From 2f7d42d077376aa9611ef3bbd10c66608cd4cd28 Mon Sep 17 00:00:00 2001 From: Local Dev Date: Sun, 4 Oct 2026 04:25:23 +0200 Subject: [PATCH] Theseus: ids that ever shipped in the bundle stay reserved Reserved ids came from the current bundle only, so an add-on dropped from a later release became an id anyone could publish under, and the newcomer inherited its extensions-data store and vault.derive namespace. Every id that has shipped is now reserved permanently. --- main.js | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/main.js b/main.js index ec853ec1..f1ee5a38 100644 --- a/main.js +++ b/main.js @@ -2244,6 +2244,13 @@ function firstPartyAddonIds() { } catch {} } } catch {} + // Ids that have ever shipped inside Theseus stay reserved even after they + // leave the bundle: their extensions-data/.json and vault.derive + // namespace (e.g. pithos/sia-recovery/v1) outlive them, and a community + // add-on installed under a dropped id would inherit both. + for (const id of ["bchwallet", "siawallet", "aegis", "blocker", "consent", "docx-editor", "notepad", "pdf-editor", "pithos", "screenshot", "translate", "vpn"]) { + if (!bundled.has(id)) absorbed.add(id); + } firstPartyIdsCache = { bundled, absorbed }; return firstPartyIdsCache; }