Skip to content

Fix Chrome Web Store submission and Firefox release metadata for v2.7.0 #1051

Description

@PeterDaveHello

Summary

The v2.7.0 tagged release successfully built the release artifacts and submitted the extension to Firefox Add-ons and Microsoft Edge Add-ons, but the Chrome Web Store submission failed during OAuth authentication.

The Firefox extension submission itself succeeded, but the Firefox release metadata update did not run because the combined store submission command exited with an error after the Chrome failure.

Chrome Web Store

The tagged-release workflow failed while exchanging the configured Chrome Web Store refresh token for an access token:

[POST] "https://oauth2.googleapis.com/token": 400 Bad Request

{
  "error": "invalid_grant",
  "error_description": "Bad Request"
}

As a result, v2.7.0 was not submitted to the Chrome Web Store. The public Chrome Web Store listing is still on v2.6.1.

This most likely requires access to the Chrome Web Store publisher account and/or the OAuth credentials currently stored in the repository secrets.

@josStorer, could you please help check the Chrome Web Store credentials and either:

  • regenerate/update the Chrome Web Store OAuth refresh token used by GitHub Actions, or
  • manually submit chromium.zip from the v2.7.0 GitHub Release if refreshing the CI credential is not practical?

No credential values should be posted in this issue.

Firefox metadata

The Firefox package submission completed successfully:

[firefox] Submitting new version
Validation results: 0 errors, 27 warnings, 0 notices
✔ Firefox Addon Store

However, scripts/submit-stores.mjs only calls updateFirefoxVersionNotes() after the combined Chrome / Firefox / Edge submission command succeeds.

Since Chrome failed, publish-extension returned a non-zero exit code and the Firefox metadata update was skipped.

This means the v2.7.0 Firefox version may still have stale release notes and compatibility metadata even though the package itself was submitted successfully.

The repository already provides the dedicated Firefox metadata workflow, so v2.7.0 can be repaired independently by running:

Actions → Firefox metadata → Run workflow → version: 2.7.0

This does not resubmit the Firefox extension package.

Follow-up

Separately, the Firefox release-notes URL currently generated by the release script still points to the old josStorer/chatGPTBox repository namespace. That should be fixed independently so future metadata updates point directly to ChatGPTBox-dev/chatGPTBox.

Related release:
https://github.com/ChatGPTBox-dev/chatGPTBox/releases/tag/v2.7.0

Activity

  1. pullfrog commented on Aug 26, 2026

    @pullfrog
  2. josStorer commented on Aug 26, 2026

    @josStorer
    Member

    I confirmed that the Chrome Web Store credentials have expired, and the existing publishing API will soon be deprecated. I think I'll re-adapt to the new publishing API and create new credentials in recent days.

  3. josStorer commented on Aug 29, 2026

    @josStorer
    Member

    v2.7.0 has been reviewed and approved for release through manual submission

  4. PeterDaveHello commented on Aug 29, 2026

    @PeterDaveHello
    MemberAuthor

    Thanks! Let's see if it works in the next release!

  5. PeterDaveHello commented on Sep 6, 2026

    @PeterDaveHello
    MemberAuthor

    Looks like the same Chrome Web Store issue happened again with v2.7.1:

    https://github.com/ChatGPTBox-dev/chatGPTBox/actions/runs/34048814762/job/101528598376

    The Chrome OAuth token exchange still fails with invalid_grant, while the Firefox and Edge submissions completed successfully.

    Because the combined store submission exits with an error, the final GitHub Release publishing step was skipped, leaving v2.7.1 as a draft. The Firefox metadata update is also skipped for the same reason.

    For now, I'll manually publish the v2.7.1 GitHub Release and run the Firefox metadata workflow for 2.7.1.

    @josStorer, could you please manually submit chromium.zip for v2.7.1 again as a temporary workaround?

    I think we should also decouple GitHub Release finalization and Firefox metadata updates from individual store submission failures, so a Chrome publishing issue doesn't block otherwise successful releases.

  6. hamzahamidi commented on Sep 26, 2026

    @hamzahamidi
    Contributor

    An option for the Chrome step is my publish-to-chrome-web-store action. It uses Chrome Web Store API v2 and accepts a short-lived access token from google-github-actions/auth. With GitHub OIDC and Google Workload Identity Federation, each release can mint a 30-minute token instead of storing CHROME_REFRESH_TOKEN, CHROME_CLIENT_SECRET, and CHROME_CLIENT_ID in Actions secrets. The Google service account still needs access to the Chrome Web Store publisher account. The action also supports dry runs and checks listing and version state before upload. Since release:submit currently handles Chrome, Firefox, and Edge together, Chrome publishing would need its own step while Firefox and Edge remain on their current path. I maintain the action. If this fits the API v2 work, I can prepare an integration PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions