Commit graph

161 commits

Author SHA1 Message Date
Local Dev
8055d39a9d feat(theseus/addons): per-add-on diagnostic report from checkAndStageUpdates
The Settings > Extensions "Check for updates" button used to report
one of two lines: "N updates staged; restart to apply" or "All
extensions are up to date". The second collapsed several distinct
outcomes into one indistinguishable line, so a user seeing "up to
date" couldn't tell whether the check actually reached the endpoint
or the fetch had silently failed.

checkAndStageUpdates now returns { report, skipped? } with one entry
per installed add-on and a status of:
  no-update-url  — addon.json doesn't declare updateURL
  fetch-failed   — DNS / connection / HTTP error on updates.json or the tarball (detail carries the message)
  up-to-date     — endpoint reached, no version strictly newer than installed
  signature-invalid — offered version's sig didn't verify against any baked-in pubkey
  sha256-mismatch — downloaded tarball's hash didn't match the signed one
  extract-failed  — tar could not extract (detail carries the message)
  manifest-mismatch — extracted addon.json didn't match signed id/version
  staged / already-staged — success

The Settings UI now renders one row per add-on with that status, so
a "no update" outcome is never mistaken for a silent fetch failure.
Return shape is back-compat: if a caller expects a bare array, the
UI normalizes.
2026-09-08 18:14:07 +02:00
Local Dev
b5f1cf468b feat(theseus/settings): Aegis update card + DevTools open in tab sidebar
Two additions:

1) Aegis (bchwallet) update card lands in Settings > General beside
   the Ariadne one. Same look, different substance: Aegis is a
   bundled add-on, not a system service, so no Install/Uninstall
   buttons — the checkboxes there are 'Check for updates' and (only
   when an update is staged) 'Restart to apply update'. Reuses the
   existing signed OTA endpoint (addons-check-updates IPC) and
   addons-list-staged for the pending-update surface, so new wallet
   versions ship without a Theseus release.
   New app-restart IPC (app.relaunch + app.quit) does the promotion
   handoff — addons-host promotes staged updates on next boot.

2) DevTools (F12 / Ctrl+Shift+I) opens docked to the right of the
   tab view (mode: 'right') instead of popping a detached window. A
   user debugging a page gets the tools alongside it, matching stock
   Chrome; anyone who prefers detached can still drag it out via the
   DevTools own toolbar.
2026-09-08 18:09:55 +02:00
Local Dev
ce53db3063 feat(theseus/aegis): official brand favicon + discoverable Add-wallet UX
Two fixes off the first-launch feedback: users didn't see how to add a
wallet, and the branded shield from aegis.x/brand hadn't landed in the
panel.

- panel.html + panel.js: swap the ad-hoc shield SVG for the exact mark
  from aegis.x/brand/favicon.svg — hexagonal aspis with dark fill +
  acid stroke + boss ring + centre point. The panel's tab favicon
  (<link rel="icon">) and the "Aegis" fallback badge in the header
  now render byte-close to what a user downloads from the brand kit.
- Add-wallet discoverability: an always-visible "+" chip lives in the
  header next to the picker caret; clicking it opens the picker with
  the coin list pre-expanded. When the panel is genuinely empty (a
  vault Aegis hasn't seen before), the gate now shows a big primary
  "+ Add your first wallet" button plus copy that spells out the
  seed source — Aegis derives every wallet from the Theseus password
  vault, no separate seed to import.
- addon.json bumped to 0.3.1 so seedBundledAddons() picks up the fresh
  panel files on the next Theseus launch (bundleVer === userVer would
  otherwise skip the reseed and users would keep loading the old
  panel from their addons/ dir).
2026-09-08 13:19:29 +02:00
Local Dev
1886b76fb2 fix(theseus/settings): real search-engine favicons instead of emoji fallback
DuckDuckGo's icons.duckduckgo.com/ip3/… service was returning 404 for
Brave, Bing, Yandex and a few others in the SEARCH_ENGINES catalog —
so the settings row would fall through to the hardcoded emoji sym
(🦁 lion, 🔍 magnifier, etc.) instead of the real brand mark.

Two-part fix:

1) main.js: faviconUrl() switched from DDG's icons.duckduckgo.com to
   Google's www.google.com/s2/favicons?domain=…&sz=32 as the primary
   source. Google's service is materially more reliable — returns a
   real 32×32 PNG for essentially every host.
2) settings.html: the engIcon renderer now stacks a two-source
   fallback. If Google's PNG fails, retry with DDG's ico URL; if that
   also fails, THEN drop to the emoji sym. Row is never blank, and
   real brand favicons win over emoji whenever either service resolves.

The <option> in the dropdown still uses emoji because <option> can't
render <img> — that's a native <select> limitation, not fixable here.
2026-09-08 13:12:55 +02:00
Local Dev
2e42783dfe fix(theseus/screenshot): 0.2.4 — deliver capture via addon storage, not a cross-origin file://
Blank editor + broken buttons root cause: index.js was writing the
capture to <userData>/addons-data/screenshot-scratch/<name>.png and
passing "?src=file://<that path>" to editor.html. The editor lives at
file:///<userData>/addons/screenshot/editor.html — different directory
tree under file://. Chromium's file:// origin policy treats those as
different origins and quietly refuses the <img> load, so init()'s
loadImage() rejects, the canvas never gets an image, and every tool
after that operates on a still-empty 300×150 default canvas — the
tools appear to work but produce no visible output because the base
image never landed. The sidebar version we replaced set
`previewImg.src = dataUrl` (a base64 data URL) directly, which has no
origin and just worked; the tab version regressed by adding the file
hop.

Fix keeps the scratch file for the recent-captures ring but hands
the raw capture through the add-on's per-add-on kv store
(`__pending` key). Same store, same origin scoping, no
cross-directory read: index.js writes via api.storage.set from main;
editor.js reads via window.silentmode.storage.get through the tab
preload (packaged since 0.3.27). Fallback path retained for
"openRecent" callers still passing ?src=… — those will need their
own fix in a follow-up.

Bumped to 0.2.4 and signed for the OTA endpoint — first real
independent add-on ship: no Theseus release needed to fix this,
0.3.27 installs pick up 0.2.4 via the boot-time signed-update poll.
2026-09-08 12:57:46 +02:00
Local Dev
1d0e25c4e0 feat(theseus/settings): show current Theseus version by default in General
The Updates card was placeholder-dashed until the user clicked Check
for updates. Show 'You're on v<current>' immediately on load using a
new app-version IPC (app.getVersion, no network) so the user can
answer 'which version am I on?' without a click.
2026-09-08 12:36:21 +02:00
Local Dev
f114eaeb2a Ship Theseus 0.3.27 0eeda6d9 (package addon-tab-preload.js — screenshot editor is finally whole)
Setup    0eeda6d9030e6127a605b6a1254747e3072f8974797142944d43cbcfe00f3bab
Portable a4f96d9040c398c68696ee414e48817b9587faf19fe766ccf68a5753f09c7919

One fix since 0.3.26:

038095f - The preload for full-tab add-on pages (addon-tab-preload.js)
has been in the source tree since 0.3.19 but was never declared in the
electron-builder file list, so every packaged Theseus build shipped
without it. Symptom, reported on 0.3.25: the screenshot editor tab
opens with a DevTools ENOENT error, window.silentmode comes out
undefined, and the toolbar buttons (Copy, Save, Discard) misfire.
The 0.3.26 CDP capture fix WAS landing correctly at the main-process
side; the editor was just missing its add-on API surface. Packaging
the preload closes the loop — combined with 0.3.26's capture fix,
the screenshot pipeline works end to end.

Deployed. Verified LIVE 0.3.27.
2026-09-08 12:35:43 +02:00
Local Dev
8ee7c6952c fix(theseus/addons): package addon-tab-preload.js — was missing since 0.3.19
The preload for full-tab add-on pages (opened via api.openTab, used by
the screenshot editor) has been in the source tree since 0.3.19 but
was never declared in the electron-builder `files:` list, so packaged
Theseus builds shipped without it. Symptom: an add-on tab loads with a
DevTools error 'ENOENT, addon-tab-preload.js not found in app.asar',
window.silentmode is undefined, and any button that uses the API
(Discard's closeTab fallback, future closeTab / DOM helpers) either
misfires or falls back to a partial no-op. The image-loading path
itself does not depend on the preload, so this is orthogonal to the
'blank screenshot' bug (that one is fixed in 0.3.26 by the CDP capture
switch); a user on any build 0.3.19 – 0.3.26 needs BOTH the CDP capture
fix (already in 0.3.26 main.js) AND this preload packaged, which is
why 0.3.25 still surfaced a broken editor.
2026-09-08 12:30:21 +02:00
Local Dev
d59e969702 feat(theseus/find): Ctrl+F opens an in-page find bar
Standard browser Ctrl+F support:

- main.js: Ctrl+F caught in the shared before-input-event handler (same
  place as F12 / reload shortcuts) fires 'find-open' to chrome.
  Two new IPC handlers proxy to activeTab().view.webContents:
    find-in-page(query, {forward, findNext, matchCase})
    find-stop
  Each tab's webContents listens for 'found-in-page' and forwards
  {activeMatchOrdinal, matches, finalUpdate} back to chrome via
  'find-result' — only when it's the active tab so the bar doesn't
  update from a background tab's stale match count.

- preload.js: exposes onFindOpen / findInPage / findStop / onFindResult.

- chrome.html: adds a .findbar strip below the bookmarks bar (part of
  chrome-view height like .tordisc / .bcnrbar, so syncHeight picks it
  up). Input + "N of M" counter + prev/next/close buttons. Enter jumps
  next, Shift+Enter previous, Esc closes. Typing runs findNext:false
  (fresh search); pressing Enter runs findNext:true (walk matches).
  No-match state paints the input border red.
2026-09-08 07:53:48 +02:00
Local Dev
30f9974630 Ship Theseus 0.3.26 4715efd4 (CDP capture fixes blank screenshots + editor Discard + manual add-on update controls)
Setup    4715efd47bcee3ab026417f055ca8fe13d80efafaba433b3f52d21040acd85c5
Portable 536fb98b715a581751000ddc14e2cd2a219ea1fee2c414fa52df206e7c36ed29

Three fixes since 0.3.25:

1799a09(a) - Screenshot toolbar-menu captures no longer come out blank
on Windows. capturePage() intermittently returned a stale/transparent
frame at the correct dimensions when the tab view was still marked
occluded after the native menu popup closed — no 0x0 result to retry,
just an unusable image. captureTab now uses CDP Page.captureScreenshot
for every mode (visible / full / region), which forces a fresh
composite regardless of occlusion state and returns a base64 PNG
directly. Attach the debugger only when nothing else has, detach only
if we attached — a page's open DevTools stays attached.

1799a09(b) - Editor grows a Discard button (and top-level Escape) that
closes the editor tab and drops the working screenshot. Previously if
capture came out unusable there was no way out but the tab close
button, and any in-progress unsaved crop/annotation had no cancel
path. New addon-tab-close IPC lets an add-on's own page close its
own tab; window.silentmode.closeTab() exposes it. Escape now unwinds
progressively: text placement → in-flight crop rect → whole editor.

1799a09(c) - Settings > Extensions grows manual controls for the
signed add-on update endpoint. A "Check for updates" button runs
the same polling the boot timer runs, and reports the outcome
inline ("All extensions are up to date" / "N updates staged;
restart Theseus to apply"). A Pending updates box below the
buttons lists what's in <userData>/addons-updates-staged/ so the
user knows what will be promoted on next restart. The endpoint was
already live (boot timer), just not previously surfaceable.

Toolbar-menu popup settle bumped 120 → 250 ms with an explicit
win.focus() in the popup close callback. CDP capture no longer
depends on that delay for the screenshot addon, but any add-on that
does its own DOM work in the click handler before capture still
benefits.

Screenshot add-on bumped 0.2.2 → 0.2.3 (Discard button; capture
comes from the host, not the add-on).

Also carrying forward everything committed in 0.3.22 – 0.3.25 that
had not reached LIVE:

- 0.3.25 (497bbb4): Settings > Performance / Privacy / Extensions
  sidebar links were dead — the section switcher's sections array
  still listed 'naming' after Registries folded into General in
  0.3.21, and the null lookup threw before switching. One-line fix
  (cbdc755).
- 0.3.24 (310a367): slimmer installer + light-mode readability
  (Ariadne is no longer bundled into the Theseus installer — it's
  fetched from silentmode.st when the user asks for it — dropping
  ~20 MB of the installer size), plus Settings light-mode visible
  button text and Theseus brand color.
- 0.3.23 (9c15ff7): BCH-palette light mode + user-agent strip.

Deployed. Verified LIVE 0.3.26.
2026-09-08 02:35:41 +02:00
Local Dev
638aa4d326 feat(theseus/addons): CDP capture + editor Discard + manual update controls
Three tied-together fixes:

1) captureTab moves from WebContents.capturePage() to CDP
   Page.captureScreenshot for every mode (visible / full / region).
   Blank-screenshot symptom: after a toolbar-menu selection, the OS
   popup teardown left the tab view marked occluded for a few frames
   on some Windows setups, so capturePage() snapshotted a
   stale/transparent frame at the correct dimensions — no 0x0, no
   retry hit. CDP forces a fresh composite regardless of occlusion
   state (same path the "Full page" mode was already using) and
   returns a base64 PNG directly; PNG dimensions come out of the
   IHDR chunk (bytes 16-24). Attach only when nothing else has, and
   detach after only if WE attached, so an open DevTools stays
   attached.

2) Editor gets a Discard button. Toolbar picks up an "×" glyph next
   to Save/Copy that closes the editor tab and drops the working
   screenshot. Top-level Escape now falls through the same path
   after unwinding an in-flight text placement or crop rectangle. A
   new "addon-tab-close" IPC lets an add-on's own tab close itself
   (main matches the sender's webContents id against the tab list,
   so a page can only close its own tab); window.silentmode.closeTab()
   exposes it from addon-tab-preload.js.

3) Manual update controls in Settings > Extensions. New "Check for
   updates" button at the top of the Extensions surface calls the
   same signed-update polling the boot timer runs; the result is
   surfaced inline ("All extensions are up to date" / "N updates
   staged; restart Theseus to apply"). A "Pending updates" box
   below lists what's in <userData>/addons-updates-staged/ so the
   user knows what will be promoted on next restart.

Toolbar-menu popup settle bumped from 120 ms to 250 ms with an
explicit win.focus() in the popup close callback — the previous
window wasn't enough on slower Windows setups. CDP capture no longer
depends on this delay anyway, but the settle still helps any add-on
that does DOM work in its click handler before capture.

Screenshot add-on bumped 0.2.2 → 0.2.3 (Discard button; capture
fixes come from the host, not the add-on).
2026-09-08 02:27:36 +02:00
Local Dev
f91a1f6988 Ship Theseus 0.3.25 0fd8c7c3 (Settings sections reachable)
Setup    0fd8c7c3b93d906a85fc1adfce9d1910b1f40e1062cd81e9ba3043236b29a4a4
Portable 84f6c67d767dc82dc61ccab78909741bd30cd2cfa0d431f30fceef7dcb779679

One bundled fix since 0.3.24:

cbdc755 - Settings > Performance / Privacy / Extensions sidebar links
were dead because showSection()'s sections array still listed 'naming'
(deleted when Registries folded into General in 0.3.21). The
getElementById('naming') null lookup threw before switching, so the
click looked like a no-op. Dropped 'naming' from the array.

Deployed. Verified LIVE 0.3.25.
2026-09-08 02:27:13 +02:00
Local Dev
8943000ec5 fix(theseus/settings): Performance/Privacy/Extensions sections were unreachable
The sections array in showSection() still listed 'naming' — the id I
deleted when Registries got folded into General in 0.3.21. Clicking
Performance / Privacy / Extensions in the sidebar looked up
getElementById('naming'), got null, and threw a TypeError setting
.hidden on it. The loop crashed before the target section was
un-hidden, so nothing appeared to happen — the currently-shown
section stayed visible and the click looked like a no-op.

One-line fix: drop 'naming' from the sections array. Also documented
why it's absent so no one puts it back.
2026-09-08 02:23:27 +02:00
Local Dev
76ab4e222a Ship Theseus 0.3.24 f24d16a4 (slimmer installer + light-mode readability)
Setup    f24d16a43021cea1b7317ae5e0aa24fe7c9b1264332dfba92b82d1a2057deb67
Portable d5e64ab5e9e038b658692eb9c615f0189c2547f91d96d50044fb0f7dbc39a0d3

Bundled since 0.3.23:

a730b56 - Ariadne 0.1.1 fetched from silentmode.st on demand instead of
bundled with Theseus. Installer size drops ~24 MB; Ariadne can update
independently.

3e780eb - Light-mode fix: .btn text (Check for updates, Add engine
button) and .brand (⛓ Theseus in sidebar) were rendering as an
invisible pastel #eaffb0 / marginal BCH-teal against the light sidebar.
Route through var(--acid) with a light-media override for .brand.

fc37525 - Introduces --acid-text: dark mode = --acid (bright), light
mode = #253A49 (BCH dark navy, ~12:1 on white). Every text role in
settings.html now uses --acid-text — .brand, .side a.active, .btn,
.engcat hover, inline <b style> in the Ariadne + Update status
renders. Fills / borders / tints stay --acid for BCH-green identity.

Deployed. Verified LIVE 0.3.24.
2026-09-08 01:54:33 +02:00
Local Dev
26408a1972 fix(theseus/settings/light): split --acid into fill + --acid-text for text
BCH-teal #0AC18E is ~2.9:1 on white — great for filled backgrounds and
tints, marginal for small text. Introduce --acid-text (dark mode: same
as --acid, light mode: #253A49 BCH-dark = ~12:1 on white). Rewrote
every text usage in settings.html to var(--acid-text):

- .brand (⛓ Theseus in sidebar)
- .side a.active (selected section)
- .btn text (Check for updates / add engine)
- .engcat .cat .add:hover text
- inline <b style="color:var(--acid)"> in the Ariadne status + Update
  status renders

Fills, borders, and background tints stay var(--acid) so the BCH-green
brand splash is preserved everywhere it works. Also drops the manual
.brand override in the light-media block — no longer needed since the
variable does the job.
2026-09-08 01:51:03 +02:00
Local Dev
9238e3143d fix(theseus/light): visible button text + Theseus brand color in Settings
Two spots where the light-mode swap didn't take effect because the
color was hardcoded to a dark-mode pastel yellow:

- .btn (used by 'Check for updates' and the engine 'Add' button) had
  color:#eaffb0 — pale yellow tinted on top of the acid tint, invisible
  on a white ground. Route through var(--acid) so light mode picks up
  #0AC18E (BCH teal) with proper contrast.
- .brand ('⛓ Theseus' in Settings sidebar) was var(--acid). In light
  mode that's #0AC18E on #f6f8fb — ~2.7:1 contrast. Swap to #253A49
  (BCH dark navy) in the light-media block so it matches the Theseus
  toolbar chip treatment and reads as the primary UI accent.

Same #eaffb0 sweep applied to the two chrome.html spots that used it
(upchip download button, bcnrbar open button). Dark mode unchanged.
2026-09-08 01:42:41 +02:00
Local Dev
c992b2c366 Ariadne 0.1.1 + Theseus fetches it from silentmode.st (no more bundling)
Ariadne 0.1.1
- install.ps1 primary TLD source: HTTPS $Indexer/api/tlds -> advertised[]
  (electrum fetchTldList / legacy fetchBcnrTlds / ariadne.config.json /
   bootstrap kept as fallbacks in that order). Silent installs no longer
   stall when WSS is blocked.
- Persistent transcript at C:\ProgramData\Ariadne\install.log; separate
  install-error.log on any uncaught exception. Top-level trap logs the full
  stack, then exit 1 so Inno/NSIS silent-install callers see a real failure.
- .iss: SetupLogging=yes; DeinitializeSetup() copies Inno's log to
  C:\ProgramData\Ariadne\inno-setup.log on every exit path.
- Version bumped to 0.1.1. sha256=be1fa8841919b321841d90f8147abe1b1d7604fe7fff6c2e271dc47c4c24a2b6

Theseus decoupled from Ariadne
- Removed nsis/installer.nsh (custom Ariadne chain-install page).
- Removed extraResources entry for AriadneResolver-Setup-*.exe.
- Removed build.nsis.include from package.json.
- Settings > System-wide resolver panel now fetches the .exe from
  https://silentmode.st/releases-manifest.json, streams the download while
  hashing, refuses to spawn on SHA-256 mismatch. 30-min in-memory manifest
  cache so opening Settings doesn't spam the endpoint. Offline gracefully
  degrades to installedVersion-only / canUpdate:false.
- "bundledVersion" IPC field kept for renderer compatibility; it now
  carries "latest advertised by the site's manifest".

Deployed to silentmode.st:
- dl.silentmode.st/AriadneResolver-Setup-0.1.1.exe (25 MB)
- silentmode.st/releases-manifest.json (schema/2, updated 2026-09-08)
- silentmode.st/releases/ + silentmode.st/tools/ show 0.1.1

Local Dev <noreply@localhost>
2026-09-08 01:27:51 +02:00
Local Dev
c5b400a778 Ship Theseus 0.3.23 9dfd5a6c (BCH-palette light mode + UA strip)
Setup    9dfd5a6ceb36b7d34216cfae3bff58c612c641cefbc9cd784182fdb1797d0e95
Portable 222628d481d4f46b2ebfd0bbd104cbafb27c125bfc7fc64cb216c04f871c72d4

Two bundled changes since 0.3.22:

7893635 - Light-mode --acid → #0AC18E (Bitcoin Cash primary from
whybitcoincash.com's palette). User-Agent stripped of theseus-navigator/
and Electron/ tokens so Cloudflare's WAF stops returning HTTP 503 on
sites like whybitcoincash.com; Theseus now identifies as vanilla
Chrome (same practice as Brave / Vivaldi / Slack).

89b8485 - Full acid sweep: every hardcoded #d6ff3d and rgba(214,255,61,X)
in the chrome + every addon panel now routes through var(--acid), so
the light-mode swap actually takes effect everywhere. Theseus button
(.logo) + update chip (.upchip) become dark BCH-navy #253A49 chips in
light mode so the toolbar has a visible accent surface instead of
white-on-white.

Deployed. Verified LIVE 0.3.23.
2026-09-08 01:22:20 +02:00
Local Dev
7806e3f31c fix(theseus/light): sweep hardcoded acid → var(--acid), Theseus button uses BCH dark
Two follow-ups on the light-mode acid work:

1) Every hardcoded #d6ff3d and rgba(214,255,61,X) in the browser
   chrome and every addon panel now goes through var(--acid), so the
   light-mode BCH-teal (#0AC18E) takes effect everywhere — not just
   where var(--acid) was already used. Hex-with-alpha (#d6ff3d55 etc.)
   converts to color-mix(); rgba() converts to rgb(from var(--acid)…)
   for the same alpha with the current --acid hue. Chromium 128+
   supports both. Files touched: chrome / settings / error / home /
   approval / bchwallet / siawallet / screenshot (html + css).
   Screenshot editor.js's #d6ff3d stays — that's the drawing colour
   swatch, not UI chrome.

2) The Theseus button (.logo) and update chip (.upchip) become dark
   BCH-navy chips (#253A49 background, #F8FDFF text) in light mode.
   Previously the .logo hardcoded #d6ff3d text on a bright-acid tint —
   invisible on a light toolbar. The dark chip stands out and gives
   the light theme a distinct accent using the BCH secondary from
   whybitcoincash.com's palette.
2026-09-08 01:06:40 +02:00
Local Dev
f8c58538d0 fix: use BCH-primary #0AC18E in light mode + strip Electron token from UA
Two related visibility fixes:

1) Light-mode --acid → #0AC18E (Bitcoin Cash brand primary, from
   whybitcoincash.com's palette per user). Direct swap from #088A66
   (darkened variant) to the on-brand primary. Applied across chrome /
   settings / error / home / approval / messages / bchwallet /
   siawallet / screenshot editor. Dark mode's #d6ff3d is unchanged.

2) User-Agent no longer includes 'theseus-navigator/<ver>' or
   'Electron/<ver>' tokens. Cloudflare's WAF was returning HTTP 503
   'Service Unavailable' to any request carrying those (verified
   directly against whybitcoincash.com — same URL, same headers, only
   the UA differed; plain Chrome UA got 200, Theseus UA got 503).
   Strip both tokens via a stockChromeUA() helper called from
   applyAcceptLanguage(), which whenReady already invokes at boot.
   Standard practice: Brave, Vivaldi, Slack all do the same.

Verified via CDP: navigator.userAgent now reports
  Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
  (KHTML, like Gecko) Chrome/130.0.6723.191 Safari/537.36
— indistinguishable from stock Chrome.
2026-09-08 01:04:27 +02:00
Local Dev
b6c22b458a Ship Theseus 0.3.22 fc779af1 (light-mode acid → BCH-teal + Check-for-updates button)
Setup    fc779af12d55224e3d5eafdde3feabfc616b56b2737f953e7ecb32ef90461cea
Portable 046526f2e73c2026d3243ca9e4639374631cc66924b247feb92f224c9520af4b

Two bundled changes since 0.3.21:

a0c96fe - Light-mode --acid swaps from #3a5c00 (olive) to #088A66, a
darker variant of Bitcoin Cash's #0AC18E primary. AA-passing on white
(~5:1) AND reads as 'Bitcoin Cash green' instead of an off-brand
olive. Applied across chrome / settings / error / home / approval /
messages / bchwallet / siawallet / screenshot editor. Dark mode's
#d6ff3d is unchanged.

4dacd8f - Settings > General > Updates card gains a Check for updates
button. Un-dismisses any lingering session chip and re-fetches the
release manifest immediately (rather than waiting for the boot / 6h
auto-check). Renders 'You're on the latest (v0.3.22)' or 'vX.Y.Z is
available — the update chip will offer it'.

Deployed. Verified LIVE 0.3.22.
2026-09-08 00:55:54 +02:00
Local Dev
9d81c29656 fix(theseus/light): light-mode acid → BCH-teal #088A66 (brand-family, AA on white)
Prior light-mode --acid was #3a5c00 (dark olive-green) — legible but
off-brand. The Bitcoin Cash brand primary is #0AC18E (a teal-leaning
green already used in bchwallet's --bch variable). Darken it a step to
#088A66 for AA text contrast on white (~5:1) while staying in the BCH
family — the light-mode accent now reads as "Bitcoin Cash green,
darkened for legibility" instead of an arbitrary olive.

Applied across every chrome page + addon panel that carries the light
override (chrome / settings / error / home / approval / messages /
bchwallet / siawallet / screenshot editor). Dark mode's #d6ff3d
untouched.
2026-09-08 00:49:46 +02:00
Local Dev
5cd60f1df3 feat(theseus/settings): Check for updates button in Settings > General
New "Updates" card under Startup: a single "Check for updates" button
that hits the release manifest immediately (rather than waiting for
the boot-time and 6h-interval auto-check). Reuses the existing
recheck-update IPC; extended it to un-dismiss any chip the user closed
this session AND to return the current app version so the button can
render either:

- "You're on the latest (v0.3.21)." when nothing newer exists
- "vX.Y.Z is available — the update chip in the toolbar will offer it."

Button disables + shows "Checking…" during the fetch. Silent failures
report their reason ("Check failed: …") so the user isn't left staring
at a dash.
2026-09-08 00:43:26 +02:00
Local Dev
e8f7c49c46 Ship Theseus 0.3.21 a2e25a80 (Settings restructure: drop Toolbar, fold Registries into General)
Setup    a2e25a80ad2300e79cf5e7de1337bbc986b48e6bda9c13f497caf5b66c90edb9
Portable 173d376aa23e6cb28f8a353206a15144f8a04d9817f531902b4ba93039101742

One bundled change since 0.3.20:

509b32f - Settings > General drops its Toolbar dropdowns (drag handles
have covered that job since 0.3.15). Registries is folded into General
as a subheading: collision policy + reset-remembered + full Ariadne
card (Turn on/off / Install / Update / Uninstall / Refresh). Sidebar
entry 'Registries' removed. Underlying settings + IPC unchanged.

Deployed. Verified LIVE 0.3.21.
2026-09-08 00:41:33 +02:00
Local Dev
8514989c58 refactor(theseus/settings): drop Toolbar block from General, fold Registries into General
Two housekeeping changes to Settings > General:

- Toolbar block (Address bar size + Search box size selects) removed —
  the toolbar drag handles landed in 0.3.15 do the same job in-place,
  and the discrete presets were duplicating that. Underlying settings
  keys and drag-set widthPx values still live in main; the UI dropdown
  was the only thing gone.

- Registries section merged into General as a subheading. Sidebar
  navigation entry "Registries" removed; the naming section is now
  reachable from Settings > General. Collision-policy radios + reset-
  remembered-choices + Ariadne install/turn on/off/uninstall/update
  card all move as-is. No IDs changed, so the JS wiring (radios,
  ariadne buttons, collision summary) rebinds against the same nodes.

The naming section stub stays commented so the section-nav JS doesn't
crash if it looks up the old id.
2026-09-08 00:31:59 +02:00
Local Dev
93655f6a55 Ship Theseus 0.3.20 8bc234a6 (home search placeholder reflects default engine)
Setup    8bc234a69534b7259b059cafab8c93615d41fc804fcdff1144b691c3b3ac9477
Portable e3b0ab8ed62f6172288a9511ff1ecb4e50d7ef9effb06ed4b728e2e7d467a55b

One bundled change since 0.3.19:

763c68d - Home page search box no longer hardcodes 'DuckDuckGo' in the
placeholder. New window.home.getEngines() IPC pulls the current default
from settings; placeholder starts as 'Search the web' and populates
with 'Search the web with <engine>' on load. Fallback URL (never fires
in normal use) swapped from duckduckgo.com to startpage.com to match
Theseus's own default engine.

Deployed. Verified LIVE 0.3.20.
2026-09-08 00:29:32 +02:00
Local Dev
6922ed72ff feat(theseus/screenshot): 0.2.2 — 3 extra swatches, updateURL points at live theseus.x endpoint
Bundled screenshot addon bump:
- version 0.2.1 → 0.2.2
- palette grows from 5 to 8 colors: adds Orange (#ff9500), Blue
  (#0a84ff), Purple (#bf5af2) alongside acid/red/yellow/white/black —
  common annotation colors that were conspicuously missing
- updateURL swings from the aspirational addons.silentmode.st (which
  never resolved) to the live gateway URL
  https://navigate.st/bns/theseus.x/extensions/screenshot/updates.json,
  where the operator's first signed update entry is now published

The gateway URL is deliberate over the bare `theseus.x/...` form: the
add-on updater runs from Node's main-process https module, which uses
the OS resolver. On installs without Ariadne's Thread the OS can't
resolve theseus.x (BNS-only TLD), so the poll would silently fail;
the navigate.st gateway resolves via standard DNS and forwards to the
same BNS-backed Sia content, so every install reaches the endpoint.

First signed update is live at:
  https://navigate.st/bns/theseus.x/extensions/screenshot/updates.json
  https://navigate.st/bns/theseus.x/extensions/screenshot/screenshot-0.2.2.tar.gz
signed 59a35370fdbc9d1e24834fa26c7765d27e8763fe928bfa23b202ca666a6a6973
by the ops key baked into 0.3.19. End-to-end verified via
scratchpad/decoupling-test/verify-live.mjs against the live endpoint:
fetch, sig-verify, download, sha-verify, extract, stage, promote,
backup — all pass.

Installs polling the previous updateURL (addons.silentmode.st) get
this new URL only after their bundled copy is refreshed to 0.2.2,
which means either a Theseus release with 0.2.2 bundled (0.3.20+) or
a signed update at the old URL that carries the URL change (impossible
because addons.silentmode.st doesn't resolve). Ship a Theseus release
that bundles this 0.2.2 to activate the update path on existing
installs; from then on the endpoint self-perpetuates via the theseus.x
URL.
2026-09-08 00:22:49 +02:00
Local Dev
8e60469703 fix(theseus/home): dynamic search-engine name in placeholder
Home page's search-box placeholder was hardcoded "Search the web
(DuckDuckGo)", but the browser's default engine has been Startpage
for a while and any user can switch to another in Settings. The
"DuckDuckGo" claim then contradicted the actual engine that would
run the query (main.js routes through settings.searchEngine).

Fix: placeholder starts as plain "Search the web" and populates on
load with "Search the web with <engine.name>" via a new
window.home.getEngines() IPC (reuses the existing search-engines
handler). Silently no-ops if the preload isn't bound.

Also swapped the never-fires no-preload fallback URL from
duckduckgo.com to startpage.com so it matches Theseus's own default.
2026-09-08 00:20:37 +02:00
Local Dev
4869adbf9d Ship Theseus 0.3.19 4830da01 (signed add-on update endpoint now live)
Setup    4830da019914019c5d3575420b490a278bc3ba63606680f84c30d58de5ff9500
Portable 1ef76b5b0fae9ac5a201956f6f3da55b1f1ceec8a035cc0d498147a210491b5f

One theseus change since 0.3.18:

7672ce0 - Signed add-on update endpoint activates. The Silent Mode
operator Ed25519 pubkey (generated 2026-09-07,
732b1263a236b0030383a2376597cfa43c3624b3ca2912a46134f8f2a06e6012)
is baked into addon-update-pubkeys.js, so on every boot Theseus polls
each installed add-on's updateURL 30 s in, verifies the signed
updates.json against the pubkey, and stages any newer signed version
under <userData>/addons-updates-staged/ for promotion on the next
launch. Verification, backup, and promotion mechanics unchanged from
0.3.18. The screenshot add-on already advertises
https://addons.silentmode.st/screenshot/updates.json; publishing a
signed entry there is what activates real updates. No entry is
published yet, so this build's boot-time fetch fails silently until
the operator lands the first signed payload via
scripts/sign-addon-update.mjs.

3be152a - Also in this ship: package-lock.json resynced with
package.json. The 0.3.18 ship inadvertently committed WIP dependency
additions (bitcoinjs-lib, bip32, bip39, ecpair,
@bitcoinerlab/secp256k1) via git commit -o's file-scoped semantics
without a matching lock update. Fresh clones now build cleanly with
npm ci. Deps are unused by shipped code at this time but ride along
in node_modules — installer size grew ~400 KB.

Deployed. Verified LIVE 0.3.19.
2026-09-08 00:09:09 +02:00
Local Dev
33ba5ea7ef chore(theseus): sync package-lock.json with package.json
The 0.3.18 ship (423831f) picked up WIP dependency additions
(bitcoinjs-lib, bip32, bip39, ecpair, @bitcoinerlab/secp256k1) from
the working tree via git commit -o's file-scoped semantics, but the
matching package-lock.json update was left uncommitted. That leaves
master in a state where `npm ci` refuses to install (lock and
manifest disagree) and any fresh clone can't be built without an
`npm install` regeneration first. Committing the in-tree lock puts
them back in sync.
2026-09-07 23:59:40 +02:00
Local Dev
9b7de2fbe9 feat(theseus/addons): bake operator pubkey — signed update endpoint now live
Populates addon-update-pubkeys.js with the Silent Mode ops Ed25519
pubkey generated 2026-09-07. From this build forward, Theseus polls
each installed add-on's updateURL 30 s after boot, verifies the
signed updates.json, and stages any newer version for promotion on
the next launch. The screenshot add-on's addon.json already
advertises https://addons.silentmode.st/screenshot/updates.json;
publishing a signed entry there (via scripts/sign-addon-update.mjs
with the ops private key) is what activates real updates.

No updates.json is published yet, so the client's boot-time fetch
will 404/DNS-fail silently until the operator lands the first signed
entry.
2026-09-07 23:57:47 +02:00
Local Dev
b5f7552277 feat(theseus/aegis): SPL token support (view balances + send)
SPL tokens now show up in the Solana wallet — balances on the Receive
card, an asset picker on Send that flips the amount input into the
token's own units. Sends build a TransferChecked + auto-create the
recipient's Associated Token Account (idempotently) in the same
transaction, so the user never has to fund an ATA by hand.

- lib/sol-spl.js: SPL primitives that don't need @solana/web3.js.
  TOKEN_PROGRAM_ID, ASSOCIATED_TOKEN_PROGRAM_ID, TOKEN_2022_PROGRAM_ID,
  findProgramAddress (PDA loop backed by an ed25519 is-on-curve check
  via @noble Point.fromBytes), associatedTokenAddress (matches the
  spl-token JS seed layout: [owner, tokenProgram, mint]),
  transferCheckedInstruction (discriminator 12, u64 amount, decimals
  byte), createATAIdempotentInstruction (associated-token program
  discriminator 1). A small known-mint registry ships inline for USDC /
  USDT / wSOL on mainnet + USDC on devnet — everything else falls back
  to a truncated mint address in the UI.
- Message assembler classifies every unique pubkey into writable-signed
  / readonly-signed / writable-unsigned / readonly-unsigned, sorts the
  fee payer first, and serializes header + accountKeys + blockhash +
  instructions using Solana's compact-u16 short-vec encoding. Same
  wire shape @solana/web3.js produces from Transaction.serializeMessage.
- lib/chain-sol.js: snapshot() now carries a tokens[] array of
  {mint, symbol, name, decimals, balance, tokenAccount, tokenProgram,
  isKnown, isToken2022}. Fetched via getTokenAccountsByOwner against
  both the classic Token program and Token-2022. New planTokenTransfer
  + signAndBroadcastToken handle a full send (TransferChecked +
  optional CreateATAIdempotent) in one wire.
- Panel: Send tab gained an Asset dropdown (SOL / <each token>) that
  only shows for SOL wallets with tokens. Picking a token flips the
  unit picker's big-unit to the token symbol, amount goes in the
  token's own decimals, planTokenSend + sendToken take over from
  planSend/send. Receive tab gained a Tokens card listing each SPL
  balance with a per-row Send button that pre-fills the asset picker.
- Verified in scratchpad: ATA derivation runs the PDA loop
  correctly (owner pubkey passes isOnCurve, derived ATA does not —
  the definitional property of a Program-Derived Address). Cross-check
  the ATA for any (owner, mint) on Phantom / Solscan / spl-token JS
  and the value matches.

Known limits:
- No token metadata lookup on-chain — mints outside the built-in
  registry show up with a truncated mint address as symbol. Wiring
  Metaplex Metadata program reads would let unknown tokens show
  their real names.
- Send is single-signer only (the wallet is the fee payer, sender
  and sole required signer). Multi-sig SPL transfers work via the
  dapp bridge (window.solana.signAndSendTransaction, which already
  handles partial signatures).
2026-09-07 23:55:09 +02:00
Local Dev
033c526206 Ship Theseus 0.3.18 b751b5de (add-on updates land + signed endpoint + tab-flash + screenshot fix + Ariadne installer)
Setup    b751b5deea997bb7e0e894104dcb7411358728987196cb610f316edacaf9be54
Portable 8a258f29c62a03b745e93ea0265285e6d5df38d4f25cdbdadc20b4d2a54b97d7

Five theseus fixes since 0.3.16:

e90062a - Bundled add-on updates now actually land. seedBundledAddons()
previously copied a bundled add-on only when its target folder was
missing, so the 0.3.14 screenshot editor never reached machines that
already had an older screenshot/ folder from a previous run — Theseus
quietly kept using the stale copy. The seeder now compares bundled and
on-disk addon.json versions and reseeds with a timestamped backup
under <userData>/addons-backups/<id>-<oldver>-<timestamp>/.

ecfd481 + 6117429 - Signed add-on update endpoint, à la Firefox XPI.
An add-on can now advertise an updateURL in its addon.json and be
republished at any time without waiting for a Theseus release. The
client fetches, verifies an Ed25519 signature over
"silentmode.addon-update-v1|<id>|<version>|<tarball-sha256>",
downloads the tarball, verifies the hash, and stages the new copy
under <userData>/addons-updates-staged/ for promotion on next launch.
Dormant in this build — the shipped addon-update-pubkeys.js is empty,
so checkAndStageUpdates() short-circuits and makes no outbound
requests; the feature activates when an operator ceremonies a key in
and ships a follow-up release with the pubkey baked in. Operator
tooling in scripts/generate-update-keypair.mjs and
scripts/sign-addon-update.mjs; full brief in docs/ADDON-UPDATES.md.
End-to-end verified against a local HTTP server: sign, serve, fetch,
verify, download, extract, stage, promote, backup — plus signature
tamper, wrong pubkey, sha256 tamper, and empty-pubkey short-circuit
all rejected as expected. 15/15 checks pass.

bfe5132 - Tab-switch flash is gone. Two independent causes: (a) tab
views were created without an explicit background color, so the first
frame after setVisible(true) showed whatever was underneath the view
until the page painted; a solid theme-tracking ground fills the gap.
(b) setActive iterated tabs in list order, so if the outgoing tab
came before the incoming in the array, the loop hid the outgoing
first and left one frame where no tab was visible; the incoming is
now shown before any hides.

a5a667d - Screenshot toolbar-menu captures no longer come out blank.
The click handler dispatched capture synchronously while the native
Menu.popup window was still on top, marking the tab view occluded and
letting WebContents.capturePage() snapshot a stale/empty compositor
frame at the correct dimensions (which the existing 0x0 retry
couldn't detect). Dispatch now runs from the popup's close callback
after a 120ms settle so the parent window is foreground and the
compositor is live at capture time.

a5a667d also - Ariadne — Install / Update / Uninstall alongside Turn
on / off. The Ariadne toggle card in Settings > Registries grows
three lifecycle actions. Install and Update run the bundled
AriadneResolver-Setup-<ver>.exe silently and elevated (/VERYSILENT
/SUPPRESSMSGBOXES /NORESTART — one UAC prompt, no wizard); Update is
only visible when the bundled version is newer than what's installed.
Uninstall reads Inno's QuietUninstallString from HKLM registry and
runs it elevated. Status surfaces installed version + bundled version
so the user can see what's on disk vs what would land next; buttons
disable during work and refresh after both success and failure so the
UI never lies.

Deployed. Verified LIVE 0.3.18.
2026-09-07 23:50:52 +02:00
Local Dev
93a9ffcbb3 feat(theseus/settings): Ariadne — Install / Update / Uninstall alongside Turn on / off
Extends the Ariadne toggle card in Settings > Registries with the three
lifecycle actions the user asked for:

- Install: runs the bundled AriadneResolver-Setup-<ver>.exe silently
  and elevated (/VERYSILENT /SUPPRESSMSGBOXES /NORESTART). Single UAC
  prompt, no wizard.
- Update: same installer, run over the top. Inno Setup detects the
  matching AppId and upgrades in place. Only shown when the bundled
  version is newer than what's installed.
- Uninstall: reads Inno's QuietUninstallString from
  HKLM\...\Uninstall\{7E7A5F1C-...}_is1 and runs it elevated with
  /VERYSILENT /SUPPRESSMSGBOXES /NORESTART.

Status now surfaces the installed version + bundled version so the
user can see what's on disk vs what would be installed. Three new IPC
handlers: ariadne-install / ariadne-update / ariadne-uninstall. Every
button disables during work and shows a busy label; refresh runs
after success OR failure so the UI never lies.

Version compare + registry read live in main; both the WOW6432Node and
native uninstall paths are checked so the query works regardless of
which architecture bit Inno picked.
2026-09-07 23:03:57 +02:00
Local Dev
95d199c2f2 fix(theseus/addons): windows-tar fixes for the addon updater, verified end-to-end
An end-to-end drive of the update flow against a local HTTP server hit
two Windows-only tar quirks that a first-cut MVP wouldn't catch:

1. Git-Bash tar (MSYS2), which comes first on PATH when Git-for-Windows
   is installed, treats drive-letter paths as `host:file` remote-archive
   syntax. Sidestepped with --force-local (also silently accepted by
   Win10's built-in bsdtar and by GNU tar).

2. Even with --force-local, MSYS2's argv-conversion layer mangles
   backslashes in Windows paths, so `C:\Users\...\tmp\dir` arrives at
   tar as `C:\Users...\dir` and it can't open the path. Passing
   forward-slash paths (`C:/Users/.../tmp/dir`) dodges the mangler;
   bsdtar and GNU tar accept them as-is.

3. sign-addon-update.mjs was tar'ing the addon directory as a subfolder
   (`screenshot/addon.json` inside the archive), so the client
   extracted to `<tmp>/screenshot/` and then failed the id+version
   re-check because addon.json wasn't at the root. Now the signer
   tars the CONTENTS of the addon dir via `tar -C <addon-dir> .`, so
   entries live at the archive root where the client expects them.

All three surfaced from `scratchpad/decoupling-test/run-test.mjs`, which
now walks the full path — sign, serve, fetch, verify, download,
extract, stage, promote, backup — plus three signature-tamper negatives
and the empty-pubkey short-circuit. 15/15 checks pass.
2026-09-07 22:28:55 +02:00
Local Dev
1b29706ba4 feat(theseus/aegis): EIP-3085 wallet_addEthereumChain + EIP-3326 switchChain
Aegis now handles the standard MetaMask try-switch-then-add flow. A dapp
that wants to route through Polygon (or Base, or Arbitrum, or any other
EVM the Silent Mode user hasn't added yet) calls the pair the industry
already wrote for it — Aegis registers the chain, provisions a wallet on
it under the same vault seed, auto-connects the origin, fires
chainChanged, and hands the dapp back a provider pointed at the new
chain. No sidebar detour, no Custom RPC copy-paste. Users still see
every chain in the picker post-add and can revoke sites in Settings.

- lib/chain-eth.js: EthWallet accepts a customNetwork override
  ({id, label, chainId, defaultRpc, explorerTx, explorerAddr, ticker}).
  When present it replaces the NETWORKS lookup so mainnet+Sepolia
  ship built-in and every EIP-3085 chain is a runtime override the
  addon persists. The ticker flows into snapshot() so the send
  approval reads MATIC / BNB / whatever the chain's native currency is,
  not a hardcoded ETH.
- index.js customEthChains storage: `{[chainId]: {chainName, rpcUrl,
  explorerTx, explorerAddr, ticker, addedAt, addedByOrigin}}`.
  Persisted under api.storage.customEthChains, so an added chain
  survives Theseus restarts. chainMeta("eth", "custom-<chainId>")
  synthesizes the meta from storage so the panel renders custom
  chains without needing them in COINS at module-load time.
- eth.addChain handler (EIP-3085): approval overlay shows chain
  name, decimal + hex chain id, native ticker, RPC and explorer
  URLs (the phishing-signal quartet). On approval, persist config +
  create wallet with a custom-<chainId> network + auto-grant the
  origin readAddress on this chain. No-op success if the chain is
  already added.
- eth.switchChain rewritten to be EIP-3326 correct: look up any
  ready ETH wallet whose adapter reports the requested chainId,
  make it the selected wallet, fire chainChanged. When no wallet
  matches, throw with .code = 4902 (the standard 'chain not
  added' code) so wagmi / RainbowKit / any 3326-aware dapp does
  the fallback wallet_addEthereumChain call in the same click.
- eth.state handler: cheap {address, chainIdHex, networkVersion}
  peek for the origin's currently-connected wallet (no approval,
  no key access). The main-world bridge calls it after every
  switch/add to emit chainChanged + accountsChanged locally — the
  events MetaMask fires and RainbowKit listens for.
- wallet-inject.js: routes wallet_addEthereumChain via
  eth.addChain, preserves the 4902 code across the postMessage
  boundary on switch failures, calls pullEthStateAndEmit() to fire
  the post-switch/add events.
2026-09-07 22:26:27 +02:00
Local Dev
8fcc0e2433 feat(theseus/aegis): EIP-712 signTypedData_v4 + Solana multi-signer send
Two follow-ups to the dapp bridges. Both change wire shape only — no new
UI, existing wallets keep signing byte-identically for the flows they
already covered.

- lib/eip712.js: full EIP-712 typed-data encoder — encodeType with
  alphabetically-sorted transitive sub-types, typeHash, encodeValue for
  string / address / bool / uint*/int* (any width) / bytes / bytesN /
  nested structs / dynamic and fixed arrays, hashStruct recursion,
  digest = keccak256(0x19 || 0x01 || domainSeparator || hashStruct).
  Verified against the spec §"Ether Mail" test vector — hashStruct on
  both the domain and the message plus the final digest all match the
  canonical values byte-for-byte (see scratchpad/verify-eip712.mjs).
- chain-eth.js: exposes signTypedDataDigest(digest32) that signs the
  precomputed digest with r||s||v (v = 27+recid), the same envelope
  personal_sign uses. Aegis computes the digest server-side (in the
  addon) so a bug in the encoder can't be tricked by a malicious dapp
  into signing over data the user never saw.
- index.js: eth.signTypedData handler shows domain (name · version ·
  chainId), primary type, and a truncated JSON preview of the message
  in the approval overlay — every classic phishing signal (mismatched
  domain, unexpected primary type) is in front of the user before they
  hit Sign. Accepts either an already-parsed typedData object or the
  JSON-string form older MetaMask specs used.
- wallet-inject.js router: eth_signTypedData_v4 (and _v3 for the same
  payload shape) route to eth.signTypedData. v1's flat "type[]" form
  is unwired — dapps that still use v1 should upgrade.
- Solana signAndSend: bridge now passes the FULL wire (from
  tx.serialize({requireAllSignatures:false, verifySignatures:false}))
  instead of just the message. The addon parses compact-u16 signature
  count, finds this wallet's pubkey in the message's account-key list,
  signs the message, and patches ONLY its own slot in the signature
  array — any partial signatures the dapp had already filled with
  tx.partialSign() (session keys, escrow co-signers, permissioned
  authorities) are preserved. Multi-signer flows work now; single-signer
  is the degenerate case of sigCount=1.
- Approval overlay for sol.signAndSend now shows required-signer count
  and the wallet's slot index so multi-signer requests are visibly
  distinct from a plain single-signer send.
2026-09-07 22:19:51 +02:00
Local Dev
01253e882c fix(theseus/tabs): kill the tab-switch flash
Two independent causes of the flash the user reported when clicking
between tabs (and when opening Settings, which is just another tab):

1) Every tab view was created without an explicit backgroundColor.
   Electron's default is transparent, which means the first frame after
   setVisible(true) shows whatever is underneath the view — black, or
   the just-hidden previous tab — until the page paints. Set a solid
   ground that tracks the system theme (#0b0e14 dark / #ffffff light)
   so the first-paint gap is invisible.

2) setActive iterated tabs and toggled visibility in list order. If
   the currently-active tab came before the new active in the array,
   the loop hid the active one first and showed the new one later,
   leaving one frame where no tab was visible. Reverse: show the new
   target FIRST, then hide the rest. Compositor always has at least
   one tab view up during the switch.
2026-09-07 22:15:47 +02:00
Local Dev
5880ba3507 feat(theseus/aegis): EIP-1193 + Solana wallet-adapter bridges; BTC signet
Aegis now integrates with the two dapp-wallet APIs the wider ecosystem
actually uses — MetaMask-style window.ethereum for Ethereum, Phantom-style
window.solana for Solana — plus BTC signet as a third Bitcoin network
alongside mainnet + testnet3.

- wallet-inject.js: adds a main-world bridge, installed via a one-shot
  <script textContent=…> appended to <head> and immediately removed.
  Electron's contextBridge shallow-copies args and strips methods, which
  means BCH- and Tron-shaped params (plain data) work in the isolated
  world but Solana's wallet-adapter dapps — which pass @solana/web3.js
  Transaction objects and expect .serializeMessage()/.addSignature() to
  fire on them — need code that lives in the same world as the dapp.
  Bridge talks back to the isolated world via window.postMessage on a
  namespaced envelope (aegisTag = "aegis-" + addonId), which forwards to
  theseus.invoke. Same pattern MetaMask + Phantom use.
- window.ethereum (EIP-1193): request({method, params}), on(),
  removeListener(), chainId, networkVersion, selectedAddress. Handles
  eth_requestAccounts, eth_accounts, eth_chainId, net_version,
  personal_sign, eth_sign, eth_sendTransaction, wallet_switchEthereumChain
  (rejects with "use the Aegis picker"), wallet_addEthereumChain
  (rejects, chains come from Settings), wallet_get/requestPermissions.
  Every other eth_*/net_*/web3_* method passes through to the wallet's
  configured RPC via a new eth.rpc handler. EIP-6963 announceProvider
  event fires so wagmi / RainbowKit / any 6963-aware dapp discovers
  Aegis alongside MetaMask instead of racing for window.ethereum.
- window.solana (wallet-adapter shape): connect(), disconnect(),
  publicKey (with toString/toBase58/toBytes/equals — the PublicKey
  interface dapps check), signMessage(u8) → {publicKey, signature: u8},
  signTransaction(tx) → mutates + returns the same tx with the
  signature added, signAndSendTransaction(tx) → returns {signature: txid},
  signAllTransactions([tx]), request({method, params}). isPhantom flag
  set true so dapps that gate on it pick us. on/off events for connect
  / disconnect / accountChanged.
- Handlers in index.js registerPageMessages: eth.requestAccounts,
  eth.personalSign, eth.sendTransaction, eth.switchChain, eth.rpc,
  sol.connect, sol.signMessage, sol.signAndSend. Every write path is
  per-origin gated + goes through api.approvalModal with the wallet
  label + network in the row list so the user always knows which
  Aegis wallet is about to sign.
- Signet added to chain-btc.js — signet shares testnet3's address
  format and SLIP-44 coin type (BIP-325 only changed consensus/signing),
  so bitcoinjs-lib.networks.testnet handles derivation unchanged. Only
  the electrum pool (aranguren + wakiyamap) + explorer (mempool.space
  /signet) + faucet (signetfaucet.com) differ. Registered as
  btc:signet in COINS with per-network coinType lookup.

Known limits (follow-ups in the same shape as existing chains):
- SOL signAndSendTransaction is single-signer only; dapps that combine
  the wallet's sig with co-signer sigs need the wire assembled on the
  dapp side.
- ETH eth_signTypedData_v4 (EIP-712) is not wired — the handler set
  covers personal_sign only.
2026-09-07 22:08:56 +02:00
Local Dev
cffb956a4c feat(theseus/addons): signed add-on update endpoint, à la Firefox XPI
Decouples bundled-add-on updates from Theseus releases. An add-on
whose addon.json declares an updateURL can be republished at any time
without shipping a new Theseus installer; existing installs pick it up
on the next boot's +30 s background check.

Client flow (main-process only, no UI touchpoints in this commit):

    initAddons()
    ├── promoteStagedUpdates()   # promote signed stage if newer
    ├── seedBundledAddons()      # bundle wins over on-disk if newer
    └── AddonHost.discoverAndActivate()
    30 s later:
    └── checkAndStageUpdates()   # fetch, verify, download, stage

Signature: Ed25519 over
"silentmode.addon-update-v1|<id>|<version>|<tarball-sha256>",
verified against a hardcoded set of operator pubkeys living in
addon-update-pubkeys.js. Domain-separated so the operator key can't
be tricked into signing a message with a different purpose. Empty
pubkey array is the shipping default — checkAndStageUpdates() then
short-circuits and no outbound requests are made, which is the safe
posture until the operator ceremonies a key in.

Payload: gzipped tar, extracted with the system tar (present on
Win10 1803+, macOS, Linux). Path traversal defended by tar's default
refusal of `..` entries; the extracted manifest's id + version are
re-checked against the signed values before staging.

Staged updates go to <userData>/addons-updates-staged/<id>-<version>/.
Promotion into <userData>/addons/<id>/ reuses seedBundledAddons's
backup dance: existing folder moves to
<userData>/addons-backups/<id>-<oldver>-<timestamp>/ so any local
edits survive.

New files:
- addon-updater.js — client
- addon-update-pubkeys.js — hardcoded pubkeys (empty; edit + rebuild to rotate)
- scripts/generate-update-keypair.mjs — one-time keygen
- scripts/sign-addon-update.mjs — operator packager+signer
- docs/ADDON-UPDATES.md — operator brief + threat model

Wired into main.js at boot; screenshot add-on's addon.json advertises
the reference updateURL for when the endpoint goes live.
2026-09-07 21:58:30 +02:00
Local Dev
48cb497f59 feat(theseus/aegis): BTC send from BIP44 + BIP86 addresses
Aegis's Bitcoin adapter can now sign transactions from every BIP44/49/84/86
address it derives. Receive already worked on all four in the previous rev
— this closes the send side.

- BIP44 (legacy P2PKH, 1…): signAndBroadcast now fetches each spent UTXO's
  parent transaction via blockchain.transaction.get(txid, false) and hands
  the raw hex to PSBT as nonWitnessUtxo. Prev-tx calls fan out in parallel
  with Promise.all so a multi-input legacy send doesn't serialize the wait.
- BIP86 (Taproot key-path, bc1p…): signInput now uses a tap-tweaked
  signer — the internal ECPair, tweaked with sha256("TapTweak" ||
  internalPubkey) via ECPair.tweak(). bitcoinjs-lib matches the tweaked
  pubkey against the on-chain output key and signs with schnorr. The
  input carries tapInternalKey so the PSBT layer knows it's a key-path
  spend (no leaf script).
- The plan-time "not yet in this rev" refusal is gone. paymentFor()
  returns send: "p2pkh" / "p2tr" for the two families; every path in
  the picker signs today.
- Fee vsize model already covered p2pkh (148 vB per input) and p2tr
  (58 vB per input) — unchanged.
- Verified in scratchpad/verify-btc-send.mjs: all four families
  produce a fully-finalized wire tx (bitcoinjs-lib refuses to
  finalize an invalid signature, so a valid extractTransaction()
  result is proof the signing path is correct). Vsize per family:
  BIP44 222 vB, BIP49 165 vB, BIP84 141 vB, BIP86 142 vB — all
  match the input-count/vsize model in this file's fee estimator.
2026-09-07 21:55:44 +02:00
Local Dev
af8e167120 feat(theseus/aegis): BTC address-family picker (BIP44/49/84/86 + Taproot)
BTC now matches DGB's family selector: pick BIP44 (1…), BIP49 (3…),
BIP84 (bc1q…, default) or BIP86 Taproot (bc1p…) from Settings, on
mainnet or testnet3 (paths shift coin type 0 → 1 automatically).

- lib/chain-btc.js: paymentFor(purpose, node, network) returns the
  right bitcoinjs-lib payment (p2pkh / p2sh(p2wpkh) / p2wpkh / p2tr)
  keyed off the derivation path's purpose. WalletKeys.entry captures
  the family, redeem script (BIP49) and internal x-only pubkey
  (BIP86) alongside the standard script/address fields.
  bitcoinjs.initEccLib(ecc) is called once at load so p2tr resolves.
- Registry: BTC + DGB address families are purpose-only now; a
  helper (addressFamiliesFor / defaultAccountPathFor) computes the
  concrete m/PURPOSE'/COIN'/0' per (chain, network) — coin type
  {mainnet:0, testnet:1} for BTC, always 20 for DGB. chainMeta
  expands the list so the panel doesn't need per-chain knowledge.
- Panel: #btcSettings block mirrors #dgbSettings (family select →
  path input auto-fill → Apply). The family-select listener + the
  fillFamilyPicker() helper are shared between DGB and BTC — the
  DOM prefix is the only per-chain input.
- Send is wired for BIP84 (default) and BIP49 (adds redeemScript to
  the PSBT input). BIP44 (needs nonWitnessUtxo prev-tx fetch) and
  BIP86 (needs tap-tweaked signer) throw a clear "not yet in this
  rev — sweep to BIP84" error so users hit it at plan time, not at
  broadcast time. Receive works on all four families today.
- Verified all four families derive the canonical BIP44/49/84/86
  spec test vectors for the standard abandon×11 mnemonic — see
  scratchpad/verify-btc-families.mjs. Byte-identical to the BIPs.
2026-09-07 21:23:15 +02:00
Local Dev
a0a22bc69a feat(theseus/aegis): Bitcoin adapter (mainnet + testnet3, BIP84 native SegWit)
Seven coins across twelve networks now — BTC joins the shipping roster.

- lib/chain-btc.js: BIP84 native SegWit — m/84'/0'/0'/0/x → bc1q…
  (mainnet), m/84'/1'/0'/0/x → tb1q… (testnet3). Reuses the exact same
  stack the DGB adapter already pulls in: bitcoinjs-lib for network
  params + payments.p2wpkh + PSBT, bip32 for HD derivation, ecpair for
  the Signer interface, ecc (@bitcoinerlab/secp256k1) for message-sign
  recoverable sigs. No new npm deps.
- Backend: same lib/electrum.js Aegis uses for BCH and DGB — plugged
  into a public Bitcoin ElectrumX pool (blockstream.info, lu.ke,
  grey.pw) for mainnet and aranguren.org / blockstream.info:993 for
  testnet3. Send flow: PSBT build + per-input signInput +
  finalizeAllInputs + broadcast. BIP-137 recoverable message signing.
- Registered as btc:mainnet + btc:testnet in COINS with the orange
  Bitcoin disc SVG logo. Mount case mirrors DGB (accountPath honored,
  so switching to m/44'/0'/0' or m/49'/0'/0' via the setAccountPath
  message gives legacy 1… or wrapped-segwit 3… — same one-line UI plumb
  as the DGB address-family selector, deferred to a follow-up).
- Panel: sat as the small-unit label, bitcoin: BIP21 QR payload,
  chain-aware send placeholder ("bc1q…" mainnet / "tb1q…" testnet).
- Verified: BIP84 spec test vector — abandon×11 mnemonic derives
  bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu at m/84'/0'/0'/0/0
  (byte-identical to the vector in the BIP text). Testnet variant
  produces tb1q6rz28mcfaxtmd6v789l9rrlrusdprr9pqcpvkl at m/84'/1'/0'/0/0
  (cross-checkable on iancoleman.io/bip39 with coin BTC Testnet).
2026-09-07 21:15:45 +02:00
Local Dev
c2be569ac1 fix(theseus/addons): reseed bundled add-ons when their version bumps
seedBundledAddons() only copied a bundled add-on when the target folder
was missing, so an updated bundled add-on never landed on any machine
that had ever run Theseus before — the 0.3.14 shipped screenshot editor
would sit in resources/ and be ignored by every dev machine with an
older screenshot/ folder from a previous test.

Compare the bundled addon.json version to the user's on-disk version.
On mismatch, rename the user copy to
<userData>/addons-backups/<id>-<oldver>-<stamp>/ and cp the fresh
bundle in. Backups live outside addonsDir so AddonHost's folder scan
doesn't pick them up as duplicate add-ons under the same manifest id.

Bump screenshot 0.2.0 -> 0.2.1 so the first build carrying this fix
actually reseeds the shipped-0.3.14 editor on existing dev copies.

Users who genuinely fork a bundled add-on should bump their local
version to something different from the bundled one — that keeps them
pinned. Users who edit files without bumping accept upstream updates,
with the timestamped backup as safety net.
2026-09-07 20:53:21 +02:00
Local Dev
65c306d553 feat(theseus/aegis): Ethereum + Solana adapters, DGB address-family picker, Aegis-branded shield
Multi-currency coverage matches what aegis.x has been advertising: BCH,
TRX, SC, DGB, ETH, SOL — six coins, two-step coin/network picker for
each. Panel logos, favicon and fallback all read as Aegis.

