Commit graph

538 commits

Author SHA1 Message Date
Local Dev
00aa37ab2b Theseus PENDING.md: drop the 0.0.2 release notes it still led with
The file opened with the 0.0.2 hashes and rollback points from August, which
reads as the current state to a session skimming it. Releases live in the
manifest and in git history; the collision-policy group below is still
accurate and stays.
2026-10-04 20:46:50 +02:00
Local Dev
3dbbc452cd fix(theseus): an installed app can be closed and removed; Settings lists apps
An app whose page has a beforeunload handler (CoinSpectrum) could not be
closed: tabs answer the page's "stay?" request, app windows had nothing
listening, and Electron reads silence as a veto. Closing the window is now
always the user's call; a reload or navigation inside the app asks, as a
tab does.

Removing it looked dead for a related reason. The confirmation was drawn
as Theseus's sheet in the main window, where the user was not looking (or
nowhere, with the main window closed), and the removal then closed the app
window with the same call the page vetoes. The question is now asked on
the app window that asked, and removal destroys the window.

Installed apps were only reachable from the address-bar chip while on the
site. Settings gets an Apps page, at theseus://settings/apps, that lists
them with Open and Remove and follows installs, removals and open windows.
The three list calls it uses are settings-only now.
2026-10-04 19:15:11 +02:00
Local Dev
45c7ca90d7 Release Theseus 0.3.78: Ariadne plug-in toggle works for 0.2.0 installs
Settings > Plug-Ins > Ariadne's Thread now switches the daemon on and off
on every install scheme. The toggle used to look for a scheduled task
named 'BNS Resolver Daemon' (and 'BNS Sia Bridge') -- the compat names
from before Ariadne 0.2.0. A fresh 0.2.0 install under the Just-me scope
registers the daemon as 'Ariadne BNS Resolver (<user>)' instead, so the
toggle silently did nothing. The handler now walks every scheduled task
whose name matches the Ariadne pattern -- the pre-0.2 compat names,
the 0.2.0 All-users names and the Just-me scoped names -- and starts or
stops each one. Unrelated 'BNS Indexer'-style tasks on the box are left
alone.
2026-10-04 18:48:51 +02:00
Local Dev
6225e79d9b Pithos 0.3.16: public links at navigate.st/sia, and the Pithos name opens Overview
Files in your own Sia account can now be shared with anyone through a
navigate.st/sia link that keeps working with this computer off; the
navigate.st service is live, so the buttons can ship.
2026-10-04 18:27:05 +02:00
Local Dev
dc7dc75bcc fix(theseus/ariadne): toggle every Ariadne task regardless of install scope
User report (2026-10-04): "Plug-Ins/Ariadne's Thread is not working
properly, it doesn't switch on / off the daemon. Other PC can't turn it
on, and other browsers on it don't recognize BNS names."

Root cause. ariadneSetState's elevated script hard-coded two names,
'BNS Resolver Daemon' and 'BNS Sia Bridge'. Those are the pre-0.2 names
and the All-users / All-browsers compat names. A machine that received a
fresh 0.2.0 install under Just-me scope has NO task with either of those
names -- the resolver there is 'Ariadne BNS Resolver (<user>)' and the
indexer is 'Ariadne BNS Indexer (<user>)'. The toggle silently did nothing
(exit 2 handling returned 'no BNS Resolver Daemon'), and the panel's
state query -- which already knows about 'Ariadne BNS Indexer' -- still
displayed the previous state because it was reading the correct task but
nothing had actually started it.

Fix. The inner script now enumerates scheduled tasks dynamically and
anchors a regex at:
  ^(Ariadne BNS Indexer
   |Ariadne BNS Indexer \(.+\)
   |Ariadne BNS Resolver \(.+\)
   |BNS Resolver Daemon
   |BNS Sia Bridge)$
That hits every Ariadne task across all three install schemes without
touching the user's own unrelated 'BNS Indexer' task (which has no
'Ariadne' prefix -- memory://ariadne-task-names). Enable/Start (or
Stop/Disable) runs against each match; exit code is:
  0 = at least one task accepted the verb
  2 = no Ariadne task found at all (needs reinstall)
  3 = tasks found but none accepted (surface in a clearer error)

Note. Full 0.2.0 integration (named-pipe IPC via Argus/src/lib/bns-pipe.js,
scope-aware policy.json path) ships via step 3 on branch
claude/agitated-bell-bd4ac2 (see TheseusNavigator/DESIGN-bns-indexer-service.md).
This commit fixes the specific toggle bug on master so the user's "can't
turn it on" symptom is resolved WITHOUT waiting for that larger merge.
The 0.1.13 settings-panel sections (collision policy / sources /
status-report via http://127.0.0.1/api/status) still display 'Daemon
unreachable' honestly on 0.2.0 installs; they'll be superseded by the
pipe-based status feed when step 3 lands.
2026-10-04 17:39:53 +02:00
Local Dev
e3729e7470 Merge charming-mclean: a legacy Middle East location no longer kills Settings 2026-10-04 17:38:44 +02:00
Local Dev
e8723c29e4 Theseus: bundle Pithos 0.3.15 2026-10-04 16:18:17 +02:00
Local Dev
39ebd87d9d Theseus: bundle Pithos 0.3.14 2026-10-04 15:56:01 +02:00
Local Dev
828100e2ce Theseus: warn before opening a name a blocklist flags
The blocklist consumer existed in the resolver library and the gateway, but
the browser opened a flagged name without comment. Now the indexer process
reads the subscribed lists from the chain every ten minutes and hands the
flags to main. A flagged name loads a warning page naming the reason, the
list and the report; the user may continue, and that is remembered per name.

Two gates, because content is reached two ways. loadBns shows the real
interstitial. serveBns refuses with an inline page on every path that skips
it: reload, back and forward, bns:// links, web app windows. The inline page
has no button, since a page at the site's own origin must not be able to
approve itself; only blocked.html may ask to continue, checked by file URL.

Settings › Naming has the policy: warn (default), never open, or ignore the
lists. The csam reason is never offered a way through. A list that cannot be
read keeps the last known flags and never stops a name from resolving.

The gateway put its own warning in front of flagged sites, which this
browser could not get past: it fetches files itself, with no cookie jar. It
now sends x-bns-policy: client and the gateway stays out of the way for a
client that says it decides for itself.

dev/blocklist-selftest.js runs the real protocol handler and decision
functions against a scratch profile.
2026-10-04 15:50:35 +02:00
Local Dev
99d7684590 Theseus: an extension update applied in place reloads its open panels
Applying an extension update without a restart swapped the files and
restarted the add-on, but a panel or tab that was already open kept
running the previous version's page, so the extension looked unchanged
until Theseus restarted (Pithos showed its old layout this way). The
add-on's open left panel, sidebar panel and tabs now reload after the
swap. Extensions can also apply their own staged update with
api.applySelfUpdate(), so their own update button needs no restart;
plug-ins such as wallets still update on the next launch.
2026-10-04 15:28:25 +02:00
Silent Mode
f3cd63134a Theseus 0.3.77: translator provider setting, Pithos 0.3.13, CF-blocked error pages
- Settings → Language gets a Translator engine radio: pick between
  LibreTranslate (hosted — current default) and Bergamot (on-device —
  WASM engine, bundled in a later release; falls back to LibreTranslate
  for now with a one-time notice). See bergamot.x for the plan.
- Bundles Pithos 0.3.13: menu reflows in setup order with the account on
  top, files waiting to upload are shown and go up on their own, s3d
  one-shot commands never open the database at once.
- Error page handles Cloudflare Bot Fight 503s: branded page explains the
  Electron TLS fingerprint and offers a one-click retry to a .bch mirror
  when one is published (path preserved).
- Fixes did-fail-load suppression: a cert error during the HTTPS fallback
  now surfaces the branded error page instead of being swallowed.
2026-10-04 15:16:45 +02:00
Local Dev
f3fbbc5805 Merge ship/mirrors-and-cf: branded error pages and the mirrors docs
These three commits were pushed to the forge's theseus and site repos
from their branch but never reached master, so pushing master would
have dropped them there. Merged so master carries them: the branded
error page on BCNR-to-clearnet fallback failures, the Cloudflare Bot
Fight 503 hint with a .bch mirror suggestion, and the site's docs page
for the p-record reverse-proxy workaround.
2026-10-04 15:14:59 +02:00
Local Dev
f2913691aa Theseus: bundle Pithos 0.3.13 2026-10-04 14:39:45 +02:00
Silent Mode
0ce2ab95dd Theseus: translator provider setting — LibreTranslate or Bergamot
A new row in Settings › Language, Translator engine: a radio between the
hosted LibreTranslate backend (the current default) and the on-device
Bergamot engine. The chip and auto-translate route through a single
dispatcher (translatorCall) that picks the provider by setting; adding
or removing an engine only touches the dispatcher.

Bergamot's WASM runtime and model manager are not bundled yet, so the
Bergamot provider falls back to LibreTranslate for now and prints a
one-time console notice. The setting itself is real today — a user can
declare their preference and the real engine lands in a later release
without the user touching Settings again. See bergamot.x for status.
2026-10-04 14:20:18 +02:00
Local Dev
b99d3a6e54 Merge branch 'master' into claude/goofy-dubinsky-1f8f33 2026-10-04 04:32:44 +02:00
Local Dev
76d342797b Theseus: page scans run in an isolated world; install sheet names the risk
The wiz:// page scan ran in the page's own world, where the page can
replace RegExp, querySelectorAll or Set and shape what the wallet is
handed; it now runs in an isolated world of its own and the results
are checked again in main. The extension install sheet now says what a
community extension can reach while the vault is unlocked (passwords
and the wallet), since extensions still run in the main process.
2026-10-04 04:29:02 +02:00
Local Dev
f834fbf80a Theseus: a wallet approval belongs to the tab that asked for it
Approvals were one global queue drawn over whatever tab was in front,
so a background tab could time a request to pop up while the user was
in the middle of something on a trusted dapp, and a request outlived
the page that made it. The host now carries the tab of a page message
through the add-on's handler (AsyncLocalStorage across its awaits); an
approval from a page shows only while its tab is in front, hides and
comes back re-armed when the user switches tabs, and is cancelled when
the tab closes or navigates. Approvals from a panel or from
WizardConnect have no tab and behave as before.
2026-10-04 04:28:18 +02:00
Local Dev
455e468186 Theseus: scrub stale add-on store copies of the PIN and session secrets
Stores nothing reads any more kept whatever they held when they were
copied: the pre-rename addons-data/ folder, the bchwallet.json left by
the Aegis absorb, and parse-failure copies. For Aegis before 0.31 that
could include the master password behind only an unsealed 6-digit PIN
and the stay-unlocked blob. Those two keys are removed from such copies
at startup; nothing else in them is touched, and the live store is not
among them. extensions-backups/, which kept a copy of an add-on on
every reseed and update forever, is pruned to the newest three per
add-on.
2026-10-04 04:26:39 +02:00
Local Dev
2f7d42d077 Theseus: ids that ever shipped in the bundle stay reserved
Reserved ids came from the current bundle only, so an add-on dropped
from a later release became an id anyone could publish under, and the
newcomer inherited its extensions-data store and vault.derive
namespace. Every id that has shipped is now reserved permanently.
2026-10-04 04:25:23 +02:00
Local Dev
21964ce385 Theseus: community updates cannot widen what an extension may do
A community install strips category and absorbs and asks the user, but
an update of the same extension was staged and promoted verbatim, so
version 2 could claim first-party placement or quietly add
capabilities and page-inject origins. Publisher-signed updates now get
the same manifest rewrite, and one that asks for new capabilities or
new pages is not staged; the user approves it by reinstalling from
theseus.x.
2026-10-04 04:25:23 +02:00
Local Dev
bc1b5fc0f3 Theseus: add-on panels never leave their own page
The right-hand panel had neither a will-navigate nor a window-open
handler, so a link in a panel navigated the privileged view itself to
a remote page that kept sidebar-preload, and window.open made a bare
window with it; panel events were routed by the selected panel id, so
Aegis's state (every address, balances, WizardConnect sessions) would
then have reached that page. Both panels now open web links as tabs and
refuse to navigate away from file://, and events go only to a view that
has the add-on's own page loaded.
2026-10-04 04:23:54 +02:00
Local Dev
4ad8f4e401 Theseus: a long approval scrolls inside the overlay instead of pushing the buttons off screen
The approval box had no height limit inside a fixed mask, so a long
message or many rows pushed the end of the text and the buttons out of
view. The box now scrolls, long values scroll in place, and the
buttons stay pinned at the bottom.
2026-10-04 04:23:01 +02:00
Local Dev
f823c042e3 Theseus: wallet-imports and Hermes IPC only answer their own pages
wallet-imports-signer hands out raw seeds and WIFs while the vault is
open, and hermes-* sends and reads the user's Nostr messages; none of
these handlers checked who was asking. No preload exposes the
wallet-imports channels (add-ons use the vaultImports shim), so they
are now Settings-only like the password channels; the Hermes channels
answer only the Messages window.
2026-10-04 04:22:41 +02:00
Local Dev
f214abaf1b Theseus: page dialogs wait while a wallet approval or the unlock prompt is up
A dapp could request a signature and then call alert(): the page's
sheet was raised over the approval, and closing it focused the page
again while the approval's buttons were already armed, so a
double-click on the sheet's OK landed on Approve. Page dialogs and
Theseus's own sheets are now held until the approval or unlock prompt
is answered, and nothing hands focus to the page while one is open.
2026-10-04 04:21:58 +02:00
Local Dev
db1acc1417 Theseus: only theseus.x can ask to install an extension, and the sheet is armed
bcnr.installExtension is in every page's main world, and install links
were honoured from any page and any frame, with no user gesture. Any
site could raise the install sheet timed so that a double-click landed
on Install, whose two buttons are always in the same place; an
installed community extension runs in the main process at once. The
call and the links now work only from theseus.x's top frame, the call
needs a real click (checked in the isolated world), and Theseus's own
sheets ignore every choice except Cancel for 800 ms, like the approval
overlay.
2026-10-04 04:21:05 +02:00
Local Dev
70b35e2520 Aegis: the PIN pads use the one Theseus PIN when the host offers it
On a host with api.vault.pin, Aegis no longer keeps a PIN of its own:
its lock-screen, reveal and transaction pads send the digits to the
Theseus vault PIN, which is checked in main against the one strike
counter Settings, the unlock prompt and Pithos also use. The vault is
opened there, and the panel receives a single-use proof (two minutes)
where it used to receive the master password; vaultUnlock, revealSecret
and pinGateSatisfied accept it, still bound to the request it was
entered for. The master password no longer passes through Aegis or its
panel for a PIN entry.

