Firefox 浏览器附加组件
  • 扩展
  • 主题
    • 适用于 Firefox
    • 字典和语言包
    • 其他浏览器网站
    • 适用于 Android 的附加组件
登录
附加组件图标

NostrComments 版本历史 - 25 个版本

NostrComments 作者: NostrComments

目前尚无评分
0 / 5 星
5
0
4
0
3
0
2
0
1
0
NostrComments 版本历史 - 25 个版本
  • 小心旧版本!显示这些版本是为了测试和参考目的。您应该始终使用附加组件的最新版本。

  • 最新版本

    版本 23.3.1

    发布于 2026年9月18日 - 103.45 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    This is a security update. Please install it.

    The comment panel is drawn inside the page you are reading, and a website's own scripts could reach into it. A malicious page could have pressed "Show private key" and read your key out of the panel, or written a comment and posted it under your name, without you clicking anything.

    Everything that touches your key or publishes something now requires a real press from you — one that a page cannot imitate. That covers showing, copying, importing, replacing and deleting your key, posting, sharing, deleting and voting, publishing your name, choosing your signer, tipping, switching the extension off for a site, and muting a word or a person. The last two matter for a different reason: a website could otherwise have switched the comment layer off on its own pages, or hidden every comment that mentioned it.

    Being straight about what this does not do: the panel still lives inside the page, so a page can still read the thread, read what you are typing, and read your key if you choose to display it while you are on that page. Moving these controls into the extension's own window is the real fix and it is next. If you keep a key in the extension and you would rather not wonder, you can rotate it in Settings; there is no sign anyone did this to anyone.

    Also fixed: relays that ask you to identify yourself (NIP-42) have not worked since 23.2.0 — neither reading nor posting. They work again. And if you had a key stored here, Settings could not show it to you; now it can.

    If you find this useful, a review on this page genuinely helps people find it. There is no company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载 Firefox 并安装扩展
    下载文件
  • 较早版本

    版本 23.3.0

    发布于 2026年9月14日 - 102.16 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    This release makes sharing more useful and fixes one setting.

    When you share your own comment to your Nostr feed, the note now includes a link that opens the whole thread in any browser. Most people who see your note do not have NostrComments, and until now the link took them to the page, where they saw no thread at all. Now they can read it without installing anything.

    If you turned off "extra relays" in Settings, tabs you already had open kept using them until you reloaded. The setting now applies to every open tab straight away.

    If you find this useful, a review on this page genuinely helps people find it. There is no company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.2.3

    发布于 2026年9月13日 - 101.83 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    This release fixes three faults in the part of the extension that talks to relays, all of them
    dating from 23.2.0.

    If a relay closed the connection — after a restart, or when your laptop woke up — nothing
    reconnected. Comments and reply notifications stopped for that page until you reloaded it, and
    nothing said so. That was the most serious of the three.

    When you posted a comment, it is sent to every relay you have configured at once. Their answers
    could be confused with one another, so a relay that was briefly busy looked like a relay that never
    replied, and the second attempt came far too late or not at all. Comments now reach more relays,
    which is the whole point of having several.

    A relay that is no longer there now says so in Settings within seconds instead of after half a
    minute.

    Also: the relay status line is easier to read, and the consent screen and the relay list now ignore
    clicks that did not come from you — a website's own scripts could previously reach into the panel.
    Nothing changes in how you use it.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.2.2

    发布于 2026年9月13日 - 100.17 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    The toolbar button now opens the comment panel.

    Until now it only told you whether the extension was active. Clicking it now opens the panel on the page you are looking at, and clicking again closes it. This matters on sites that remove the floating button from the page — some do, deliberately or as a side effect of how they manage their own page — because the toolbar is outside the page's reach.

    Also fixed: on a page that was already open when the extension was installed or updated, a second floating button could appear on top of the first, which looked like a stray unread counter stuck behind the button.

    No new permissions. Nothing changed about what is stored, what is sent, or which relays are used.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.2.1

    发布于 2026年9月12日 - 99.06 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    This release is a maintenance one, and all of it is under the hood.
    
