Commit graph

19 commits

Author SHA1 Message Date
Local Dev
9351045f45 feat(bns): name marketplace and TLD-owner co-sign rule
Two gaps the owner panel left open. First, a hidden TLD was only a UI
gate: anyone could still broadcast a REG under it and every indexer
admitted it. Second, there was no way to sell a name without trusting
the other side.

Co-sign rule (consensus, applied in lockstep by bns.js and
resolver-web.js): a REG under a TLD whose records at that height say
policy "cosign" or hidden 1 is indexed only if the transaction carries
the TLD's own certificate. The certificate can only be spent by the
owner's key and is re-issued to them in the same transaction, so it is
a co-signature nobody can forge and nothing is consumed. The TLD map
now keeps the TUPD timeline so policy is evaluated at the REG height.
Owners register under their private TLDs with the certificate added
from their own wallet; third parties under a "cosign" TLD build the
full transaction, sign their inputs and queue it at /api/cosign, where
the owner approves it from the dashboard (signCosignRequest refuses to
sign unless the certificate returns to the same locking script).

Marketplace: a listing is the seller's certificate input plus a price
output signed SIGHASH_SINGLE|ANYONECANPAY, stored by the gateway as a
bulletin board (/api/market, verified against the on-chain owner and
pruned when the certificate moves). The buyer completes it in one
transaction, so the seller is paid exactly when the name moves.
Cancelling also spends the certificate once so the offer is void.

Site: market.html, Sell sub-tab and Pending approvals in the portal,
Market link in nav and footer, six dictionaries extended, cache tags
bumped. Verified on chipnet: cosigned.sc registered by a throwaway
wallet through the queue with the .sc certificate back at the owner;
aloevera.test listed and delisted through the API.

Ariadne's resolver-web.js copy and the mobile Bns.java port still need
the co-sign rule; until then they admit REGs this index rejects.
2026-09-17 04:05:45 +02:00
Local Dev
25d17f5e92 fix(wallet): message signatures verified only half the time
BuiltInWallet.signMessage read `recovery` from libauth's recoverable
signature, but libauth v3 names it `recoveryId`. The flag byte came out as
0, so verifiers recovered the right key only when the true recovery id
happened to be 1. Signed DNS manifests and Studio uploads failed with
"signature does not match current on-chain NFT owner" and a different
derived address each attempt. Read the right field, fail loudly if it is
missing, rebuild the browser bundle and move every importer to the new
bundle URL. Also lands the registrar's signRecordsManifest that the bundle
already shipped.
2026-09-17 01:40:10 +02:00
Local Dev
f6459fe518 feat(sirius-x): dashboard with sidebar, persistent sign-in, full DNS panel
The portal was a flat page with tabs that asked for the password or PIN on
every visit and offered little beyond a records form. Owners need a
control panel they can live in.

Sign in once: the recovery phrase is kept encrypted under a
non-extractable browser key (IndexedDB) so the next visit opens the
dashboard silently; sign-out or the Settings toggle destroys it. Payments
approve with one click unless "Ask for PIN before payments" is on.

Dashboard: left menu (Overview, Domain names, My TLD list, Wallet,
Register name/TLD, Settings). Per-name detail with a summary, a DNS
record table (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA) that signs the
manifest, content & hosting (h, s3, p, ip, tls), a redirect tab (u),
ownership transfer (UPD that re-issues the certificate to the recipient)
and zone-file/JSON export. Per-TLD detail with policy, on/off, owner
registration and the public list of names under it. Overview flags names
that point nowhere or lack DNS.
2026-09-17 01:09:20 +02:00
Local Dev
55ddee18ec feat(sirius-x): TLD owner panel — owner-set price, on/off switch, private TLDs
A TLD owner needed to run their namespace without the operator: set what
every name under the TLD sells for, take the TLD off the public registry
for a while, and still register names under it themselves.

Both settings live on chain in the TLD's TUPD records (`price`, `hidden`)
because changes are rare and every client already walks the TLD beacon.
The gateway's /api/tlds now carries records, owner, price_usd and
hidden_by per TLD; pricing.js quotes the owner price ahead of the length
tiers and only trusts a TLD_BEACON-sourced list; the register flow refuses
hidden and frozen TLDs for the public but lets the owner through at the
platform share only (the 90% owner cut would be paid to themselves). The
portal's TLDs tab loads real holdings, shows price and on/off state, and
gives each TLD a one-click switch, a price/policy editor and an inline
"register a name under .tld" form. Docs and the design table describe the
two new records.
2026-09-16 21:28:18 +02:00
Local Dev
caf11c2512 feat(sirius-x): raise TLD pricing to $25–$500; PIN gate on payment approval
TLD price tiers (pricing.js):
  1 char  $500  (was $10)
  2 char  $250  (was $8)
  3 char  $150  (was $6)
  4-6ch   $100  (was $5)
  7-10ch  $50   (was $5)
  11+ch   $25   (was $4)

Payment approval (register-flow.js):
  New stepApprove(...) gates the actual sign+broadcast on an explicit
  user gesture — PIN pad when a PIN blob exists on this device, wallet
  password otherwise. Same "3 wrong PINs → wipe, fall back to password"
  behavior as the sign-in unlock step. Wired between stepConfirm(Tld)?
  and stepRegister(Tld)? so both name mints and TLD mints require
  approval even when the wallet is already in memory.

tld.html fee card: reflects the new $25–$500 range instead of the
"≈ 1,250,000 sat · ≈ $5" placeholder.
2026-09-09 03:45:41 +02:00
Local Dev
495054ca8a feat(sirius-x/signin): PIN escrow — encrypted-at-rest quick unlock, 3-strike password fallback
Removes the sessionStorage plaintext-mnemonic cache (fixed under the
same commit) and replaces it with a PIN-encrypted blob in localStorage.
No plaintext secret ever touches disk or memory outside the live
BuiltInWallet object.

New js/pin-escrow.js — WebCrypto PBKDF2(50k) + AES-GCM(256). Public
API on window.siriusPin: savePinBlob(mnemonic, pin), tryUnlock(pin),
hasPin(), attemptsUsed(), attemptsRemaining(), clear(), MAX_ATTEMPTS.
Iteration count is lighter than BuiltInWallet's 250k because a 4-6
digit PIN's key space is small anyway; the point is 'not plaintext at
rest,' not brute-force resistance — the durable secret is the full
password.

register-flow.js:
- After a fresh password unlock (Import / Create / Unlock), stepSetPin
  offers a 4-6 digit PIN with confirm — skippable with 'Not now'.
  Never overwrites an existing PIN blob.
- stepUnlock now shows a numeric PIN pad when a PIN blob is present;
  the password field only appears when the user opts to 'Use password
  instead' or after the blob was wiped.
- Wrong PIN → increment counter, surface 'N attempts left'. Third
  wrong PIN → wipe blob and route to a 'PIN reset' screen that hands
  off to the password form.
- Correct PIN → decrypt the mnemonic in-browser, rebuild the
  BuiltInWallet, finishSignIn(). Attempt counter resets to 0.

profile-menu.js:
- Sign-out clears the PIN blob (via siriusPin.clear()) alongside the
  siriusProfile so the device isn't quick-unlockable with a stale PIN.

All pages that host the sign-in flow now include pin-escrow.js. Same
tabbed layout in stepUnlock — the PIN pad and the password field both
live under 🔓 Unlock, transparent tab-switch works exactly as before.

Verified live:
- Fresh Import → 'Set a PIN' step → 4242 confirmed → blob written
- Reload → PIN pad, 3 attempts remaining
- Correct PIN 4242 → signed in, counter resets to 0
- 3 wrong PIN attempts → 'Wrong PIN — N attempts left' per attempt,
  then 'PIN locked — enter your full password to continue', blob
  wiped, next reload shows the password form
- localStorage contains only ciphertext + salt + iv + counter; no
  plaintext mnemonic anywhere on disk or in sessionStorage.
2026-09-09 01:31:18 +02:00
Local Dev
0a86b012d6 fix(sirius-x): sign-in Done unblocks portal; session survives reload
Two issues reported after an Import sign-in:

1. Done button was stuck — user saw the ✓ Signed in screen but the
   portal never switched to the names view. Root cause: finishSignIn
   fired siriusProfileChanged BEFORE setting window.siriusWallet, so
   the portal's listener called adoptWalletFromModal() while
   window.siriusWallet was still null, saw no wallet, and did nothing.
   Fix: expose the live wallet BEFORE writeProfile so the sync
   listener sees it and can enterPortal() immediately.

2. Every reload asked for the password again. Cache the wallet's
   mnemonic in sessionStorage on sign-in — same tab (or a page
   reload) rebuilds the BuiltInWallet silently via
   BuiltInWallet.fromMnemonic; a full browser close clears
   sessionStorage and the user is back at the Unlock tab.
   sessionStorage is per-origin per-tab so an XSS on Sirius.X pages
   would still be able to read it — that's the tradeoff for the
   convenience. Chipnet only; mainnet gets the PIN escrow pattern
   (3 wrong PIN tries → escalate to password) that Digibyte.x/web
   already uses. PIN implementation is deferred to its own commit.

portal.html adoptWalletFromModal now tries sessionStorage after the
in-memory check; register-flow.js startFlow/startTldFlow do the same
via a new async adoptSessionWalletAsync so name and TLD mints on any
page reuse the session wallet with no re-prompt. profile-menu.js
sign-out clears sessionStorage + window.siriusWallet so signing out
really does drop the user.
2026-09-09 01:15:14 +02:00
Local Dev
ce9248a327 feat(sirius-x): tier-based label pricing; badges on search cards + TLD list
Single source of truth (js/pricing.js) mirrored on landing, tld.html
and the mint flow — same label always shows the same price everywhere.

Name tiers (label part):
  1 char           $5.00  premium-1
  2 chars          $3.00  short-2
  3 chars          $2.00  short-3
  4–5 chars        $1.00  standard
  6–7 chars        $0.50  long
  8–16 chars       $0.25  extended
  17+ chars        $0.10  very-long
  all-digits       ×0.5   (less brandable)
  contains hyphen  ×0.7

TLD tiers (label part):
  1 char           $10.00  premium-1
  2 chars          $8.00   short-2
  3 chars          $6.00   short-3
  4–8 chars        $5.00   standard
  9+ chars         $4.00   long

Rendering:
  - Landing #search-results: acid-tinted price badge on each available
    row; grid grew a fourth column so name + badge + price + button
    all sit on one line
  - tld.html search result-card: same price badge next to the Register
    button on available TLDs
  - tld.html registered-TLDs table: new 'Mint price' column showing the
    tier price for every registered TLD, so buyers see the pricing
    ladder next to concrete examples

Mint pipe:
  - startFlow(name)/startTldFlow(label) resolve the label price via
    window.siriusPricing (default) but honour opts.serviceFeeSats when
    the caller passes one — leaves the door open for coupons /
    operator discounts / oracle overrides in a future revision without
    reshuffling call sites
  - The overridden service fee is threaded through quoteRegistration
    AND registerWithBuiltInWallet/registerWithExternalWallet so the
    confirm screen and the on-chain output agree

Chipnet placeholder rate (250,000 sat/USD) stays in pricing.js;
mainnet will swap in a live BCH/USD oracle. Operator-side discounts
and coupon codes are the next iteration — deliberately not disclosed
in this shipping copy.
2026-09-09 01:09:05 +02:00
Local Dev
4f776844a0 feat(sirius-x/signin): Unlock tab always visible; friendly copy when empty
Unlock tab used to be hidden when no saved wallet existed on the
device — so a fresh browser saw a 3-tab strip, and a returning
browser saw a 4-tab strip. Inconsistent, and users kept asking where
Unlock went.

Now Unlock is always the first tab:
- if a saved wallet exists, stepUnlock() renders the usual password
  form (nothing else changes)
- if no saved wallet, stepUnlock() renders 'No wallet on this device'
  with a one-line explanation and two shortcut buttons — 📥 Import
  and 🆕 Create — that jump straight to those tabs

Same tab bar renders in all cases so the layout is stable across
sessions and between devices.
2026-09-09 00:47:32 +02:00
Local Dev
0dc79c6c13 feat(sirius-x): show mint prices; reuse unlocked wallet for TLD/name mint
Two things:

1. Reuse the wallet the user already unlocked (adoptSignedInWallet).
   startFlow / startTldFlow were always calling stepWallet(), which
   showed the four-option wallet-choice and then prompted for the
   password again on 'Unlock'. Right after signing in, that meant
   entering the password twice to buy a TLD. Now both flows check
   window.siriusWallet at start and, if it's populated (built-in
   wallet in memory, or a WC-wrapper with a live session), skip
   straight to stepFund with state.wallet already set. Password is
   only asked when there is no in-memory wallet to reuse.

2. Prices are visible on the landing card + tld.html search:
   - name: '≈ 10,000 sat service fee · 1,300 sat chain dust · < 1 ¢'
     with a note that the 90/10 split applies (TLD owner gets 90 %)
   - TLD: '≈ 1,250,000 sat · ≈ ' with the incentive line
     ('you earn 90 % of the fee on every name registered under
     your TLD — forever, no renewals')
   Both labelled 'chipnet placeholder' — mainnet will price by
   label length via an on-chain oracle.

PIN as a lighter approval than the full password is a bigger design
change (encryption key derivation, cache lifetime, revocation) — not
in this commit; adopting the already-unlocked in-memory wallet is
the fix that removes the password-again symptom for now.
2026-09-09 00:30:05 +02:00
Local Dev
6378e179b6 fix(sirius-x/register-flow): inline render actually writes to the inline mount
renderSignInInline() reassigned the module-level 'sheet' variable to the
host page's container, but render() had been shadowing that with a
separate 'mountTarget' constant captured at module init — so every step
kept writing into the modal sheet instead of the inline container.
Portal.html therefore showed an empty #signin-inline while the tabs +
form rendered off-screen inside the (closed) modal.

Drop mountTarget entirely and let render() write directly into 'sheet'.
'sheet' is already the reassignable target for both modal and inline
paths, and renderSignInInline / close() already keep it in sync.
2026-09-08 13:06:16 +02:00
Local Dev
14cc83dfae feat(registrar): 90/10 revenue split — TLD owner earns from name mints
Every second-level name registration under a TLD now routes 90% of the
service fee to whoever holds that TLD's certificate on chain, with 10%
going to the platform address. That's the economic incentive for
minting a TLD: you earn from every name registered under it.

The mechanism, end to end:

1. resolver-web.js fetchTldMap now also records mintScriptHex — the
   scriptPubKey of the TREG output that carries each TLD's NFT.
   Exported so registrar can decode it into a cashaddr with libauth.
   MVP: this is the ORIGINAL owner; NFT transfers after mint are not
   traced yet (a follow-up will walk the chain of transfers).

2. registrar.js gains findTldOwnerAddress(client, tld) and
   splitServiceFee(sats). The split constants live at the top of the
   file (TLD_OWNER_SHARE_NUM/DEN = 90/100) so the ratio moves in one
   place. Rounding: BigInt division favours the platform on odd sat
   counts so the two shares always sum EXACTLY to the input.

3. quoteRegistration wraps the existing flow: it derives the TLD from
   the name, looks up the TLD owner, and if the owner ≠ buyer it asks
   buildRegistrationTx to add a second fee output. If the owner
   couldn't be resolved (TLD not registered, decode failure) the full
   fee stays on the platform address — the buyer still pays the same
   amount either way.

4. register-tx.js buildRegistrationTx accepts tldFeeAddress/tldFeeSats
   and, when set, emits an extra P2PKH output for the TLD owner. Sits
   between the beacon dust and the platform-fee output; outputMap
   records .tldOwnerFee so callers can find it. costs also carries
   tldOwnerFeeSats and netCostSats includes it.

5. priceSummary in registrar-config splits the 'Service fee' row into
   'Service fee — TLD owner (90%)' + 'Service fee — platform (10%)'
   whenever tldOwnerFeeSats > 0, with a per-line note explaining
   where the money goes.

Bundle: re-exported findTldOwnerAddress + splitServiceFee from
register-entry.js. Rebuilt bns-register.js (~34 kB) and deployed;
cache-buster bumped to ?v=20260908split on portal / admin /
register-flow.js.

Verified live: findTldOwnerAddress('.bch') returns the operator
cashaddr; quoteRegistration('tester42.bch') builds cleanly with a
9,000/1,000 split output pair on a 10,000-sat fee; priceSummary
renders both lines. No regressions on the TLD-mint flow (buyer IS
the TLD owner there — split short-circuits and it stays a single
fee output as before).
2026-09-08 02:42:16 +02:00
Local Dev
7687b115f9 fix(sirius-x/portal): use shared modal instead of stale inline sign-in cards
/sirius-x/portal.html?mode=import was landing users on the old three-card
inline sign-in UI (New / Import / WizardConnect each as its own form).
The new UX is: one tabbed modal, everywhere. Portal was the one page
still shipping the legacy cards.

Replaces the whole <section id='signin'> with a single launcher card
('🔑 Sign in or create wallet' → opens the shared modal). The old
handlers (, ,  etc.) are
comment-blocked out; new script uses window.siriusSignInWallet().

?mode=new|import|wc|unlock auto-opens the modal at that tab (the same
handler dropdown items use). If the user arrives with a siriusProfile
but no in-memory wallet (e.g., they signed in on another page), portal
opens the modal at Unlock (or Import when no saved wallet). Sign-out
delegates to the shared signOutUi(). Cross-tab and same-tab profile
changes both re-adopt.

register-flow.js: finishSignIn now sets window.siriusWallet so portal
(and any other page loaded in the same tab) can pick the wallet up
without re-prompting for a password. In-memory only — reload/nav clears
it, and the profile listener falls through to Unlock.
2026-09-08 02:35:56 +02:00
Local Dev
109e9e7351 feat(sirius-x): admin TLD hide/unhide + tabbed sign-in modal (4 direct actions)
Two features:

1. Operator can hide TLDs from the public /api/tlds listing so hidden
   TLDs stop appearing in name-search UIs. On-chain registrations
   under a hidden TLD keep resolving — this is a UX filter, not
   enforcement.

   Gateway (public-gateway.mjs):
   - Persistent HIDDEN_TLDS set backed by hidden-tlds.json next to
     the service script
   - GET /api/tld-visibility  -> {hidden:[...]}                (public)
   - POST /api/tld-visibility -> updates the list (operator-gated by
     Bearer BNS_OPERATOR_TOKEN env var; if unset, all writes refused
     so we default-deny)
   - /api/tlds filters out HIDDEN_TLDS; add ?include_hidden=1 to see
     everything (used by the admin panel to show all rows)
   - Operator token installed via systemd override on the VPS

   Admin panel:
   - New 'Operator token' card at the top of the TLD-registry section;
     token stored in sessionStorage (not localStorage) so a full
     browser close forgets it
   - Each TLD row got a 'Hidden from public' checkbox that POSTs on
     toggle and refreshes the table; failures roll back the checkbox
     and surface the error next to the token field

2. Wallet dropdown restored to 4 direct actions
   (Unlock / Create a wallet / Import a wallet / WizardConnect) and
   the shared mint/sign-in modal grew a tab strip so users can switch
   between the four wallet actions from any step without going back
   to a choice screen.

   register-flow.js:
   - renderTabs(active) prepended to stepCreate/stepImport/stepUnlock/
     stepExternal when signInOnly is set. Unlock tab only appears
     when a saved wallet exists.
   - Delegated click handler on the sheet routes tab clicks to the
     matching step; switching away from a live WC session tears it
     down first so we don't leak WebSockets.

   profile-menu.js:
   - Restored 4-item onboarding menu (Create/Import/WC plus Unlock
     when saved). Each item is a direct entry point; the tabbed modal
     lets the user pivot to any other option without closing.