An existing Aegis PIN moves to the vault PIN on its first correct entry.
If Theseus already has a different PIN, the user is asked once which
one to keep. Setting and removing the PIN act on the vault PIN, and
Settings says that it is shared. Hosts without the API (Theseus
0.3.74-0.3.76) keep Aegis's own PIN exactly as before.
2026-10-04 04:19:38 +02:00
Local Dev
9d6d8c3cc5 Theseus: one PIN — the vault PIN, offered to Aegis through api.vault.pin
Theseus and Aegis each wrapped the same master password under their
own PIN: two offline targets, two guess budgets, and two PINs to keep
in step. The vault PIN is now the only one. Built-in add-ons get
api.vault.pin {status, unlock, set, clear} (advertised by
features.vaultPin); unlock(pin) opens the vault in main and answers
only { ok } or why not, so the master password stays in main.

The policy is the one Aegis's PIN screens describe: five wrong PINs
lock the PIN for 15 minutes, every further wrong one locks it again,
and the master password always works. The unlock prompt uses the same
PIN pad and the same wording as Aegis, and Settings says so.
2026-10-04 04:15:15 +02:00
Local Dev
b292408cea Theseus: credit a wiz:// pairing link only to the top document
will-navigate and the window-open handler routed every wiz:// link to
the wallet with the top-level URL's origin, whichever frame raised it.
An ad iframe on a trusted dapp could window.open() a pairing URI and
the pairing prompt would name the trusted site; one click on Pair gave
the attacker the wallet's xpubs and a standing signing channel. A
link must now come from the main frame (navigation initiator, or for
window.open the referrer's origin), and only on pages where the wallet
is allowed by the inject policy.
2026-10-04 04:11:42 +02:00
Local Dev
b9ffe7e1a0 Theseus Settings: the vault notes describe the vault that exists
Privacy still said there is no persistent password manager and pointed to
Bitwarden or KeePass, and Passwords said autofill was "phase 2". Both
contradicted the encrypted vault and the address-bar fill button Theseus
has had for a while.
2026-10-04 04:10:50 +02:00
Local Dev
77f90dfa64 Aegis: smaller hardening from the 0.32 audit
- Electrum: a reply larger than 8 MB ends the connection; a server
  streaming without newlines used to grow the buffer without bound and
  re-parse it on every chunk, on the Electron main thread.
- Overlay amounts are formatted from integer strings: 0.1 ETH read
  0.100000000000000006, and 1 ETH + 1 wei read 1.
- The panel escapes a broadcast txid shown without an explorer link.
- A TPM refusal hands back only its own PIN attempt, not the count
  before it, which could undo guesses made in parallel.
- BCH WIF imports must carry this network's version byte and a valid
  compression flag; a 64-byte Solana keypair must have a public half
  that matches its secret half.
- WizardConnect: the overlay shows the network fee (exact, as
  SIGHASH_UTXOS commits to the inputs), marks outputs to this wallet's
  own addresses, lists every token input and every output instead of
  "... and N more" (more than 30 is refused), and a very high fee or
  token inputs get the danger button.
- DAI permits: expiry 0 reads "never expires", and the allowed flag is
  read the way the encoder signs it.
2026-10-04 04:09:45 +02:00
Local Dev
001fce02e7 Theseus: bundle Pithos 0.3.12
New installs carry the same Pithos the extension channel serves.
2026-10-04 04:06:04 +02:00
Local Dev
c79a513836 Aegis: a connected site keeps the wallet the user approved
Dapp calls resolved their wallet afresh every time: Ethereum took the
first ready wallet on the site's chain, Solana and Tron the sidebar
selection. A site connected to wallet B was served wallet A, choosing
another wallet in the sidebar re-pointed every connected Solana/Tron
site and told it the new address, and a connected site could list
every EVM wallet's address by looping wallet_switchEthereumChain and
reading the account after each switch.

Grants now record the wallet id and address the user approved, and
calls use exactly that wallet (older grants are bound on first use; a
missing wallet is an error, not a substitute). A switch to a chain
whose wallet has a different address is asked for. A site can no
longer "add" a built-in chain id with its own RPC and get a second
mainnet wallet; chainMeta has no chainId for built-in networks, so
that check never matched.
2026-10-04 04:05:45 +02:00
Local Dev
bd6e990598 Aegis: BCH payments list only the payees and show a site's OP_RETURN data
The HD wallet's plan listed the change output as a recipient with no
address, so a dapp payment overlay showed "To #2: undefined" and an
Amount and Total inflated by the change; the imported wallet's total
counted change and left out the fee. Plans now list payees only, with
total = payees + fee.

A site's memo went on-chain as OP_RETURN data without appearing on the
overlay, and could ride on a silent allowance payment. It is now a row,
and a payment carrying data always asks. A 32-byte-hash cashaddr was
forced into a 20-byte template, producing an unspendable script; it is
refused.
2026-10-04 04:01:58 +02:00
Local Dev
df7f26552a Aegis: judge EIP-712 risk from its structure and encode it strictly
Non-Permit typed data was flagged only when its primaryType was on a
short list (Seaport, SafeTx, ...); any other order, relay or
account-abstraction type got a plain Sign button and no PIN. Every
signed field is now listed with its declared type, and a payload that
names an address other than the user's and the verifying contract
together with an amount, or carries raw bytes, gets the danger button
and the PIN; text-only payloads stay ordinary.

