// Background script: performs the cross-origin fetch to the resolver, and drives the // toolbar badge. // // Why this exists: a content script running in the HTTPS reddit page CANNOT reach // http://localhost:8787 — reddit's Content-Security-Policy (and mixed-content rules) // block the request, so it never leaves the browser. The background page runs in the // extension origin (moz-extension://), which is exempt, and may fetch any host listed // in `permissions`. The content script therefore asks us to do the request. const api = globalThis.browser ?? globalThis.chrome; // Keep in sync with manifest.json `permissions` if you change host/port. const RESOLVER_URL = "http://localhost:8787"; async function resolveCandidates(candidates) { const r = await fetch(`${RESOLVER_URL}/resolve`, { method: "POST", headers: { "content-type": "application/json" }, body: JSON.stringify({ candidates }), }); if (!r.ok) throw new Error(`resolver http ${r.status}`); return r.json(); } api.runtime.onMessage.addListener((msg, sender) => { if (!msg || typeof msg !== "object") return; if (msg.type === "resolve") { // Returning a Promise makes sendMessage() in the content script resolve with it. return resolveCandidates(msg.candidates) .then((data) => ({ ok: true, data })) .catch((e) => { console.warn("[rsl/bg] resolve failed:", e && e.message); return { ok: false, error: String((e && e.message) || e) }; }); } if (msg.type === "badge") { const tabId = sender.tab && sender.tab.id; if (tabId != null) { const n = msg.count | 0; try { api.browserAction.setBadgeBackgroundColor({ color: "#1db954", tabId }); api.browserAction.setBadgeText({ text: n > 0 ? String(n) : "", tabId }); } catch (e) { /* badge is best-effort */ } } } });