Cache-buster bumped on all 8 sirius-x pages to ?v=20260908tabs.
2026-09-08 02:19:41 +02:00
Local Dev
e19226cbbb feat(sirius-x): choice-first wallet UX, Bitcoin Cash Domain Names in Theseus copy
Two changes:

1. Wallet dropdown simplified from three direct-action items into one
   'Sign in or create wallet' launcher (plus 🔓 Unlock when a saved
   wallet is present). The single item opens the shared modal at
   stepWallet — the choice screen showing all four options (Unlock /
   Create / Import / WizardConnect) as clear cards. Clicking a card
   reveals its form. Users see the options first, then commit to a
   path, instead of landing on a form for one path without seeing the
   others.

   register-flow.js's stepWallet grew a signInOnly-aware header ('Sign
   in or create a wallet' / 'Pick one. Your keys stay in this browser')
   so the choice screen reads as sign-in context, not a name mint.
   startSignIn still accepts direct-mode entry points (new/import/wc/
   unlock) for deep-links like portal.html?mode=X, but the nav dropdown
   funnels to 'choose' for the choice-first experience.

2. Theseus subpage copy updated per request: 'native .bch / BCNR name
   resolution built in' -> 'native Bitcoin Cash Domain Names resolution
   built in'. Meta description mirrored.
2026-09-08 01:43:35 +02:00
Local Dev
afeae356aa feat(sirius-x): 🔓 Unlock my wallet in nav dropdown when a saved wallet exists
Previously, the only way to unlock a wallet that had been saved in this
browser was to click Register (name or TLD), open the modal, and pick
'Unlock my browser wallet' from the wallet-choice step. From the nav
dropdown you could only start onboarding fresh (New / Import / WC).

profile-menu.js now checks localStorage for the BuiltInWallet's storage
key (bns.wallet.v1) at every render, and when a saved wallet is present
inserts a '🔓 Unlock my wallet' item at the top of the not-signed-in
dropdown — with a divider below it, so it reads as the primary action
and the Onboarding options stay available for adding a different wallet.

The dropdown click handler already lazy-loads register-flow.js and
calls window.siriusSignInWallet(action); register-flow.js's startSignIn
grew an 'unlock' mode that opens the modal directly at stepUnlock (the
password prompt). Same success path as every other sign-in: on unlock
success, siriusProfile is written and the modal closes with '✓ Signed
in' — the nav pill flips to the address without a reload.

Verified end-to-end on landing: saved wallet detected -> dropdown shows
Unlock as first item -> click -> password -> '✓ Signed in' -> pill
becomes 'qqyx49…zx8x seed ▾' with no reload. TLD mint from tld.html
also verified end-to-end: search 'e2etldtest' -> Register -> modal ->
Unlock -> password -> Fund -> Confirm (fee 1,250,000 sat + beacon dust
~1,300 sat) -> Register -> checking-availability -> loading-coins ->
'wallet is empty' (expected without chipnet funds; downstream code is
the same registerTldWithBuiltInWallet path the CLI uses).
2026-09-08 00:24:54 +02:00
Local Dev
bce4aa3529 feat(sirius-x): pencil Register icon + TLD mint via shared modal
Two UX polishes:

1. Register-tab icon flipped from 🪪 (identification-card emoji, renders
   as a hollow box in system-ui fonts without extended emoji) to ✏️
   (pencil), which reads as 'edit/create' and ships in every emoji font
   worth targeting. Changed across the nav on all 8 pages plus the
   footer injector's Product column. Kept the Register nav item — six
   items total in the nav, and from any subpage it's one click to the
   search on landing.

