2026-09-21 22:28:30 +02:00
|
|
|
|
# Word editor — a Theseus extension
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
feat(docx-editor): Save as…, PDF export, and a mark of our own
Three gaps, one theme: the editor could produce a file but not decide where
it went, what format it was in, or look like anything in the dock.
**Save as…** opens a real file dialog, and the extension typed there picks
the format. Save then writes to that file instead of dropping another copy
in Downloads every time. The renderer never names a path: the dialog returns
an opaque token, and the add-on will only write to a path a dialog actually
returned. An extension page is the least trusted thing in the add-on, and
"write these bytes anywhere" is not a capability it needs.
**PDF** goes through Chromium's own print pipeline in a hidden window — the
same engine as Ctrl+P — on the paper size read out of the document's own
sectPr. For that to match what the user was looking at, the page's
typography had to stop living in editor.css, which the export window can't
reach: it moves to lib/doc-css.js and both surfaces read the one string. The
result embeds subsetted fonts, keeps images, and turns hyperlinks into real
PDF link annotations.
**The icon** is ours. Microsoft's Word mark is a trademark and borrowing it
to look official is not something a browser that talks about sovereignty
should do. icon.svg says "text document" in its own words — a turned corner,
a heading rule, body lines, a pilcrow badge in Silent Mode green — and
`npm run icons` derives the PNGs and addon.json's copy from it, so there is
one drawing rather than several that drift.
Also: the scratch folder follows the profile rename to extensions-data/ via
the api.dataDir the host now provides, instead of creating a stale
addons-data/ beside it.
2026-09-21 03:35:55 +02:00
|
|
|
|
Opens, edits and saves Word documents (`.docx`) in a full Theseus tab, and
|
|
|
|
|
|
exports them as PDF.
|
|
|
|
|
|
|
|
|
|
|
|
Saving comes in three shapes. **Save** drops a copy in your downloads until the
|
|
|
|
|
|
document has a home; **Save as…** opens a real file dialog where the extension
|
|
|
|
|
|
you type — `.docx` or `.pdf` — decides the format, and from then on Save writes
|
|
|
|
|
|
straight to that file; **PDF** is the one-click export. PDFs are rendered by
|
|
|
|
|
|
Chromium's own print pipeline from `lib/doc-css.js`, the same stylesheet the
|
|
|
|
|
|
editor displays, on the paper size the document itself specifies — so the
|
|
|
|
|
|
export matches the preview rather than being a second opinion about it.
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
2026-09-21 22:28:30 +02:00
|
|
|
|
It is a first-party extension: written here, signed with the Silent Mode
|
|
|
|
|
|
operator key, and updated over the channel at
|
|
|
|
|
|
`theseus.x/extensions/docx-editor/` like every other add-on Theseus ships.
|
|
|
|
|
|
It does not go through the community catalogue, which is for extensions
|
|
|
|
|
|
published by whoever owns a BNS name.
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
2026-09-21 22:47:13 +02:00
|
|
|
|
It ships inside Theseus, so a fresh install already has it and Settings
|
|
|
|
|
|
lists it under **Built into Theseus**; the channel above then updates it
|
|
|
|
|
|
between releases without waiting for one. That is the same arrangement as
|
|
|
|
|
|
screenshot, aegis and pdf-editor, and it is what gives a user their first
|
|
|
|
|
|
copy at all — Settings can only *install* from the community catalogue, so
|
|
|
|
|
|
an extension that is neither bundled nor catalogued has a working update
|
|
|
|
|
|
channel and no way in.
|
|
|
|
|
|
|
|
|
|
|
|
The cost is about 400 KB compressed in the installer, most of it the
|
|
|
|
|
|
vendored editor libraries.
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
feat(docx-editor): Save as…, PDF export, and a mark of our own
Three gaps, one theme: the editor could produce a file but not decide where
it went, what format it was in, or look like anything in the dock.
**Save as…** opens a real file dialog, and the extension typed there picks
the format. Save then writes to that file instead of dropping another copy
in Downloads every time. The renderer never names a path: the dialog returns
an opaque token, and the add-on will only write to a path a dialog actually
returned. An extension page is the least trusted thing in the add-on, and
"write these bytes anywhere" is not a capability it needs.
**PDF** goes through Chromium's own print pipeline in a hidden window — the
same engine as Ctrl+P — on the paper size read out of the document's own
sectPr. For that to match what the user was looking at, the page's
typography had to stop living in editor.css, which the export window can't
reach: it moves to lib/doc-css.js and both surfaces read the one string. The
result embeds subsetted fonts, keeps images, and turns hyperlinks into real
PDF link annotations.
**The icon** is ours. Microsoft's Word mark is a trademark and borrowing it
to look official is not something a browser that talks about sovereignty
should do. icon.svg says "text document" in its own words — a turned corner,
a heading rule, body lines, a pilcrow badge in Silent Mode green — and
`npm run icons` derives the PNGs and addon.json's copy from it, so there is
one drawing rather than several that drift.
Also: the scratch folder follows the profile rename to extensions-data/ via
the api.dataDir the host now provides, instead of creating a stale
addons-data/ beside it.
2026-09-21 03:35:55 +02:00
|
|
|
|
## The icon
|
|
|
|
|
|
|
|
|
|
|
|
`icon.svg` is the one drawing. `npm run icons` rasterises it to
|
|
|
|
|
|
`icon-16/32/48/128/256.png` and writes a minified copy into `addon.json`'s
|
|
|
|
|
|
`icon` field, which is what the dock button and the catalogue card read — so
|
|
|
|
|
|
there is never a second version to keep in step.
|
|
|
|
|
|
|
2026-09-22 00:10:56 +02:00
|
|
|
|
It is a blue document badge, paired with pdf-editor's red one so the two
|
|
|
|
|
|
editors read as a set in the dock — a solid fill stays legible at the 16–18px
|
|
|
|
|
|
the dock actually renders, which an outlined page does not.
|
|
|
|
|
|
|
|
|
|
|
|
Deliberately not Microsoft's Word icon: their mark is a blue sheet carrying a
|
|
|
|
|
|
white W, and dressing our extension up as theirs would be both a legal
|
|
|
|
|
|
problem and a dishonest one. A folded-corner page is the universal document
|
|
|
|
|
|
glyph, and "DOC" is the file format rather than anyone's trademark.
|
feat(docx-editor): Save as…, PDF export, and a mark of our own
Three gaps, one theme: the editor could produce a file but not decide where
it went, what format it was in, or look like anything in the dock.
**Save as…** opens a real file dialog, and the extension typed there picks
the format. Save then writes to that file instead of dropping another copy
in Downloads every time. The renderer never names a path: the dialog returns
an opaque token, and the add-on will only write to a path a dialog actually
returned. An extension page is the least trusted thing in the add-on, and
"write these bytes anywhere" is not a capability it needs.
**PDF** goes through Chromium's own print pipeline in a hidden window — the
same engine as Ctrl+P — on the paper size read out of the document's own
sectPr. For that to match what the user was looking at, the page's
typography had to stop living in editor.css, which the export window can't
reach: it moves to lib/doc-css.js and both surfaces read the one string. The
result embeds subsetted fonts, keeps images, and turns hyperlinks into real
PDF link annotations.
**The icon** is ours. Microsoft's Word mark is a trademark and borrowing it
to look official is not something a browser that talks about sovereignty
should do. icon.svg says "text document" in its own words — a turned corner,
a heading rule, body lines, a pilcrow badge in Silent Mode green — and
`npm run icons` derives the PNGs and addon.json's copy from it, so there is
one drawing rather than several that drift.
Also: the scratch folder follows the profile rename to extensions-data/ via
the api.dataDir the host now provides, instead of creating a stale
addons-data/ beside it.
2026-09-21 03:35:55 +02:00
|
|
|
|
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
## Building
|
|
|
|
|
|
|
|
|
|
|
|
The vendored libraries (mammoth, ProseMirror, docx, JSZip) are bundled by a
|
|
|
|
|
|
build step that lives outside this folder, because mammoth needs local patches
|
|
|
|
|
|
before it can carry everything the editor edits:
|
|
|
|
|
|
|
|
|
|
|
|
cd ../../addon-build/docx-editor
|
|
|
|
|
|
npm install
|
|
|
|
|
|
npm run build # writes vendor/docx-vendor.js here
|
2026-09-21 22:28:30 +02:00
|
|
|
|
npm run icons # re-rasterises icon.svg after editing it
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
|
|
|
|
|
`vendor/docx-vendor.js` is committed, so the extension is installable straight
|
|
|
|
|
|
from a checkout; re-run `npm run build` after touching anything under
|
|
|
|
|
|
`addon-build/`.
|
|
|
|
|
|
|
|
|
|
|
|
## Publishing
|
|
|
|
|
|
|
2026-09-21 22:28:30 +02:00
|
|
|
|
The full recipe is in [docs/ADDON-UPDATES.md](../../docs/ADDON-UPDATES.md);
|
|
|
|
|
|
the short version, signed with the operator key and always from a clean copy
|
|
|
|
|
|
of the commit rather than the working tree:
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
2026-09-21 22:28:30 +02:00
|
|
|
|
git archive HEAD TheseusNavigator/extensions/docx-editor | tar -x -C <clean>
|
|
|
|
|
|
node scripts/sign-addon-update.mjs <clean>/TheseusNavigator/extensions/docx-editor https://navigate.st/bns/theseus.x/extensions/docx-editor "$USERPROFILE/.silentmode/ops/addon-update-key.pem" --out out/
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
2026-09-21 22:28:30 +02:00
|
|
|
|
node ../Argus/src/lib/sia-upload.js out/docx-editor-<version>.tar.gz bns/theseus/extensions/docx-editor
|
|
|
|
|
|
node ../Argus/src/lib/sia-upload.js out/updates.json bns/theseus/extensions/docx-editor
|
|
|
|
|
|
|
|
|
|
|
|
The channel lives on Sia only — nothing goes to the VPS filesystem — and is
|
|
|
|
|
|
served through the gateway at `https://navigate.st/bns/theseus.x/extensions/`.
|
|
|
|
|
|
A first release has no `updates.json` to prepend to, so it ships one holding
|
|
|
|
|
|
just its own entry. Versions must increase.
|
refactor(docx-editor): ship it as a community extension, not part of the browser
A .docx editor is a megabyte of vendored library. Bundling it would charge
that to everyone who wanted a browser, including the people who will never
open a Word document in it.
So it leaves the build: out of bundled-addons/, out of extraResources, absent
from a fresh profile. It arrives the way anyone else's extension does —
Settings › Extensions › Community, from the catalogue the gateway builds, and
listed on theseus.x/extensions alongside everything else published there.
That also means it is signed by the owner of a BNS name rather than by the
operator key, which is the right trust story for something that isn't part of
the browser.
`npm run pack` produces the tarball the publish page takes; the signature
needs the publisher name's wallet, so it isn't something the repo can do.
The end-to-end test now installs the extension into a throwaway profile the
way the community installer would, and asserts up front that a fresh profile
doesn't already have it — the bundling is what was being removed, so it is
worth a test that would notice it coming back.
2026-09-21 01:06:58 +02:00
|
|
|
|
|
|
|
|
|
|
## Testing
|
|
|
|
|
|
|
|
|
|
|
|
Three levels, all re-runnable, all from `../../addon-build/docx-editor`:
|
|
|
|
|
|
|
|
|
|
|
|
node test/roundtrip.mjs # the built-in fixture
|
|
|
|
|
|
node test/corpus.mjs <folder of .docx> # real documents
|
|
|
|
|
|
node ../../../scratchpad/verify-docx-editor/drive.mjs # a real Theseus, over CDP
|
|
|
|
|
|
|
|
|
|
|
|
The last one installs this folder into a throwaway profile the way the
|
|
|
|
|
|
community channel would, and is the only one that catches browser-only
|
|
|
|
|
|
breakage.
|
|
|
|
|
|
|
|
|
|
|
|
What survives a round trip, and what doesn't, is written up in
|
|
|
|
|
|
[ROUND-TRIP.md](ROUND-TRIP.md). Read that before promising anyone a Word
|
|
|
|
|
|
feature.
|