Fix WebSocket URL scheme and drop stale dev-only CSP override

BACKEND_WS_URL was set to https://, but new WebSocket() requires a
ws://wss:// scheme and throws a SyntaxError otherwise. Also removes
the Firefox-only CSP override that worked around Firefox upgrading a
plaintext ws:// dev connection to wss:// — now that the backend is
real wss:// behind TLS, there's nothing left to upgrade.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01Tn7uDYjTuZEbLPwpEiSCUw
This commit is contained in:
2026-09-08 12:02:44 +02:00
co-authored by claude
parent 3cc150508d
commit bee164ebf9
3 changed files with 8 additions and 25 deletions
+3 -15
View File
@@ -7,13 +7,11 @@ export default defineConfig({
modules: ['@wxt-dev/module-react'],
// Target Manifest V3 on both Chromium and Firefox (modern Firefox / Zen support it).
manifestVersion: 3,
manifest: ({ browser }) => ({
manifest: {
name: 'Nexa',
description: 'Your blockchain powered agent to help with your trading emotions.',
permissions: ['storage'],
// axiom.trade: the site adapter target. localhost:8080: the Nexa backend
// (dev only — swap/extend for the real backend host before shipping).
// Not 3000 — that's this extension's own Vite dev server port.
// axiom.trade: the site adapter target. The other entry is the Nexa backend.
host_permissions: ['https://axiom.trade/*', BACKEND_HTTP_URL + "/*"],
browser_specific_settings: {
gecko: {
@@ -21,15 +19,5 @@ export default defineConfig({
id: '[email protected]',
},
},
// Firefox's implicit default extension-pages CSP includes
// upgrade-insecure-requests, which silently rewrites our ws:// WS client
// connections to wss:// and breaks them against the plaintext local dev
// backend (no TLS in dev — see backend/CLAUDE.md). Declaring our own CSP
// (identical to the standard default otherwise) replaces Firefox's
// implicit one and drops that directive. Chrome doesn't have this
// behavior, so this is Firefox-only.
...(browser === 'firefox'
? { content_security_policy: { extension_pages: "script-src 'self'; object-src 'self'" } }
: {}),
}),
},
});