Fix WebSocket URL scheme and drop stale dev-only CSP override
BACKEND_WS_URL was set to https://, but new WebSocket() requires a ws://wss:// scheme and throws a SyntaxError otherwise. Also removes the Firefox-only CSP override that worked around Firefox upgrading a plaintext ws:// dev connection to wss:// — now that the backend is real wss:// behind TLS, there's nothing left to upgrade. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Tn7uDYjTuZEbLPwpEiSCUw
This commit is contained in:
+3
-15
@@ -7,13 +7,11 @@ export default defineConfig({
|
||||
modules: ['@wxt-dev/module-react'],
|
||||
// Target Manifest V3 on both Chromium and Firefox (modern Firefox / Zen support it).
|
||||
manifestVersion: 3,
|
||||
manifest: ({ browser }) => ({
|
||||
manifest: {
|
||||
name: 'Nexa',
|
||||
description: 'Your blockchain powered agent to help with your trading emotions.',
|
||||
permissions: ['storage'],
|
||||
// axiom.trade: the site adapter target. localhost:8080: the Nexa backend
|
||||
// (dev only — swap/extend for the real backend host before shipping).
|
||||
// Not 3000 — that's this extension's own Vite dev server port.
|
||||
// axiom.trade: the site adapter target. The other entry is the Nexa backend.
|
||||
host_permissions: ['https://axiom.trade/*', BACKEND_HTTP_URL + "/*"],
|
||||
browser_specific_settings: {
|
||||
gecko: {
|
||||
@@ -21,15 +19,5 @@ export default defineConfig({
|
||||
id: '[email protected]',
|
||||
},
|
||||
},
|
||||
// Firefox's implicit default extension-pages CSP includes
|
||||
// upgrade-insecure-requests, which silently rewrites our ws:// WS client
|
||||
// connections to wss:// and breaks them against the plaintext local dev
|
||||
// backend (no TLS in dev — see backend/CLAUDE.md). Declaring our own CSP
|
||||
// (identical to the standard default otherwise) replaces Firefox's
|
||||
// implicit one and drops that directive. Chrome doesn't have this
|
||||
// behavior, so this is Firefox-only.
|
||||
...(browser === 'firefox'
|
||||
? { content_security_policy: { extension_pages: "script-src 'self'; object-src 'self'" } }
|
||||
: {}),
|
||||
}),
|
||||
},
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user