Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Kutt Extension has been flagged and disabled by Chrome Web Store #127

Open
adan89lion opened this issue Jul 10, 2022 · 18 comments
Open

Kutt Extension has been flagged and disabled by Chrome Web Store #127

adan89lion opened this issue Jul 10, 2022 · 18 comments

Comments

@adan89lion
Copy link

Description:
Kutt Extension has been automatically disabled (and locked) on my Edge browser on macOS on July 10th, 2022. Its page on Chrome Web Store has also been removed. (I've attached the screenshot of the alert on Edge browser).
Screen Shot 2022-07-10 at 12 46 42 PM

Device info:

  • OS: macOS 12.4 (Build 21F79)
  • Browser: Microsoft Edge 103.0.1264.51 (Official build) (x86_64)
@lukasgabriel
Copy link

I also noticed this yesterday on Edge.

The extension was also removed from the Firefox Addon Store: https://addons.mozilla.org/firefox/addon/kutt/

Can anyone provide info about whether this is a false positive and the extension can safely be re-enabled, or is there actually malware present? Is there any reason to also be worried about the main repo? I've shut down my self-hosted Kutt instance, just to be safe, until there's a response from the developers.

@moquito64
Copy link

Edge, Chrome, and Firefox all seem to have flagged this as containing malware. Hope we get more information soon. I have disabled this until further notice.

@hammady
Copy link

hammady commented Jul 12, 2022

How is this report related to the kutt server itself? It seems to be a different repo. We need a prompt explanation in case the kutt server has serious security issues and must be taken down.

@imakiro
Copy link

imakiro commented Jul 21, 2022

No update on the rejection from stores, bugfix releases ?

@abhijithvijayan
Copy link
Member

abhijithvijayan commented Jul 30, 2022

@poeti8 any ideas on what caused the rejection?

I will land a PR with all dependencies upgrade for the extension. Maybe that will help?

@Tnology
Copy link

Tnology commented Aug 28, 2022

Any update on this? I just got my selfhosted Kutt service up and running, and I'm super excited to use this (especially for custom domains like [my domain].com/apply alongside all of the other useful features).

@poeti8
Copy link
Member

poeti8 commented Sep 4, 2022

@abhijithvijayan This is the email I got from Firefox:

Details:

  1. Extensions defining a content security policy that allows eval ('unsafe-eval') are generally not allowed for security and performance reasons. ‘eval’ is only necessary in rare cases. Please use a different method or explain why eval is required in your add-on.
  • manifest.json line 45

In addition the following is required to complete the review:

  1. This version contains minified, concatenated or otherwise machine-generated code. Please provide the original sources, together with instructions on how to generate the final XPI. Source code must be provided as an archive and uploaded using the source code upload field, which can be done during submission or on the version page in the developer hub.

Please read through the instructions at https://extensionworkshop.com/documentation/publish/source-code-submission/ .

And for Chrome:

image

@abhijithvijayan
Copy link
Member

abhijithvijayan commented Sep 29, 2022

will migrate to v3 soon and we can go ahead with the release which would resolve this.

I will add the missing permission to the manifest as well so that this issue is rectified.

@poeti8
Copy link
Member

poeti8 commented Oct 16, 2022

@abhijithvijayan any updates on this?

@abhijithvijayan
Copy link
Member

this is blocked on the migration of the plugin i wrote to support webpack 5. https://github.com/abhijithvijayan/wext-manifest-webpack-plugin

Webpack has introduced major breaking changes and deprecated APIs relied on by the plugin. Once I manage to get it migrated, I will pick this issue up.

@poeti8
Copy link
Member

poeti8 commented Oct 27, 2022

Can't we use something else for now? Or take another approach?

@lukasgabriel
Copy link

@poeti8 You can still use the plugin just fine.

@brianantonelli
Copy link

No, you can't use it just fine. It's missing from the store.

@poeti8
Copy link
Member

poeti8 commented Nov 26, 2022

You can use it if you have already installed it.
I'll check with the issue myself soon, seems like @abhijithvijayan doesn't have free time.

@mtan93
Copy link

mtan93 commented Dec 4, 2022

You can install manually by downloading the chrome.zip release, enable developer mode and drop the extracted folder into the chrome://extensions page.

@poeti8
Copy link
Member

poeti8 commented Dec 20, 2022

Kutt is now back on Chrome Web Store: https://chrome.google.com/webstore/detail/kutt/pklakpjfiegjacoppcodencchehlfnpd

Firefox review is still pending.

@Lancaban
Copy link

Any updates on this yet?

@poeti8
Copy link
Member

poeti8 commented Oct 19, 2023

Any updates on this yet?

For FireFox? I submitted many times but each time they respond with something weird that I don't know how to fix. I should try again soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests