theseus/settings-preload.js

112 lines
8 KiB
JavaScript
Raw Normal View History

const { contextBridge, ipcRenderer } = require("electron");
contextBridge.exposeInMainWorld("cfg", {
get: () => ipcRenderer.invoke("settings-get"),
set: (key, value) => ipcRenderer.invoke("settings-set", key, value),
engines: () => ipcRenderer.invoke("search-engines"),
addEngine: (eng) => ipcRenderer.invoke("add-engine", eng),
removeEngine: (id) => ipcRenderer.invoke("remove-engine", id),
setEngineEnabled: (id, on) => ipcRenderer.invoke("set-engine-enabled", id, on),
setEngineOrder: (ids) => ipcRenderer.invoke("set-engine-order", ids),
Theseus: shield green polish, picker→Search section, toggle-vs-remove Three follow-up asks from the previous ship: 1. Shield "secure" colour bumped from #4fd1a5 (mint) to #3fb950 — the GitHub-style saturated green, matches the +N/-N diff colour the user pointed at as reference. 2. Engine-picker "Search settings…" now opens the Search section directly instead of General. New IPC channel `focus-section` fires from main after picker-open-settings, carried through settings-preload as `onFocusSection`, and the settings.html sidebar handler exposes showSection(sec) so any section can be focused programmatically. Works for both a fresh settings tab (fires on did-finish-load) and an already-open one (fires immediately). 3. Toggle no longer removes an engine from the list. Two-tier state: INSTALLED (visible in the Settings list) and ENABLED (toggled on in the toolbar dropdown). Toggling off keeps the row visible with an .off class (dimmed 55%). Right-click any row → new context menu with "Remove from list" is what actually removes an engine (built-ins go back to the catalog, customs are dropped entirely). Model changes: - New settings.installedEngines persistent array (defaults to DEFAULT_ENABLED). enabledEngines becomes a subset of installedEngines. - isInstalled(id) helper; allEngines() carries `installed: bool` alongside `enabled`. - New IPC `remove-from-list` (right-click action); exposed as removeFromList in settings-preload. - set-engine-enabled now also INSTALLS when enabling (the catalog "+ Add" flow), preserves installed state when disabling. - add-engine (custom URL) auto-adds the new id to enabledEngines too. - remove-engine (custom delete) prunes from enabledEngines as well. - Never-empty invariant kept: enabledEngines falls back to ["duckduckgo"] if everything gets removed. Settings UI: - Enabled list shows all INSTALLED engines (was: only enabled), rendered with toggle reflecting enabled state; rows carry data-builtin so the context menu picks the right remove IPC. - Catalog panel and Discover-more pane filter on !installed instead of !enabled — a toggled-off engine stays in the enabled list, not here. - Ctxmenu is a floating .ctxmenu div; closes on outside click / Escape. - .eng.off dims the row and mutes the name colour. Preview harness stubs updated to include the `installed` field on every engine + `removeFromList` and `onFocusSection` no-op stubs so _settings-preview.html renders the new UI accurately.
2026-08-06 01:41:31 +02:00
removeFromList: (id) => ipcRenderer.invoke("remove-from-list", id),
// Storage: wipe browsing data on demand. Pass any subset of
// { cookies, cache, storage, history }.
clearBrowsingData: (opts) => ipcRenderer.invoke("clear-browsing-data", opts),
// Password vault. All calls return { ok, ... } | { ok: false, err }.
// Renderers never see the seed / vault key / master password past setup/
// unlock; get() returns plaintext only in explicit response to a user click.
pwStatus: () => ipcRenderer.invoke("password-status"),
pwSetup: (masterPassword, seedSource) => ipcRenderer.invoke("password-setup", { masterPassword, seedSource }),
pwUnlock: (masterPassword) => ipcRenderer.invoke("password-unlock", masterPassword),
pwLock: () => ipcRenderer.invoke("password-lock"),
pwList: () => ipcRenderer.invoke("password-list"),
pwGet: (id) => ipcRenderer.invoke("password-get", id),
pwAdd: (entry) => ipcRenderer.invoke("password-add", entry),
pwUpdate: (id, patch) => ipcRenderer.invoke("password-update", id, patch),
pwRemove: (id) => ipcRenderer.invoke("password-remove", id),
pwGenerate: (spec) => ipcRenderer.invoke("password-generate", spec),
// Quick-unlock PIN. pinSet proves the master password in main before
// wrapping it; pinUnlock opens Theseus's own PIN / password prompt.
pinStatus: () => ipcRenderer.invoke("vault-pin-status"),
pinSet: (pin, masterPassword) => ipcRenderer.invoke("vault-pin-set", { pin, masterPassword }),
pinClear: () => ipcRenderer.invoke("vault-pin-clear"),
Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins The PIN could only be six digits and was set from three bare inputs; the unlock prompt sat at the top of the page; and the password manager only filled when you found the key chip, never offered to save, and "Clear cookies on quit" signed you out of every site, including the ones whose login the vault already holds. - PINs are 6 to 8 digits. The PIN record stores its length so pads draw the right number of dots and submit on the last digit; a PIN of the wrong length is refused without a strike, so an older Aegis pad cannot burn the count against an 8-digit PIN. - Settings sets a PIN in steps: master password, choose the PIN on a pad (6/7/8), repeat it, done. The locked vault opens Theseus's own prompt, which is now centred, with the PIN pad or the master password field. - After a sign-in or sign-up form is sent and the page moves on, Theseus offers to save (or update) the login, with an optional "ask for my PIN or password before filling it". Focusing a login form offers the saved logins under it; on a locked vault it offers to unlock first. A failed login (the password field still showing) gets no offer. - "Keep sign-ins for sites in your vault" (on): the quit clear spares the cookies and site storage of sites with a saved login. Their hostnames are kept sealed with the OS keystore so the list is readable at quit while the vault is locked. Verified end to end on a scratch profile: signed in, restarted, still signed in; another site's cookie was cleared.
2026-10-04 20:23:43 +02:00
pinCheckMaster: (masterPassword) => ipcRenderer.invoke("vault-check-master", masterPassword),
// Asks for the PIN or master password even while the vault is open.
pwConfirm: (reason) => ipcRenderer.invoke("vault-confirm", reason),
Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID Pages of Silent Mode projects can now sign the user in with their Theseus ID instead of a wallet phrase typed into the page. Theseus writes the sign-in message itself, takes the origin from the committed top frame, and signs as a project only on an origin that project's list includes, so a phishing page cannot get another project's signature and no page can use the ID key to sign anything else. - lib/theseus-id.cjs: the policy (first sign-in always asks and lets the user pick a private or One ID; Silent Mode projects are silent after that while the vault is open; per-site "always"; 10 silent signatures per minute per origin), the per-project record encrypted under a key derived from the vault, origin-list fetching with a 1 h cache and a 7-day stale fallback, and ID moves that send a proof signed by both keys and only finish once the project confirms. - A locked vault is unlocked only for a page the user just clicked or typed in: navigator.userActivation alone is true on load for pages opened with loadURL, which would let a page pop the vault prompt by itself. - Settings › Theseus ID: default mode, One ID, automatic sign-in toggle, signed-in projects (always, change ID, new ID, revoke) and a recovery key behind a fresh PIN / password check. - TheseusID/registry/projects.json is the first-party list (Hephaestus, Sirius, Pithos); it and TheseusID/lib ship as extraResources. - Token-aware cashaddrs (BNS owners) now decode for owner-signed lists. Verified on a scratch profile against a local test project whose server checks signatures with TheseusID/lib/verify.mjs: locked vault on load gives "locked" with no prompt, first sign-in prompt, silent second sign-in, a claimed foreign project refused without a prompt, an ID move that keeps the project's account, and the recovery key behind the confirm prompt.
2026-10-04 20:48:07 +02:00
// Settings › Theseus ID. Each resolves { ok, result } or { ok: false, error: { code, message } }.
tidOverview: () => ipcRenderer.invoke("theseus-id-overview"),
tidSetDefaultMode: (mode) => ipcRenderer.invoke("theseus-id-set-default-mode", mode),
tidSetAuto: (on) => ipcRenderer.invoke("theseus-id-set-auto", !!on),
tidSetAlways: (projectId, on) => ipcRenderer.invoke("theseus-id-set-always", projectId, !!on),
tidRevoke: (projectId) => ipcRenderer.invoke("theseus-id-revoke", projectId),
tidMove: (projectId, to) => ipcRenderer.invoke("theseus-id-move", projectId, to),
tidCancelMove: (projectId) => ipcRenderer.invoke("theseus-id-cancel-move", projectId),
tidRotate: (projectId) => ipcRenderer.invoke("theseus-id-rotate", projectId),
tidUnlock: () => ipcRenderer.invoke("theseus-id-unlock"),
tidRecoveryKey: () => ipcRenderer.invoke("theseus-id-recovery-key"),
pinUnlock: () => ipcRenderer.invoke("vault-pin-unlock"),
Theseus: shield green polish, picker→Search section, toggle-vs-remove Three follow-up asks from the previous ship: 1. Shield "secure" colour bumped from #4fd1a5 (mint) to #3fb950 — the GitHub-style saturated green, matches the +N/-N diff colour the user pointed at as reference. 2. Engine-picker "Search settings…" now opens the Search section directly instead of General. New IPC channel `focus-section` fires from main after picker-open-settings, carried through settings-preload as `onFocusSection`, and the settings.html sidebar handler exposes showSection(sec) so any section can be focused programmatically. Works for both a fresh settings tab (fires on did-finish-load) and an already-open one (fires immediately). 3. Toggle no longer removes an engine from the list. Two-tier state: INSTALLED (visible in the Settings list) and ENABLED (toggled on in the toolbar dropdown). Toggling off keeps the row visible with an .off class (dimmed 55%). Right-click any row → new context menu with "Remove from list" is what actually removes an engine (built-ins go back to the catalog, customs are dropped entirely). Model changes: - New settings.installedEngines persistent array (defaults to DEFAULT_ENABLED). enabledEngines becomes a subset of installedEngines. - isInstalled(id) helper; allEngines() carries `installed: bool` alongside `enabled`. - New IPC `remove-from-list` (right-click action); exposed as removeFromList in settings-preload. - set-engine-enabled now also INSTALLS when enabling (the catalog "+ Add" flow), preserves installed state when disabling. - add-engine (custom URL) auto-adds the new id to enabledEngines too. - remove-engine (custom delete) prunes from enabledEngines as well. - Never-empty invariant kept: enabledEngines falls back to ["duckduckgo"] if everything gets removed. Settings UI: - Enabled list shows all INSTALLED engines (was: only enabled), rendered with toggle reflecting enabled state; rows carry data-builtin so the context menu picks the right remove IPC. - Catalog panel and Discover-more pane filter on !installed instead of !enabled — a toggled-off engine stays in the enabled list, not here. - Ctxmenu is a floating .ctxmenu div; closes on outside click / Escape. - .eng.off dims the row and mutes the name colour. Preview harness stubs updated to include the `installed` field on every engine + `removeFromList` and `onFocusSection` no-op stubs so _settings-preview.html renders the new UI accurately.
2026-08-06 01:41:31 +02:00
// Main asks settings to jump to a specific sidebar section (e.g. from the
// engine picker's "Search settings…" click). Emits the section id string.
onFocusSection: (cb) => ipcRenderer.on("focus-section", (_e, section) => cb(section)),
// Collision-mode: BCNR/ICANN policy + per-name/per-TLD overrides
collisionState: () => ipcRenderer.invoke("collision-state"),
setCollisionPolicy: (p) => ipcRenderer.invoke("collision-set-policy", p),
resetCollisions: () => ipcRenderer.invoke("collision-reset"),
// Blocklists: flagged names, the policy, and the "continue anyway" choices
blocklistState: () => ipcRenderer.invoke("blocklist-state"),
setBlocklistPolicy: (p) => ipcRenderer.invoke("blocklist-set-policy", p),
resetBlocklist: () => ipcRenderer.invoke("blocklist-reset"),
Theseus: add-on framework MVP + Notepad reference add-on New subsystem for extending Theseus with folders on disk. Each add-on lives at <userData>/addons/<id>/ with an addon.json manifest and a CommonJS entry that exports activate(api). Nothing about a private add-on ships in the public installer - drop the folder, restart, it's live. Bundled reference add-ons ride in the packaged app under resources/bundled-addons/ and are seeded into <userData>/addons/ on first boot; the framework treats seeded and drop-in add-ons the same. Files: - addons-host.js Loader + api.registerSidebarPanel() + per- addon storage on <userData>/addons-data/. Kept at the CommonJS-scoped top level (lib/ is ESM-scoped via its own package.json). - sidebar-preload.js Runs in every sidebar panel. Exposes window.silentmode.storage.{get,set,all} + onVisibility. Main-side handlers derive the add-on id from the sender file:// URL, so a panel can only touch its own store. - bundled-addons/notepad/ Reference add-on: addon.json, index.js, note.html. Autosaving textarea with char / word count. main.js: - Extension point: sidebar-panel. One right-anchored WebContentsView (SIDEBAR_W=340) hosts the current panel; layout() shrinks the tab views by the sidebar width when visible. First registered panel wins for MVP; picker for multiple panels lands later. - initAddons() at app.whenReady(): seedBundledAddons, then AddonHost.discoverAndActivate. - IPC surface: sidebar-toggle / sidebar-open / sidebar-close / sidebar-state, addons-list / addons-set-enabled / addons-reveal / addons-open-dir / addons-reload, and origin-gated addon-storage-get/set/all. - Settings gains `disabledAddons: []` — off-toggled ids persist and the loader honours them without a restart (discoverAndActivate runs again on toggle). chrome.html: toolbar sidebar-toggle button, hidden until at least one add-on has registered a sidebar panel. settings.html: new "Add-ons" section under privacy. Lists installed add-ons with icon / name / version / description / capabilities; per-add-on enable/disable toggle + Show folder button; page-level Reload and Open add-ons folder buttons; warning note about the trust model. package.json: build.files gains sidebar-preload.js + addons-host.js. extraResources gains bundled-addons/ so the packaged app carries the reference notepad for the first-boot seed. Verified: `npm start` boots, addons-host discovers the notepad, activates it, registers one sidebar panel. Log confirms "1 installed, 1 enabled, 1 sidebar panels". Actual sidebar rendering + notepad UI need clicked-through validation on a real install. Not shipped yet - deploy still blocked on the fail2ban VPS SSH ban. Ships as 0.2.0 once SSH clears (this is a new subsystem, not a fix).
2026-08-31 13:51:08 +02:00
// Add-ons management (Settings > Add-ons tab).
listAddons: () => ipcRenderer.invoke("addons-list"),
setAddonEnabled: (id, enabled) => ipcRenderer.invoke("addons-set-enabled", id, !!enabled),
revealAddon: (folder) => ipcRenderer.invoke("addons-reveal", folder),
// Delete a non-bundled extension's folder (Settings › Extensions › ⋯ › Remove).
removeAddon: (id) => ipcRenderer.invoke("addons-remove", id),
openAddonsDir: () => ipcRenderer.invoke("addons-open-dir"),
reloadAddons: () => ipcRenderer.invoke("addons-reload"),
// Add-on update flow. checkAddonUpdates hits the release manifest and
// stages any newer signed version; listStagedAddonUpdates reports what's
// waiting; applyStagedAddons promotes staged → active and reactivates the
// addon host so the new bytes load without a full Theseus restart.
// Community extensions from theseus.x/extensions: the catalog (with what
// is installed already) and a verified install/update of one entry.
communityCatalog: () => ipcRenderer.invoke("addons-community-catalog"),
installCommunity: (id) => ipcRenderer.invoke("addons-install-community", id),
checkAddonUpdates: () => ipcRenderer.invoke("addons-check-updates"),
listStagedAddonUpdates: () => ipcRenderer.invoke("addons-list-staged"),
applyStagedAddons: (id) => ipcRenderer.invoke("addons-apply-staged", typeof id === "string" ? id : undefined),
// Settings › Performance › Protections: talk to an add-on's own message
// handlers (Shield, Cookie Pop-ups) and open its panel for the details.
addonInvoke: (id, msg, payload) => ipcRenderer.invoke("addon-invoke", String(id || ""), String(msg || ""), payload),
openPanel: (panelId) => ipcRenderer.invoke("settings-open-panel", String(panelId || "")),
// Which page is showing (the address bar follows), Tor state + toggle for Privacy › Network.
reportSection: (slug) => ipcRenderer.invoke("settings-section", String(slug || "")),
torState: () => ipcRenderer.invoke("tor-state"),
toggleTor: () => ipcRenderer.invoke("toggle-tor"),
// OS locale — used by the Website-language row to label "Automatic (OS: …)".
systemLocale: () => ipcRenderer.invoke("system-locale"),
// Live settings updates — the toolbar chip, this page's Website-language
// row, and the Anti-fingerprinting Language row all edit the same setting;
// any of them writing pushes a "settings-update" the others react to.
onSettingsUpdate: (cb) => ipcRenderer.on("settings-update", (_e, d) => cb(d)),
// Ariadne's Thread plug-in (system-wide resolver). The state getter returns
// { state:"running"|"stopped"|"not-installed", installedVersion, bundledVersion,
// canUpdate, hasUninstaller }; the mutators prompt UAC for admin.
ariadneState: () => ipcRenderer.invoke("ariadne-state"),
ariadneToggle: (on) => ipcRenderer.invoke("ariadne-toggle", !!on),
ariadneInstall: () => ipcRenderer.invoke("ariadne-install"),
ariadneUpdate: () => ipcRenderer.invoke("ariadne-update"),
ariadneUninstall: () => ipcRenderer.invoke("ariadne-uninstall"),
feat(theseus/ariadne): settings panel — policy + per-source toggles + status report Ariadne 0.1.13 exposed /api/status and per-source enable flags in policy.json. Theseus's Plug-ins > Ariadne's Thread sub-page now wires those into a full UI, no daemon restart, no UAC. Added to the plugins-ariadne sub-page (after Status, before Remove): Collision policy -- radio group (BCNR-first / ICANN-first) writes C:\ProgramData\Ariadne\policy.json.policy; hot-reloaded by the daemon within 5 s. Sources -- 3-column grid, one row per source (snapshotHttps, electrumWss, perQueryLookup, diskCache, localApi): enable checkbox + last-state summary (last success / last error / hit-miss counters / disk-cache size+mtime). Toggle writes policy.json.sources.<name>.enabled and re-polls after the 5-s hot-reload tick so the state text catches up. Status report -- <pre> JSON dump of GET http://127.0.0.1/api/status with Copy report + Refresh report buttons. This is the paste-me-into-support artefact for any diagnosis. IPC wiring: main.js ariadne-get-status -> GET http://127.0.0.1/api/status ({ok, status|error}) ariadne-get-policy -> read C:\ProgramData\Ariadne\policy.json (or {}) ariadne-set-policy -> merge {policy}, write back (validates enum) ariadne-set-source -> merge {sources.<name>.enabled}, write back (validates against the known 5 names) settings-preload.js ariadneGetStatus, ariadneGetPolicy, ariadneSetPolicy, ariadneSetSource All four handlers write policy.json as the local user; no UAC. Works because install.ps1 grants BUILTIN\Users Modify on the file (0.1.7+). Sub-page auto-refreshes state every time it opens (listens on the existing 'section' custom event dispatched by showSection). Not building/shipping Theseus here -- this rides the next Theseus release. Panel gracefully handles: daemon down (shows 'Daemon unreachable' with a pointer to the Status toggle), localApi disabled (daemon returns 503, panel shows the error), missing policy.json (all sources default to true).
2026-10-01 00:51:50 +02:00
// Local BNS daemon settings + status (0.1.13+). All read/write against
// C:\ProgramData\Ariadne\policy.json (user-writable ACL) and the daemon's
// own /api/status endpoint on 127.0.0.1. No UAC required for any of these.
ariadneGetStatus: () => ipcRenderer.invoke("ariadne-get-status"),
ariadneGetPolicy: () => ipcRenderer.invoke("ariadne-get-policy"),
ariadneSetPolicy: (policy) => ipcRenderer.invoke("ariadne-set-policy", String(policy || "")),
ariadneSetSource: (name, enabled) => ipcRenderer.invoke("ariadne-set-source", String(name || ""), !!enabled),
// Manual "Check for updates" — un-dismisses any existing chip and re-
// fetches the release manifest. Returns { updateAvailable, currentVersion }.
recheckUpdate: () => ipcRenderer.invoke("recheck-update"),
appVersion: () => ipcRenderer.invoke("app-version"),
restartApp: () => ipcRenderer.invoke("app-restart"),
});