Flatsonar

SzafirHostProxy

by deno

Browser bridge for Szafir website signing

Broad permissions Unverified publisher GPL-2.0-only v0.5.6
Screenshot 1 of SzafirHostProxy Screenshot 2 of SzafirHostProxy Screenshot 3 of SzafirHostProxy Screenshot 4 of SzafirHostProxy Screenshot 5 of SzafirHostProxy Screenshot 6 of SzafirHostProxy

About

SzafirHostProxy is an open-source Native Messaging bridge for Szafir on Linux. It connects supported browsers with the Szafir signing environment so qualified signatures can work on supported websites. The GitHub repository publishes a proxy build that keeps copyrighted runtime components out of the Flatpak image. The bridge downloads required upstream runtime components during first-run setup instead of bundling them inside the image. Supported browsers include: - Mozilla Firefox, LibreWolf, Waterfox - Google Chrome, Google Chrome Dev - Chromium, Ungoogled Chromium Features: - Guides first-run setup with a welcome screen, component download step, and license screen. - Installs browser integration files for supported host and Flatpak browsers. - Shows a live status window that waits for browser activity and links to browser extensions. - Lets you remove installed browser integrations at any time. Browser integrations can be removed manually at any time by running: flatpak run pl.deno.kir.szafirhostproxy --uninstall - Mozilla Firefox, LibreWolf, Waterfox - Google Chrome, Google Chrome Dev - Chromium, Ungoogled Chromium - Prowadzi użytkownika przez pierwszą konfigurację z ekranem powitalnym, pobieraniem komponentów i akceptacją licencji. - Instaluje integrację przeglądarkową dla wspieranych przeglądarek systemowych i Flatpak. - Wyświetla ekran statusu oczekujący na aktywność przeglądarki oraz odsyłacze do rozszerzeń. - Pozwala w dowolnym momencie usunąć zainstalowaną integrację przeglądarkową.

Permissions

3 permissions weaken the sandbox. Flatsonar asks before installing.

  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • smart card readers
    --socket=pcsc
  • sets PATH: changes which libraries or plugins get loaded
    --env=PATH=/app/jre/bin:/app/bin:/usr/bin
  • Wayland display
    --socket=wayland
  • inter-process communication (needed for X11)
    --share=ipc
  • GPU acceleration
    --device=dri
  • owns its own bus name
    --own-name=pl.deno.kir.szafirhostproxy
  • system tray
    --talk-name=org.kde.StatusNotifierWatcher
  • notifications
    --talk-name=org.freedesktop.Notifications
  • access to ~/.mozilla
    --filesystem=~/.mozilla:create
  • access to ~/.librewolf
    --filesystem=~/.librewolf:create
  • access to ~/.waterfox
    --filesystem=~/.waterfox:create
  • access to xdg-config/google-chrome
    --filesystem=xdg-config/google-chrome:create
  • access to xdg-config/google-chrome-unstable
    --filesystem=xdg-config/google-chrome-unstable:create
  • access to xdg-config/chromium
    --filesystem=xdg-config/chromium:create
  • access to ~/.local/share/flatpak/overrides
    --filesystem=~/.local/share/flatpak/overrides:rw
  • access to ~/.local/share/flatpak/exports/share/icons
    --filesystem=~/.local/share/flatpak/exports/share/icons:ro
  • access to /var/lib/flatpak/exports/share/icons
    --filesystem=/var/lib/flatpak/exports/share/icons:ro
  • access to ~/.local/share/flatpak/app
    --filesystem=~/.local/share/flatpak/app:ro
  • access to /var/lib/flatpak/app
    --filesystem=/var/lib/flatpak/app:ro
  • access to ~/.var/app/org.mozilla.firefox
    --filesystem=~/.var/app/org.mozilla.firefox:create
  • access to ~/.var/app/io.gitlab.librewolf-community
    --filesystem=~/.var/app/io.gitlab.librewolf-community:create
  • access to ~/.var/app/net.waterfox.waterfox
    --filesystem=~/.var/app/net.waterfox.waterfox:create
  • access to ~/.var/app/com.google.Chrome
    --filesystem=~/.var/app/com.google.Chrome:create
  • access to ~/.var/app/com.google.ChromeDev
    --filesystem=~/.var/app/com.google.ChromeDev:create
  • access to ~/.var/app/org.chromium.Chromium
    --filesystem=~/.var/app/org.chromium.Chromium:create
  • access to ~/.var/app/io.github.ungoogled_software.ungoogled_chromium
    --filesystem=~/.var/app/io.github.ungoogled_software.ungoogled_chromium:create
  • network
    --share=network
  • keeps .java between runs
    --persist=.java
  • sets environment variable JAVA_HOME
    --env=JAVA_HOME=/app/jre

Who publishes this

Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.

  • pl.deno.kir.szafirhostproxy claims the domain kir.deno.pl; only its owner can prove that
    publisher:namespace

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.