alpheios-project / webextension

Alpheios Browser Extensions
ISC License
6 stars 2 forks source link

Firefox: Action Required: Add-on Policy Changes #325

Closed irina060981 closed 2 years ago

irina060981 commented 2 years ago

Hello,

 

You are receiving this email because you are listed as the developer of an extension for Firefox.

 

We will be updating our add-on policies effective December 1st, 2021. To summarize the changes that will go into effect:

 
  • We will no longer be accepting the collection of browsing activity data, unless it is part of the add-on’s primary function.
  • Add-ons with the sole purpose of promoting, installing, loading or launching another website, application or add-on are no longer permitted to be listed on addons.mozilla.org.
  • The use of encryption - standard HTTPS - is now always required when communicating with remote services.

We have also updated the language regarding the data disclosure, collection and management. If your add-on does not have a privacy policy listed on addons.mozilla.org, or your add-on does not show a consent prompt at first run of the add-on, we encourage you to read our updated policies and take action as necessary.

 

When the policies go into effect, they apply both to existing and future submissions on addons.mozilla.org

 

You can preview the policy and ensure your extensions abide by them to avoid any disruption.

 

Thank you for your help in keeping the add-ons ecosystem safe. If you have questions about these updated policies or would like to provide feedback, please post to this thread in our community forum.

 

Regards,

 

The Add-ons Team

addons.mozilla.org

irina060981 commented 2 years ago

We will no longer be accepting the collection of browsing activity data, unless it is part of the add-on’s primary function. We don't collect browsing activity data - if it means reading history, checking urls of other tabs

from @irina060981 the only problem here that for some reasons we have to get these permissions from a user. But I don't remember why do we have them.

from @balmas I don’t remember either. We could try removing the permission and having Monica do a full regression test, and if everything works, then not worry about it.

Add-ons with the sole purpose of promoting, installing, loading or launching another website, application or add-on are no longer permitted to be listed on addons.mozilla.org.

from @irina060981 We have activities - launching other site for using chinese vocabulary for translating in an iframe, but it couldn't be named as the sole purpose.

from @balmas I agree

The use of encryption - standard HTTPS - is now always required when communicating with remote services.

from @irina060981 I found one place that should be checked:

from @balmas We could just remove these settings. They aren’t used.

We have also updated the language regarding the data disclosure, collection and management. If your add-on does not have a privacy policy listed on addons.mozilla.org, or your add-on does not show a consent prompt at first run of the add-on, we encourage you to read our updated policies and take action as necessary.

from @irina060981 I din't find privacy policy listed on https://addons.mozilla.org/ru/firefox/addon/alpheios-reading-tools/ and we don't show any prompt on starting the extension. But if I understand right - it is not really necessary to have.

from @balmas We do have one. It’s at http://alpheios.net/pages/privacy-policy/. I was pretty sure I loaded it on the add-ons site, so it’s weird that it’s not there.

irina060981 commented 2 years ago

We will no longer be accepting the collection of browsing activity data, unless it is part of the add-on’s primary function. We don't collect browsing activity data - if it means reading history, checking urls of other tabs

Hope this is fixed

irina060981 commented 2 years ago

I believe that everything here is fixed (except publishing privacy policy - waiting for credentials)

So you can verify it after regression tests

monzug commented 2 years ago

Irina, do you mean that regression test should be enough to verify above fixes or is there any specific testing that I should be doing?

irina060981 commented 2 years ago

No, there is no specific testing here - all testing is to verify that everything is still working :)

monzug commented 2 years ago

Privacy police is in https://addons.mozilla.org/en-US/firefox/addon/alpheios-reading-tools/privacy/

irina060981 commented 2 years ago

Thank you - I didn't find it myself from user perspective :)

monzug commented 2 years ago

regression passed in Alpheios Reading Tools 3.4.1 build incr-3.4.x.20211201209 Alpheios Components 3.3.3-incr-3.4.x.20211125318 build i331-la-lat-update-lang.20211201494