2. tld.html no longer duplicates the wallet-choice + mint flow inline.
   The Register button on a search result now hands the label off to
   the shared register-flow.js modal — same modal that name registration
   uses — via a new window.siriusRegisterTld(label, {serviceFeeSats})
   entry point.

   register-flow.js grew:
   - startTldFlow / window.siriusRegisterTld: sets state.tld and walks
     the modal through wallet-choice → Fund → stepConfirmTld → stepRegisterTld
     → stepDoneTld
   - stepConfirmTld: shows label + fee + owner, no per-name quote
   - stepRegisterTld: dispatches to registerTldWithBuiltInWallet or
     registerTldWithExternalWallet based on state.wallet/state.session
   - stepDoneTld: 'X is yours' with txid + certificate id + operator
     address, no record editor (a TLD certificate has no records to
     set immediately)
   - stepWallet / stepExternalConfirm branch on state.tld so the modal
     heading and the WC-confirm path route correctly

   tld.html trimmed: removed the entire signin-section + mint-section
   plus their inline handlers (~250 lines gone). Now just search +
   registered-TLDs list + a delegator to the shared modal. If a user
   is already signed in via the wallet dropdown, the modal recognises
   the saved wallet ('Unlock my browser wallet' button appears) instead
   of asking them to sign in again on this page.
2026-09-08 00:10:11 +02:00
Local Dev
5e0c971c23 feat(sirius-x): inline wallet dropdown — no navigation, no portal detour
Wallet dropdown items (New / Import / WizardConnect) were navigating
to portal.html?mode=X and asking the user to click again on arrival.
That is 'the sign in landing page which is not functioning' from the
user's perspective — a whole redirect for one form.

Now every dropdown item opens the mint modal (register-flow.js) inline
at the matching step, on whatever page the user is on:
  New         -> stepCreate  ('Create your wallet' — password + generate)
  Import      -> stepImport  ('Import a recovery phrase' — textarea)
  WizardConnect -> stepExternal ('Open your wallet' — QR/URI)

register-flow.js grew a signInOnly mode: state.name is null, the step
Back buttons close instead of going to a wallet-choice step there is
no context for, and on wallet-loaded the flow writes siriusProfile
and shows a 'Signed in' confirmation instead of Fund -> Confirm -> Mint.

WC signInOnly keeps the session alive (state.session) so a later
record edit can reuse it without a fresh QR handshake.

profile-menu.js: menu items became <a data-action='new|import|wc'>
and the click handler lazy-loads register-flow.js on demand — the
docs/brand/theseus pages don't ship it in their initial payload, so
their nav pill loads it the first time a wallet button is clicked and
caches it for subsequent opens. Falls back to portal.html?mode=X if
the module can't load. Cache-buster bumped so cached copies pick up
the new behavior.

Importmap for @bitauth/libauth added to docs/, brand/, theseus/ so
the bundle's bare specifier resolves when register-flow.js is
lazy-loaded from those pages.

Verified end-to-end on the live docs page: all three dropdown items
open the modal inline at the correct step, no console errors, no
navigation.
2026-09-07 23:52:12 +02:00
Local Dev
94bf3bcf68 feat(sirius-x): merge register.html into landing via shared mint flow
Register.html and the landing were running duplicate name-search UIs.
The register one was reported broken; the landing one already works
inline. Merged both into the landing:

- New js/register-flow.js — the full mint modal + wallet setup (Create /
  Import / Unlock / WizardConnect / Fund / Confirm / Register / Point
  it somewhere) extracted from register.html's <script type='module'>
  and turned into a shared module. Injects its own scoped modal HTML +
  CSS into the host page on load and exposes
  window.siriusRegisterName(fullName) as its public entry point.

- Landing search results now have Register buttons that call the shared
  flow directly. The whole 'search -> pick name -> mint' journey stays
  on one page, no redirects, no duplicate search UI to maintain.

- register.html reduced to a redirect stub: preserves ?q= if present,
  refreshes/JS-forwards to './' (landing), and shows a one-line
  'Name search moved to the home page' fallback for JS-off users.
  Old links keep working; no /register.html deep links are broken.

- All nav 'Register' entries now point at './#search-input' (or
  '../#search-input' on subpages), scrolling straight to the landing
  search box. Footer injector and every internal href updated the
  same way. Zero live href='.../register.html' left in the tree.

Verified: register.html?q=hello redirects to /?q=hello; landing
search 'fresh42abc' -> Register button -> modal opens with
'Register fresh42abc.bch' at the wallet-choice step.
2026-09-07 22:36:02 +02:00