The part of the extension that connects to relays — new in 23.2.0, and the reason comments load on sites like x.com — has been gone over line by line. Five things came out of that. The one you could have noticed: after the browser had put the extension to sleep, the first attempt to load a thread could report that you had not accepted the disclosure screen when you had, and then quietly fix itself. It no longer happens.
    
On Firefox, the panel now names Attest wherever it suggests a signing extension. nos2x, which it used to name, is a Chrome extension and was never installable here.
    
Nothing changed about what is stored, what is sent, or which relays are used. No new permissions.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.2.0

    发布于 2026年9月11日 - 98.02 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    NostrComments now works on sites that used to show an empty panel. Some sites — x.com is the best known — forbid the page from connecting anywhere they have not listed themselves, and Firefox applied that rule to NostrComments as well, so no comments could load there. The connections are now made by the extension itself, where the site has no say. If anything behaves differently, Settings has a switch to go back.
    
You can choose whether your comments carry a small label saying they were written with NostrComments. It stays on unless you turn it off, and turning it off only affects what you publish from then on.
    
Generating a new key, or deleting yours, now clears the previous identity's page list and reply notifications straight away. Until now they stayed until the page was reloaded, which made it look as if the old key was still in use.
    
For people without a Nostr signer, the welcome screen now suggests Attest instead of nos2x-fox, which has a publicly known flaw that lets a website read the PIN protecting your key. Attest is made by the same developer as NostrComments.
    
Nothing about what is stored, what is sent, or which relays are used has changed.
    
If you find this useful, a review on this page genuinely helps people find it. There is no company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.1.0

    发布于 2026年8月19日 - 90.55 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Replies to your comments are now something you can follow. The panel kept a count and little else; it now keeps who replied, what they said and where, in a "Replies to you" list in Settings. A reply about a page links back to that page. A reply to one of your Nostr notes is labelled as such and points at a client where you can answer it.

    The badge counts page replies only. Everything still appears in the list, but a conversation you have to go elsewhere to join no longer interrupts you here.

    Comments now carry a client tag identifying the extension, so it is possible to tell how much it is actually used rather than how often it is installed.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.11

    发布于 2026年8月18日 - 88.52 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    You can now share a comment to your feed. A comment here is only visible to somebody who has this
    extension and opens the same page — which is what keeps comments out of the timelines of everyone
    who follows you, but it also means a comment cannot travel. Your own comments now carry a Share
    button that posts an ordinary Nostr note with the comment and a link back. Behind a confirm, per
    comment, never automatic.

    Settings lists the pages you have commented on. A comment is filed under one address, so once you
    had written it and moved on there was no way back to it.

    Reply notifications now say where. They used to count replies and leave you to work out which page,
    and to vanish after five seconds. They name the pages, link to them, and stay until you dismiss
    them.

    Repeated comments from one key fold into one line, with the rest a click away. Nothing is blocked
    and nothing is hidden. A comment posted twice is left alone, and so is the same short phrase from
    two different people.

    And the panel is readable throughout. It carried two shades of blue and the one used for text was
    below the contrast standard the rest of it meets; there is one now. Checking that turned up 191
    more failures in parts of the panel that had never been measured — unreadable headings in dark
    Settings, the buttons under every comment — all of them fixed.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.8

    发布于 2026年8月17日 - 84.61 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Pictures can now wait until you ask for them.

    A picture in a comment is fetched from wherever the person who posted it chose, which tells that
    server your IP address — and nobody moderates a thread here, so a thread can carry a picture you
    would not have chosen to open. Settings now has "Load pictures automatically". Turn it off and
    every picture, avatars included, waits behind the name of the host it would come from, with a
    button to fetch it. Clicking one fetches that one and nothing else.

    It stays on by default, because a thread of grey boxes is a worse thing to read. And it is a
    decision point rather than a shield: somebody who clicks is exactly as exposed as before.

    The panel also tells you which address a thread belongs to, when that is not obvious. Anchors and
    tracking parameters are stripped so everyone reading the same page lands in the same
    conversation, and when that differs from your address bar a line above the thread says so. It
    decides who you are talking to.

    And nothing in a profile can point your browser at your own network any more. Verifying a NIP-05
    name, and loading a picture, both accept plain domain names only — a bare address like
    192.168.1.1 no longer gets through.

    A correction to the last release. 23.0.7 said a site can no longer act on what you type. That was
    too strong: its shortcuts no longer fire on what you write, but a page that sets out to listen can
    still read your keystrokes and can read the comment box directly. Closing that needs the box moved
    out of the page entirely, which is planned. Until then, treat what you type on a site you do not
    trust as visible to it.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.7

    发布于 2026年8月16日 - 81.5 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Typing now works on sites that have their own keyboard shortcuts.

    The comment panel draws itself inside the page you are reading, so every key you pressed in the
    box also travelled through whatever that page was listening for. On a site that reads the space
    bar and cancels it — most Nostr clients do, and so do GitHub, YouTube and Reddit — your spaces
    simply vanished as you typed.

    Two things were wrong behind that. Keys are no longer handed to the page at all, so a site can
    no longer act on what you write in a comment. And where the page cancels a key before the panel
    can see it, the character is put into the box afterwards.

    Nothing about what is stored, what is sent, or which relays are used has changed.

    If you find this useful, a review on this page genuinely helps people find it. There is no
    company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.6

    发布于 2026年8月16日 - 80.85 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    The small "note" label, on comments carried over from the old Nostr note format, now uses the same grey as everything else in the panel. It came from a different grey scale with a blue tint, which in dark mode turned it into a blue pill on an otherwise neutral panel — and on light backgrounds left it fainter than the contrast standard the rest of the interface meets.

    Nothing about what is stored, what is sent, or which relays are used has changed.

    If you find this useful, a review on this page genuinely helps people find it. There is no company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.5

    发布于 2026年8月16日 - 80.85 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Two changes, both about the panel being straight with you.

    Settings no longer leaves your lists where the website can read them. Your relays, the people
    and words you have muted, and the sites you switched NostrComments off on were written into
    the page when you opened Settings — and left there afterwards. The list of disabled sites is
    the awkward one: it names other sites you visit, sitting in the page of one of them. All four
    are cleared when you close Settings, and again when you close the panel.

    And if you already have a Nostr signer, the welcome screen now offers to connect it. It used
    to show links to install Alby or nos2x even when one of them was already running, while the
    only way to actually use it was the Connect button, which did not say so.

    Nothing about what is stored, what is sent, or which relays are used has changed.

    If you find this useful, a review on this page genuinely helps people find it. There is no
    company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.4

    发布于 2026年8月15日 - 79.21 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Your Nostr public key is no longer sitting where the website can read it.

    The panel writes your identity — the status line, your npub, and your profile name — into
    the page it is running on. Until now it did that on every page you visited, whether or not
    you ever opened the panel. Your public key is meant to be public, but that is not the same
    as letting every site you read recognise you by it without you posting anything.

    It is now written only while the panel is actually open, and removed again when you close
    it. Nothing about what is stored, what is sent, or which relays are used has changed.

    If you find this useful, a review on this page genuinely helps people find it. There is no company behind it and no advertising budget — word of mouth is the whole distribution.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.3

    发布于 2026年8月15日 - 78.5 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Your dark/light choice is now remembered once, for every website, instead of separately per
    site. It also no longer lives in the storage of the page you are visiting — where any site
    could read it and tell that you have NostrComments installed.

    Buttons and text that were too faint have been made readable. White on the blue used for
    Post, Connect Nostr and every other primary button measured 3.00:1, below the accessibility
    floor of 4.5:1; the blue is now deeper. The same has been done for the hints in Settings,
    the message shown for an empty thread, and the connection status, which was hard to read on
    the dark theme.

    The floating button keeps its original colour: it carries an icon rather than text, and
    that has a different, lower requirement which it already met.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.2

    发布于 2026年8月15日 - 77.58 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Some websites block NostrComments from reaching your relays through their own security
    policy. On Firefox this silently emptied the panel — you were told nobody had commented,
    when in fact the connection was never allowed. The panel now says the site is in the way,
    and the relay list marks those relays as blocked. The connection still cannot be made;
    this release stops it being a mystery.

    Pictures in comments and profile avatars no longer tell their host which page you are
    reading. They load from whichever server the poster chose, and until now every one of
    those requests named the page — so an avatar revealed where its owner's readers were
    going. They also load only as they scroll into view.

    An empty thread now says which kind of empty: everything hidden by your own mutes, no
    search results, or genuinely nothing yet. And the Muted users and Disabled sites lists in
    Settings stay on screen when they are empty, so you can see that nothing is muted instead
    of guessing.

    Searching returns a flat list of matches, so a reply containing your search term is no
    longer hidden because the comment above it does not.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 23.0.0

    发布于 2026年8月14日 - 73.3 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Fixed: switching off your signer extension while a tab stayed open left the Post button
    dead with nothing on screen. Disabling nos2x or Alby does not remove window.nostr from a
    page that is already loaded, so the request was accepted and never answered. The panel now
    says so after four seconds and points at the way out, instead of going quiet for a minute.

    Fixed: two relays that stopped answering, dropped from the defaults back in 22.59, were
    never removed from lists that had been edited by hand — a saved list is only written when
    you change it, so it froze with them in it. They are retired once now. A relay you removed
    on purpose stays removed, and Settings tells you when this happened.

    Also, from 22.63, which was pulled shortly after release and never reached most installs:
    the comment button can be moved to any of the four corners and remembers that per site, and
    it is smaller than it was.

    A signer request that never comes back now times out in the userscript build too, and
    messages you need to act on stay on screen instead of disappearing after a couple of
    seconds.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.633

    发布于 2026年8月14日 - 71.42 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Automatic rollback based on version [22.63].

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.632

    发布于 2026年8月13日 - 70.46 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Automatic rollback based on version [22.62]. Schnorr security measures too strict, causing some people to not being able to comment. Working on it.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.63

    发布于 2026年8月12日 - 71.43 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    The floating button is smaller, and you can now choose which corner it sits in, per site. Bottom right is where most chat widgets and back-to-top buttons live, so a button parked there eventually covers something; Settings offers all four corners and remembers the choice for that site only.

    That section also reads in a more sensible order: moving the button is offered before switching the extension off, which used to come first.

    Internally, the Schnorr signature implementation is now tested against the complete official BIP-340 vector set rather than a single vector — including the ten that must be rejected. No behaviour changed; it is now measured.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.62

    发布于 2026年8月11日 - 70.47 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Adds a toolbar button. Everything this extension shows is drawn into the page, and that cannot happen without permission for the page — so without it, the extension showed nothing at all and could not explain why. The button needs no such permission: it says whether the extension can see pages and can ask for access.

    Fixes three ways a private key could be lost or exposed. Pasting an nsec into the comment box published it to public relays; it is now refused there and everywhere else except the import field. "Show private key" shows an nsec instead of raw hex. And choosing a browser signer that later stops answering no longer strands you — the key stored in the extension is offered instead.

    Generating a key no longer opens Settings and shows a warning about losing your identity. It connects and lets you comment; the backup prompt moved to just after your first comment, where it is about something real.

    Install links now point at addons.mozilla.org rather than a source repository, and the signer buttons show which signer is actually in use.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.61

    发布于 2026年8月10日 - 64.92 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Adds a field in settings to publish a display name, so comments from a key made here no longer show as npub1abc…. An existing profile is merged rather than replaced.

    Fixes four ways a key or a profile could be lost: the onboarding button could generate over a stored key without asking; an external signer that switched account could have its profile overwritten; an old profile left on a slow relay could overwrite a newer one; and a signer prompt approved a moment too slowly threw away what you had written.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.60

    发布于 2026年8月9日 - 61.13 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    This one is about which key speaks for you.


    If you chose Key stored here and then reloaded a page with Alby or nos2x
    installed, the panel connected as the signer's identity instead. Silently. Your
    own key was never touched — it sat in storage the whole time — but you could post
    under an identity you had not chosen and nothing said so.

    On load the panel asked only whether a signer was installed, not which one you had
    picked. Your choice is honoured now. Only when you have never made a choice does
    the presence of a signer decide, which is a reasonable default for a first run.

    Worth checking after updating: open ⚙ Settings and confirm the Signing section
    shows the source you expect.


    After switching to your signer and reloading, switching back was refused with that
    message — while your npub was displayed two lines above it. The check asked whether
    the key was loaded, not whether it existed. It asks storage now.


    Alby and nos2x add themselves to the page asynchronously. The panel looked once,
    allowed 800ms, and if that look came back empty it never tried again for the rest
    of the page — pressing the signer button in Settings by hand was the only way out.
    It now allows 2.5 seconds and keeps looking for about thirty.


    Switching back to a stored key loaded it but left "Show private key" showing an
    empty box. Introduced by the fix in v22.54 that took the key out of the page's
    reach; corrected here.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.59

    发布于 2026年8月9日 - 60.21 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Two of the six relays included by default were not responding and have been
    replaced. Your own relay list is untouched — this only affects fresh installs.

    The same relay could also appear twice in the list if it was added once with a
    trailing slash and once without, which quietly doubled the connections made on
    every page. Addresses are now normalized, and existing lists are cleaned up.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.58

    发布于 2026年8月9日 - 59.62 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    Settings now says what each of your relays is actually doing.

    A relay that never answers looked exactly like a relay with nothing to say. Both
    give you a thinner, slower thread, and nothing explained why — connections failed
    silently, retried a few times and gave up without a word.

    Each relay in Settings now carries a line: "answered · 12", "answered · nothing
    here", "no answer", or "gave up". Answering with nothing and never answering are
    different problems, and they were indistinguishable before.

    This came out of finding that three of the six relays shipped by default did not
    respond from one machine on one afternoon. The default list is deliberately
    unchanged — that measurement was taken after hours of hammering those relays, and
    one of the three had been serving data minutes earlier. Rather than change what
    everyone gets based on one bad sample, the extension now shows you the answer for
    your own machine.

    源代码遵循 MIT 许可证 发布

    下载文件
  • 版本 22.57

    发布于 2026年8月9日 - 58.41 KB
    适用于 firefox 142.0 及更高版本, android 142.0 及更高版本
    You can now reply to ordinary Nostr notes from the panel. A note that links to the
    page is a Nostr conversation rather than a comment written here, so your reply is
    published as an ordinary Nostr note threaded onto it — which is also why the reply
    box now tells you, before you type, that it will reach your followers and how many
    people it will notify.

    Notes are easier to tell apart from comments: they have their own border and a
    slightly recessed card instead of looking identical to a comment with a small
    label. Tapping that label explains what a note is, which previously only worked
    with a mouse.

    Two fixes from a security review of everything that changed since v22.53. The
    small button that re-enables the extension on a site you switched it off on could
    be hidden by that site's stylesheet, which left no way to turn it back on there.
    And an error while composing a post could leave the Post button stuck with no
    explanation.

    源代码遵循 MIT 许可证 发布

    下载文件
转至 Mozilla 主页

附加组件

  • 关于
  • Firefox 附加组件博客
  • 扩展工坊
  • 开发者中心
  • 开发者政策
  • 社区博客
  • 论坛
  • 报告缺陷
  • 评价指南

下载

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

最新版本

  • Nightly
  • Beta

商用版 Firefox

  • Enterprise

社区

  • Connect
  • Contribute
  • Developer

关注

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • 隐私
  • Cookie
  • 法律

除非另有注明,否则本网站上的内容可按知识共享 署名-相同方式共享 3.0 或更新版本使用。