Skip to content

feat: add native Safari Web Extension support - #1265

Closed
MaxiJuarez33 wants to merge 1 commit into
SevenTV:masterfrom
MaxiJuarez33:feat/safari-web-extension
Closed

MaxiJuarez33 wants to merge 1 commit into
SevenTV:masterfrom
MaxiJuarez33:feat/safari-web-extension

Conversation

@MaxiJuarez33

Copy link
Copy Markdown

Summary

Adds a native macOS Safari Web Extension build that packages the existing 7TV implementation instead of reimplementing emotes or chat behavior.

The Safari variant:

  • statically enables the existing Twitch, Kick, and YouTube site modules;
  • removes Chromium-only management, scripting, and activeTab permissions;
  • skips dynamic content-script registration, preventing duplicate registration after Safari service-worker restarts;
  • includes an Xcode host app and Safari Web Extension target with generic bundle identifiers;
  • adds local build, signing, release-verification, live-smoke, reload-stress, and performance tooling;
  • adds Safari coverage to the existing CI job without requiring Xcode in CI.

Security

  • Runtime messages and permission requests are validated and restricted to supported origins.
  • Login popup messages now validate both origin and source window.
  • The shared worker is loaded from the packaged extension URL instead of a page-controlled local-storage value.
  • Changelog HTML and packaged SVG insertion are sanitized.
  • Safari exposes only storage plus the three required site origins.
  • Native host and extension targets use App Sandbox and Hardened Runtime.
  • Generated extension resources, signing identities, team IDs, build products, and user-specific Xcode data are not committed.

The runtime dependency audit reports zero known vulnerabilities. The repository's older development toolchain still has known audit findings; modernizing that toolchain is intentionally left for a separate change so this compatibility PR remains reviewable.

Validation

  • yarn lint
  • yarn test:safari: 11 passed, 1 opt-in installed-app check skipped, 0 failed
  • yarn audit --groups dependencies: 0 vulnerabilities
  • production MV3 build passed
  • production MV2/Firefox build passed
  • Safari production build passed
  • native Release build passed with Xcode 27, targeting macOS 12+
  • nested app/extension signature validation passed
  • manual Safari validation on Twitch, including repeated page reloads
  • manual Safari validation of core 7TV emotes on Kick during development

The live WebDriver test is included but was not run because Safari remote automation was not enabled on the validation machine. YouTube and the complete advanced-feature matrix still need live Safari testing.

Distribution

This PR provides source-build support. It does not publish a notarized binary. Public downloadable releases would still require project-owned distribution signing, notarization, and an update policy.

Refs #1037 and discussion #57.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant