theseus/bundled-addons/aegis/addon.json

30 lines
1.1 KiB
JSON
Raw Normal View History

{
refactor(theseus/aegis): rename bundle bchwallet→aegis + retire standalone siawallet Cleans up the naming that leaked from the wallet's origin story (BCH-only) into the actual bundle layout. Aegis is one integrated addon now: - Bundle folder: TheseusNavigator/bundled-addons/aegis/ (was bchwallet/). - Addon id: "aegis" (was "bchwallet"). Vault-derive still accepts legacy "bchwallet/*" and "siawallet/*" paths via the absorbs list, so no on-chain funds move. - Version: 0.4.0 (bumped to trigger seedBundledAddons's reseed). - Retired: TheseusNavigator/bundled-addons/siawallet/. Sia is folded into Aegis as a chain adapter (lib/sia/*.js already in-tree) and Aegis's manifest lists siawallet under absorbs so pre-Aegis SC keys derive identically. main.js migrateAegisRename() runs before seedBundledAddons on every launch. First run does the move; subsequent runs are no-ops: - addons/bchwallet/ -> addons-backups/bchwallet-migrated-<stamp>/ - addons-data/bchwallet.json COPIED to addons-data/aegis.json (kept copied not moved so a downgrade to 0.3.x can still boot). - addons/siawallet/ -> addons-backups/siawallet-migrated-<stamp>/ (addons-data/siawallet.json left untouched — its walletdUrl is per-user config Aegis's Sia wallet takes fresh via Settings). settings.html Aegis update card now matches either "aegis" (new id) or "bchwallet" (pre-rename) so upgraders coming from 0.3.x see the same one card while the OTA endpoint's next signed bundle catches up. Internal purpose paths inside index.js/chain-*.js are unchanged — LEGACY_BCH_PURPOSE stays "bchwallet/mainnet/0" and every purposePrefix still starts with "bchwallet/*". The addon absorbs its own former id, so those paths keep resolving to the same seed the shipping Aegis has been using since 0.3.14.
2026-09-08 18:17:44 +02:00
"id": "aegis",
feat(theseus/aegis): multi-wallet + Tron mainnet + Tron Nile in the bundled addon Turns the single-account BCH addon into Aegis: a chain-agnostic wallet manager with a wallet picker in the sidebar header, per-wallet sub-accounts, and Tron mainnet + Nile alongside BCH. Add-on id stays "bchwallet" so vault-derive paths stay in the same namespace and the legacy BCH default wallet uses PURPOSE "bchwallet/mainnet/0" byte-identical to before — funds are untouched. - lib/chain-bch.js wraps the existing keys/tx/wallet/electrum stack with the common adapter shape and scopes each wallet's storage under wallets/<id>/… - lib/chain-tron.js: m/44'/195'/0'/0/0 → secp256k1 → keccak256 → 0x41 || h20 → base58check. Balance + history via TronGrid v1, send via createtransaction + sha256(raw_data_hex) sign + broadcasttransaction. Mainnet and Nile share the address format; different vault paths mean different keys so a mainnet wallet can never accidentally sign against Nile. - lib/base58check.js: bitcoin-alphabet base58 with sha256d checksum. k=1 derivation verified against Ethereum's canonical k=1 H160 in a scratchpad harness (correct-by-construction for Tron address). - Combined wallet-inject.js: window.bitcoincash on .x pages (unchanged gate), window.tronWeb + window.tronLink on any https page. tron_requestAccounts triggers the approval overlay; sign / sendRawTransaction / signMessageV2 route to the currently-selected Tron wallet. Emits accountsChanged / setNode messages TronLink dapps listen for; chain ids 0x2b6653dc / 0xcd8690dc match what TronLink itself uses. - New panel: chain-aware wallet picker in the header (badges 🟨 BCH, 🔴 Tron, 🔵 Nile), Add-wallet dropdown per chain, per-chain unit picker (BCH/sat, TRX/sun), per-wallet rename + remove (isLegacy default is protected). Sends show the chosen wallet in the approval overlay so the user can never mistake sub-account. - Migration on first launch: pre-multi-wallet storage (top-level receiveCursor / txCache) is rehomed under wallets/bch-default/… and the legacy account path is preserved. Not shipped: user is bundling into the next release. Live Nile broadcast + real dapp connect need a set-up vault; the code paths are unit-verified end to end but a testnet send + tronscan.io/nile connect are user-side steps.
2026-09-06 22:00:27 +02:00
"name": "Aegis Wallet",
feat(aegis): 0.22.0 — show a wallet's secret key, behind the PIN Getting a key back out of Aegis only worked for wallets it derived itself. Every imported adapter's recovery() returned xprv:null with "Recovery lives in the source of the import", so the wallets most likely to need exporting were the ones that refused, and the vault-derived ones handed over an xprv behind nothing but an approval click. There is one gate now, and it is enforced in the host. revealSecret takes the master password and verifies it with vault.lifecycle.unlock before it reads anything; the panel obtains that password either by decrypting the PIN blob, which wraps exactly it, or by asking. Both routes end at the same proof, so the host never takes the panel's word for authorisation. The old recovery({reveal:true}) path is gone and all six Settings buttons route here. Three wrong PINs switch to the master password rather than dead-ending, and those attempts still count toward the existing 15-minute lockout, so a fumbled PIN costs nothing and a guessed one gains nothing. Being locked out of the PIN also falls through to the password: the lockout exists to stop PIN guessing, not to lock an owner out of their own key. "Use PIN to show secret keys" defaults ON, unlike the send flag — a send is already fronted by an approval overlay, whereas a revealed key is irreversible the moment it is on screen. Turning it off moves the prompt to the master password. There is deliberately no setting that reveals a key without asking for anything. It is NOT called a recovery phrase, because Aegis has none to show. An import stores mnemonicToSeedHex(words) and discards the words, vault wallets are HKDF(vault root, purpose) and never had words, and password-vault.js is explicit that the seed is never persisted. So each form names itself — WIF, private key (hex), wallet seed (hex), wallet key (hex) — and says where it can actually be restored. Someone who writes down what this shows believing it is twelve words has backed up nothing, which is the one outcome this screen has to prevent.
2026-10-02 00:04:06 +02:00
"version": "0.22.0",
"category": "plugin",
"description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.",
"author": "Silent Mode",
"icon": "data:image/svg+xml;utf8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32' fill='none'%3E%3Cpolygon points='16,2 28,9 28,23 16,30 4,23 4,9' fill='%230a0a0d' stroke='%23D6FF3D' stroke-width='1.6' stroke-linejoin='round'/%3E%3Ccircle cx='16' cy='16' r='4.5' fill='none' stroke='%23D6FF3D' stroke-width='1.4'/%3E%3Ccircle cx='16' cy='16' r='1.6' fill='%23D6FF3D'/%3E%3C/svg%3E",
"main": "index.js",
"updateURL": "https://navigate.st/bns/theseus.x/extensions/aegis/updates.json",
feat(aegis): 0.12.0 — open the wallet full screen, sidebar becomes the rail The 380px panel is the wrong shape for anything that needs room. This opens the wallet as a full Theseus tab, with the sidebar's own furniture — identity, network, balance, section nav, wallet list — laid out as a left rail and the tab body given to the selected section. It is the SAME panel.html, loaded with ?surface=web. No second wallet, no second copy of 4,600 lines to drift apart. That works because an add-on's own tab is handed a window.silentmode with the same invoke/on surface as the sidebar, and addon-msg dispatches it as from:"panel" with the add-on identity derived from the file:// sender — so every existing handler, including the panel-only ones, works there untouched. The whole change is a CSS grid behind one attribute plus a chip to open it. Details that needed care: - The QR is drag-sized against a 380px panel and the size is remembered. Given a 720px column it filled the page, so it is capped on this surface only; the stored sidebar preference is left exactly as the user set it. - #drop (the coin picker sheet) is fixed-position and sized for the panel; it is pinned to the rail instead of covering the window. - Content columns are capped at 720px so forms and lists keep the measure the sidebar already tuned, rather than stretching across a monitor. - Under 900px the grid falls back to the stacked layout, so a narrow window degrades to what the sidebar already does. - The "open full screen" chip hides itself on the full-screen surface, so it cannot open a second copy of itself. Everything is scoped to [data-surface="web"], so the sidebar is byte-for-byte unchanged. Verified both surfaces, the narrow fallback (by exercising the real media rule) and zero horizontal overflow. The aegis.x/app URL still needs a main.js route in Theseus; this ships the destination over the add-on channel first.
2026-09-27 20:17:08 +02:00
"capabilities": [
"sidebar-panel",
"vault-derive",
"page-inject",
"approval-modal",
"scan-page",
"open-tab"
],
"absorbs": [
"bchwallet",
"siawallet"
],
"page-inject": {
"preload": "wallet-inject.js",
feat(aegis): 0.12.0 — open the wallet full screen, sidebar becomes the rail The 380px panel is the wrong shape for anything that needs room. This opens the wallet as a full Theseus tab, with the sidebar's own furniture — identity, network, balance, section nav, wallet list — laid out as a left rail and the tab body given to the selected section. It is the SAME panel.html, loaded with ?surface=web. No second wallet, no second copy of 4,600 lines to drift apart. That works because an add-on's own tab is handed a window.silentmode with the same invoke/on surface as the sidebar, and addon-msg dispatches it as from:"panel" with the add-on identity derived from the file:// sender — so every existing handler, including the panel-only ones, works there untouched. The whole change is a CSS grid behind one attribute plus a chip to open it. Details that needed care: - The QR is drag-sized against a 380px panel and the size is remembered. Given a 720px column it filled the page, so it is capped on this surface only; the stored sidebar preference is left exactly as the user set it. - #drop (the coin picker sheet) is fixed-position and sized for the panel; it is pinned to the rail instead of covering the window. - Content columns are capped at 720px so forms and lists keep the measure the sidebar already tuned, rather than stretching across a monitor. - Under 900px the grid falls back to the stacked layout, so a narrow window degrades to what the sidebar already does. - The "open full screen" chip hides itself on the full-screen surface, so it cannot open a second copy of itself. Everything is scoped to [data-surface="web"], so the sidebar is byte-for-byte unchanged. Verified both surfaces, the narrow fallback (by exercising the real media rule) and zero horizontal overflow. The aegis.x/app URL still needs a main.js route in Theseus; this ships the destination over the add-on channel first.
2026-09-27 20:17:08 +02:00
"origins": [
"https://*/*"
]
}
}