlbg: a store copy and a GitHub copy stop being two
extensions in one Chrome. Testeiya hashes the installed manifest's key, so it
follows by itself. Check the manifest now fails unless the key gives that ID,
and fails on an update_url, which marks a store install and would stop a GitHub
copy reading the host's file. The install guide names the zip to take.

A GitHub copy updated to this release is a new extension to Chrome: connect
and pin it again, and let unsent results go out first.

Probed by running the workflow's own run: blocks on a copy of the repo with a
handoff.json planted: both zips, 158 entries each, no handoff.json, the GitHub
key giving the store ID. A planted update_url, the old key, a Pack that keeps
handoff.json in one zip or both, or one that leaves the key in the store
manifest each fail the run before Publish. In Chromium the GitHub zip loads as
amcnjlghmkkjfaajanfeghpgbjakdcka and the store zip without a key.

Closes #391

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gololdf1sh gololdf1sh self-assigned this Sep 30, 2026
@gololdf1sh
gololdf1sh merged commit 6819b80 into main Sep 30, 2026
1 check passed
@gololdf1sh
gololdf1sh deleted the fix/391-webstore-zip-one-id branch September 30, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The release zip is refused by the Chrome Web Store: "key field is not allowed in manifest"

1 participant