The encoder signed "false" as true, turned non-hex characters into zero
bytes, wrapped integers past their width (2^256+5 signed as 5) and
signed a non-array as an empty array, each while the overlay showed
the original value. Such input is now refused before any overlay.
Domain rows and the chain check use only the fields EIP712Domain
declares; others are labelled as not signed.
2026-10-04 03:59:28 +02:00
Local Dev
cc8a87c5d6 Aegis: dapp overlays show fees and flag risky Solana, Ethereum and Tron calls
Solana: a ComputeBudget price the site added was paid on top of the
base fee but shown as "program ComputeB...: not decoded", so a
transaction could burn the balance in priority fees behind a plain
Sign button. The maximum network fee is now a row, and Assign, durable
nonces, Approve/ApproveChecked, SetAuthority, closing a token account
to someone else and very high fees get a warning and the danger button.
signAndSend also requires one signature slot per required signer.

Ethereum: only allowances of 2^255 and up counted as unlimited; 2^96
and up now does, and Permit2 approve, increaseApproval, NFT
safeTransferFrom and multicall are decoded. The estimate shown was
gas x the node's price even when the site set a far higher tip, which
is what is actually paid; it now uses base fee + the real tip (or the
full legacy gasPrice) and warns when the site's fee is far above the
network's or a fifth of the balance. A personal_sign over 32 raw bytes
is a hash a Safe or an order book will take as approval of something
unseen, so it gets the danger button and the PIN.

Tron: TRC10 sent along with a contract call (call_token_value) was
never read, contract types Aegis does not decode were shown by name as
if harmless, a truncated TRC20 call rendered as "undefined", and the
validity window was hidden. Those are now shown, flagged or refused;
the TronGrid draft check also refuses a memo, a permission id or an
expiration more than a day away.
2026-10-04 03:56:45 +02:00
Local Dev
d38da383d9 Aegis: stay-unlocked needs a real keystore and the right password
Remember-me sealed the master password with whatever safeStorage
offered, which on Linux without a keyring is a constant key, i.e. the
password in the clear in the add-on store; and it stored any string
without checking it. It now uses the same keystore test as the PIN,
verifies the password with the vault first, and drops a blob sealed
under no real keystore. Settings says that remember-me leaves the
master password readable to anything running as the user, which the
PIN's TPM protection does not change.
2026-10-04 03:49:40 +02:00
Local Dev
e72c0ed96b Aegis: check every BTC/DGB input against its previous transaction
Coin selection, change and the fee on the overlay came from the
Electrum server's listunspent values, and a legacy signature does not
commit to the value it spends. A server that under-reported a P2PKH
coin made Aegis sign away the difference as fee: a 1,000,000 sat coin
reported as 100,000 produced a transaction paying 901,180 sat while
the overlay said 1,180. Segwit v0 commits only to its own input, which
leaves the two-request variant open.

Every non-taproot input's previous transaction is now fetched, its txid
recomputed, and its output's value and script compared with the plan;
the fee of the finalized PSBT must equal the approved one.
2026-10-04 03:49:39 +02:00
Local Dev
3264c6d019 Aegis: WizardConnect relay keys from the real root, overlay names the pairing origin
mountWallet zeroed the vault root after mounting, but the WizardConnect
adapter kept a reference to that same buffer and read it again for
every new pairing's relay key. Every pairing made after mount therefore
got a Nostr identity derived from 32 zero bytes and the pairing URI
alone, so anyone who saw the URI (the QR, a script on the dapp page)
could read the relay traffic, xpubs included, and speak as the wallet.
The adapter now gets, and keeps, its own copy.

The signing overlay and the PIN request named the dapp by its own
userPrompt, so a dapp paired once could present itself as any site.
The pairing origin the host verified is now recorded per URI and shown
instead; the dapp's text is a quoted row with invisible and bidi
characters removed. One sign request per connection may be on screen
at a time, and revoking a site in Aegis ends its pairings too.
2026-10-04 03:45:34 +02:00
Local Dev
561cb122ea Vault PIN: tie it to the TPM and never store it unsealed
Theseus's own quick-unlock PIN had the same limit as Aegis's: once the
DPAPI seal is opened (as the user, or from a disk image plus the
Windows password) the 6-digit PIN falls to an offline search. The PIN
is now also the authorization value of a Platform Crypto Provider TPM
key whose secret is mixed into the wrapping key, so the chip's lockout
bounds guessing; lib/tpm-pin.cjs is the same module Aegis uses.

set() now refuses when there is no real OS keystore (Linux basic_text
included) instead of writing the blob in the clear, an unsealed record
from an older build is deleted, and Settings says what the PIN actually
protects against on this machine.
2026-10-04 03:42:02 +02:00
Local Dev
cda17fc885 Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed
A 6-digit PIN behind PBKDF2 + DPAPI falls in minutes to anything that
can open DPAPI (malware running as the user, a disk image plus the
Windows password). The PIN is now also the authorization value of a
TPM key from the Microsoft Platform Crypto Provider; the key releases a
secret mixed with PBKDF2(pin), so the stored blob alone opens nothing
and the chip's own lockout (32 failures, then one per 10 minutes)
limits guesses however the blob was obtained. Reached through Windows
PowerShell's CNG classes with the PIN on stdin, so no native module.
Machines without a TPM keep the software PIN, and Settings now says
plainly what that protects against.

A PIN is no longer stored when there is no real OS keystore (including
Linux's basic_text backend, whose key is a constant); a pre-0.31 plain
blob is sealed or deleted and remembered, so the panel can tell the
user to change the master password if the profile was ever copied.
2026-10-04 03:42:02 +02:00
Local Dev
0514d2d4e3 Merge aegis-pin-view: Aegis 0.31.1 restores the earlier PIN screens 2026-10-04 03:40:18 +02:00
Local Dev
4117a010c4 Aegis 0.31.1: the PIN screens look and behave as they did before 0.31
0.31 moved the PIN check into index.js and, with it, replaced the
15-minute lockout after five wrong PINs by "PIN off until the master
password", with new wording on every PIN screen. The user wants the
screens as they were. The wording, the lockout and the switch to the
master password are back; the check stays in index.js, so the lockout is
now enforced by the host and the panel still never sees the PIN blob.
After the lockout every further wrong PIN locks it again.
2026-10-04 03:40:10 +02:00
Local Dev
af95af4540 Merge master: Theseus 0.3.76 release 2026-10-04 03:38:28 +02:00
Local Dev
d355bbbf87 Theseus: bundle Pithos 0.3.11
New installs carry the same Pithos the extension channel serves, including
drives on Silent Mode and the Sia account card.
2026-10-04 03:36:50 +02:00
Local Dev
7d080c3383 Theseus 0.3.76: Pithos at pithos.sia, music in background tabs, Aegis 0.31
Built-in extensions can answer paths under a name they ship with, so
Pithos opens at pithos.sia/<user>/<drive>/<folder> instead of a
loopback address, signed in only while the vault is unlocked. A tab
playing sound is no longer frozen in the background, so music keeps
playing when you switch tabs. A widened left panel covers the page
instead of squeezing it and the right sidebar. The tab that was open
at close loads on launch. Bundles Pithos 0.3.10 (views, compact sidebar
layout, music player, updater footer, Account page) and Aegis 0.31.0
(the audit fixes).
2026-10-04 03:36:15 +02:00
Local Dev
399e763745 Theseus: bundle Pithos 0.3.10 2026-10-04 03:29:32 +02:00
Local Dev
bdc8f951c6 Theseus: built-in extensions can answer paths under a name they ship with
Pithos needs its full-page app at pithos.sia/<user>/<drive>/<folder>
instead of a loopback address. A new site-route capability lets a
built-in add-on declare names in its manifest (siteRoutes) and register
a handler for them; the bns:// handler asks it first for every path but
the root, and a handler that returns nothing hands the request back to
the name's own site. Community add-ons cannot use it, since answering
for a name is impersonating it.
2026-10-04 03:29:30 +02:00
Local Dev
556a22b062 Theseus: bundle Pithos 0.3.9 2026-10-04 03:18:25 +02:00
Local Dev
6fd44db1d6 Theseus: the tab that was open at close loads on launch
Restore left every tab dormant, the active one included, so a fresh launch
showed the right tab highlighted over an empty page until it was clicked,
which reads as a broken restore. The active tab now loads as soon as the
toolbar has painted; every other restored tab stays dormant until it is
activated, so launch still costs one page renderer.
2026-10-04 03:03:17 +02:00
Local Dev
5e67f81a94 Theseus: bundle Pithos 0.3.8 with the menu and Account page 2026-10-04 03:01:00 +02:00