Yes, it is quite possible to do that. One of my down the road goals is to add light obfuscation to the source code upon packaging. If anyone is motivated, they can break into _any_ source code and repackage.
I'd also like to add some form of checksumming, but again if they have access to the source code they can change anything they want to.
I guess my preferred solution for be for Electron to find a way to put the ASAR inside the main binary and find it there and then codesign that, I'm not sure why it hasn't happened yet AFAIK.
Note that I'm saying "Electron validating the signature" - not web app doing that, which I assume what you meant by "hand-rolling".
Yes, it is still possible — https://github.com/electron/asar