# How is AMO enfroncing rules without code review?

**URL:** <https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588>\
**Category:** addons.mozilla.org\
**Created:** [November 27, 2017, 9:20pm UTC](https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588 "2017-11-27T21:20:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreip](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/andreip/32/24181_2.png) [@andreip](https://discourse.mozilla.org/u/andreip)\
**Post date:** [November 27, 2017, 9:20pm UTC](https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588/1 "2017-11-27T21:20:10Z")

</div>

Hi,

I was looking at [this page](https://developer.mozilla.org/en-US/Add-ons/AMO/Policy/Reviews) and quite a lot of items there seem to be hard to translate in some automated tool. For example “Execute remote code”. How does an automated system know if a request just loads resources or it fetches some code to be executed? Or an even harder one “Cause harm to users’ data, systems, or online identities”.

> **[Add-on Policies](https://extensionworkshop.com/documentation/publish/add-on-policies/)**
>
> Get help creating & publishing Firefox extensions.

Thank you,  
Andrei

---

<div class="post-metadata">

**Author:** ![erosman](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/erosman/32/15447_2.png) [@erosman](https://discourse.mozilla.org/u/erosman)\
**Post date:** [November 27, 2017, 9:47pm UTC](https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588/2 "2017-11-27T21:47:17Z")

</div>

It is done in post review

[https://blog.mozilla.org/addons/2017/09/21/review-wait-times-get-shorter/](https://blog.mozilla.org/addons/2017/09/21/review-wait-times-get-shorter/)

---

<div class="post-metadata">

**Author:** ![andreip](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/andreip/32/24181_2.png) [@andreip](https://discourse.mozilla.org/u/andreip)\
**Post date:** [November 28, 2017, 8:37am UTC](https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588/3 "2017-11-28T08:37:23Z")

</div>

Hmm… Interesting. I missed that. And if the author refuses to offer non-obfuscated code?

---

<div class="post-metadata">

**Author:** ![erosman](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/erosman/32/15447_2.png) [@erosman](https://discourse.mozilla.org/u/erosman)\
**Post date:** [November 28, 2017, 1:47pm UTC](https://discourse.mozilla.org/t/how-is-amo-enfroncing-rules-without-code-review/22588/4 "2017-11-28T13:47:35Z")

</div>

> [@andreip](#):
>
> And if the author refuses to offer non-obfuscated code?

The request is made to upload sources within 7 days otherwise addon gets rejected.
