Theseus: ids that ever shipped in the bundle stay reserved

Reserved ids came from the current bundle only, so an add-on dropped
from a later release became an id anyone could publish under, and the
newcomer inherited its extensions-data store and vault.derive
namespace. Every id that has shipped is now reserved permanently.
This commit is contained in:
Local Dev 2026-10-04 04:25:23 +02:00
parent 21964ce385
commit 2f7d42d077

View file

@ -2244,6 +2244,13 @@ function firstPartyAddonIds() {
} catch {}
}
} catch {}
// Ids that have ever shipped inside Theseus stay reserved even after they
// leave the bundle: their extensions-data/<id>.json and vault.derive
// namespace (e.g. pithos/sia-recovery/v1) outlive them, and a community
// add-on installed under a dropped id would inherit both.
for (const id of ["bchwallet", "siawallet", "aegis", "blocker", "consent", "docx-editor", "notepad", "pdf-editor", "pithos", "screenshot", "translate", "vpn"]) {
if (!bundled.has(id)) absorbed.add(id);
}
firstPartyIdsCache = { bundled, absorbed };
return firstPartyIdsCache;
}