Fix AMO submission requirements: data collection permissions, innerHTML lint, source README

- Declare data_collection_permissions in browser_specific_settings.gecko
  (Firefox 140+/AMO validation requirement) to reflect wallet address,
  auth signature, and trading-identity data sent to the backend.
- Replace innerHTML assignments in blur-disable.ts and toast.ts with
  DOM construction (createElementNS/createElement) to clear the AMO
  linter's unsafe-innerHTML warning on content.js.
- Add build instructions to README.md for AMO's source code submission
  requirement, triggered by WXT/Vite's bundling and minification.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01HoMzqFw3d93hG6c9xB4thU
This commit is contained in:
2026-09-09 12:20:31 +02:00
co-authored by claude
parent cd56cf60cd
commit 891d561aaa
4 changed files with 103 additions and 14 deletions
+11
View File
@@ -17,6 +17,17 @@ export default defineConfig({
gecko: {
// Placeholder id for local/dev builds; replace before publishing to AMO.
id: '[email protected]',
// Firefox-required data collection disclosure (Firefox 140+ / AMO
// validation). Reflects what the extension actually transmits to the
// backend: wallet address + signature during Phantom sign-in
// (authenticationInfo, personallyIdentifyingInfo), and the wallet
// identity that ties the account to on-chain trading activity
// (financialAndPaymentInfo). See copilot/CLAUDE.md's "Backend
// connection" and "Wallet auth" sections.
data_collection_permissions: {
required: ['authenticationInfo', 'personallyIdentifyingInfo', 'financialAndPaymentInfo'],
optional: [],
},
},
},
},