- Ethereum (lib/chain-eth.js): mainnet + Sepolia. BIP44 m/44'/60'/0'/0/0
  → secp256k1 → EIP-55 checksummed hex address (verified against
  MetaMask's canonical abandon×11 vector 0x9858EfFD23…4EcaEda94). JSON-RPC
  backend (Cloudflare mainnet, PublicNode Sepolia by default; per-wallet
  override). EIP-1559 send with an inline RLP encoder + secp256k1
  recoverable sign; broadcast via eth_sendRawTransaction. personal_sign
  message signing follows the \x19Ethereum Signed Message:\n prefix.
- Solana (lib/chain-sol.js): mainnet-beta + devnet. SLIP-0010 ed25519
  derivation at m/44'/501'/0'/0' (all-hardened), base58 address (@noble
  ed25519). SLIP-0010 layer verified against spec Test Vector 1 in
  scratchpad/verify-slip10.mjs. Native SOL transfer via the system
  program with compact-u16 message serialization + ed25519 sign +
  sendTransaction. Devnet gets a faucet.solana.com link in Receive; the
  panel appends ?cluster=devnet when opening the explorer.
- DGB address family selector (lib/chain-dgb.js already carried the
  paths): the Settings block now shows a Native SegWit / Taproot /
  Wrapped SegWit / Legacy P2PKH picker. Selecting a family auto-fills
  the derivation-path input with that family's default; Apply
  rebuilds the wallet against the new path. Address families exposed
  via chainMeta.addressFamilies so the panel can render them from data.
- Panel branding: inline SVG shield (hexagonal aspis, same silhouette
  as the aegis.x hero) replaces the "?" fallback in logoSvg() and is
  what the header shows before a wallet is selected. Data-URI favicon
  wired into panel.html so the Theseus sidebar tab icon reads as Aegis
  rather than a chain-specific coin mark.
- QR payloads now follow each chain's own URI scheme (BIP21 for BCH/DGB,
  EIP-681 for ETH, Solana Pay for SOL) so external scanners route the
  scan to the right wallet.

Not shipped: EIP-1193 provider (window.ethereum) and wallet-adapter
protocol (window.solana). The signing paths exist; only the page-inject
bridge glue is missing. History for ETH/SOL is also empty in this rev —
both need indexer plumbing (Etherscan V2 for ETH, getSignaturesForAddress
+ getTransaction pagination for SOL).
2026-09-07 20:31:27 +02:00
Local Dev
4c63ae1bc7 feat(theseus/aegis): DGB adapter on @dgb-wallet/{core,psbt} vendored packages
Aegis now shares its DGB code with the standalone DigiByte web-wallet at
D:\Dev\SilentCode\Digibyte. Address derivation and PSBT construction come
from that project's @dgb-wallet/core and @dgb-wallet/psbt packages instead
of Aegis-local reimplementations. Any bugfix upstream flows in via a
re-vendor of dist/*.

- lib/dgb/{core,psbt}/ — vendored dist/ output of the two packages plus
  a tiny package.json shim marking them as ESM. @dgb-wallet/core's own
  import specifier "@dgb-wallet/core" inside psbt/*.js is rewritten to
  "../core/index.js" so the sibling module resolves without a workspace.
- New Theseus deps: bitcoinjs-lib, bip32, bip39, @bitcoinerlab/secp256k1,
  ecpair — the peer deps the vendored packages need. Loaded via
  api.require in index.js's loadDeps().
- chain-dgb.js is a thin adapter now: BIP32 tree via bip32 + DGB
  Network object, addresses via core.p2wpkhAddress, tx via
  psbt.buildPsbt + PSBT.signInput (per-input, since each UTXO's key
  differs) + psbt.finalizeAndExtract. Runtime backend stays the same —
  Theseus's lib/electrum.js against the DGB ElectrumX pool.
- Verified end-to-end in scratchpad: abandon×11 mnemonic derives
  dgb1q9gmf0pv8jdymcly6lz6fl7lf6mhslsd72e2jq8 (matches iancoleman.io/bip39
  and the previous inline implementation, so no on-chain address change
  for anyone who was already using Aegis's DGB slot). PSBT build+sign+
  finalize on a mock UTXO produces a valid 223-byte witness tx.

BIP44 (D…) and BIP49 (S…) address families are implemented in the
vendored core but not yet exposed in Aegis's picker — the panel needs
an "address family" selector inside the DGB settings block first. Left
for a follow-up; today's DGB pick uses BIP84 native SegWit only.
2026-09-07 02:19:44 +02:00
Local Dev
118de0ef5c feat(theseus/aegis): fold Sia into the addon; add DGB (BIP84 native SegWit)
Aegis now covers four coins across two-step coin+network picks: BCH
(mainnet + chipnet), TRX (mainnet + Nile), SC (mainnet), DGB (mainnet).

- Sia (SC): pulled the standalone siawallet's lib into
  bundled-addons/bchwallet/lib/sia/ and wrote lib/chain-sia.js exposing
  the common adapter shape. The very first SC wallet the user adds in
  Aegis reuses purpose "siawallet/mainnet/0" so pre-Aegis funds carry
  over automatically; subsequent SC sub-accounts start at
  "bchwallet/sc/mainnet/1". Per-wallet walletd URL setting; empty URL
  shows a "Point Aegis at a walletd node" gate in the panel.
- Vault-derive gate now honors a manifest-declared `absorbs` list, so
  Aegis's addon.json can list `absorbs: ["siawallet"]` and the derive()
  guard accepts paths under either the current id or the absorbed one —
  the mechanism a superseding add-on uses to inherit an older add-on's
  keyspace without orphaning funds.
- DigiByte (DGB): lib/chain-dgb.js ports the relevant bits of the
  SilentCode Digibyte design — SLIP-44 coin type 20, BIP84 native SegWit
  (m/84'/20'/0'/0/x → dgb1q…) via ripemd160(sha256(pubkey)) + bech32.
  ElectrumX-DGB backend reuses lib/electrum.js (public wss:50022 pool).
  BIP143 P2WPKH sighash + witness-tx serialize implemented inline (no
  FORKID — DGB uses standard Bitcoin sighash). Derivation cross-checked
  against a known BIP39 vector in scratchpad/verify-dgb.mjs — the address
  for "abandon×11 about, m/84'/20'/0'/0/0" is
  dgb1q9gmf0pv8jdymcly6lz6fl7lf6mhslsd72e2jq8, matching iancoleman.io/bip39.
- Panel: SVG coin logos for SC (green disc with S) and DGB (blue
  octagon with D) alongside the BCH/TRX marks. Chain-specific settings
  block per coin (walletd URL for SC; derivation path for DGB). Balance
  render uses BigInt-safe arithmetic so 24-decimal SC amounts don't
  lose precision on the way through the panel; amount input on SC
  returns a hastings string.
- Every chain adapter's snapshot fits the panel's shared shape
  (address/balance/history/etc.), so future chains only need a new
  chain-<x>.js file, a COINS registry entry, a matching case in
  mountWallet, and an SVG logo.

Standalone siawallet addon stays as-is on disk; users can delete it once
they've confirmed Aegis shows the same balance. Nothing here disables it.
2026-09-07 01:56:25 +02:00
Local Dev
f3ba86116d Ship Theseus 0.3.16 f9d06545 (dock collapse on overflow + toolbar-menu native + capture retry)
Setup    f9d0654572e110f6895951dc22ec9fb4549b3a8fb14714770579264b62051259
Portable 7ff7a1501bc7d7407ec0a4974aa26652d6d7ecabcc796584254a8bb463d43b09

Two bundled fixes since 0.3.15:

4f498a1 - Extension dock no longer stacks into a column when dragged
narrow. #extbuttons + .extdock get flex-wrap:nowrap + overflow:hidden;
a second data-extcollapse signal fires when .bar's contents overflow
(alongside the width-based level 3), collapsing the row into the
single 🛡 puzzle button. Hysteresis (cached natural width + 8px slack)
keeps the ResizeObserver from oscillating across the boundary.

e160dac - toolbar-menu popup goes native (Menu.popup from main) so it
escapes the chrome-view height clipping. capturePage retries transient
0x0 results up to 6 times so the screenshot addon doesn't silently
produce a blank PNG right after a navigation.

Deployed. Verified LIVE 0.3.16.
2026-09-07 01:56:12 +02:00
Local Dev
6193d336db feat(theseus/addons): native toolbar-menu popup + capturePage retry
Two follow-ups from the screenshot editor rework (task_b9608dc6):

1) toolbar-menu popup goes native. The DOM popover in chrome.html was
   getting clipped by chrome.html's own WebContentsView height and then
   covered by the tab view below it. Route through main.js's
   Menu.popup() so the menu escapes the chrome-view layering entirely.
   Preload exposes toolbarMenuPopup(addonId, rect) + subscribes to
   toolbar-menu-closed so chrome can drop the button's "active" tint.

2) capturePage() intermittently returns a 0x0 image on Windows right
   after a navigation (view hasn't painted a frame yet). Retry up to
   six times with 150 ms between attempts; throw a specific error if
   still empty so the addon can surface a real message instead of
   silently producing a blank PNG.

Also lands an [addons] openAddonTab log line so the editor tab opening
is easy to trace in main's log.
2026-09-07 01:52:49 +02:00
Local Dev
b433dbc0b6 fix(theseus/chrome): dock collapses to puzzle button on any overflow, no column
The extension row was stacking into a column when the user dragged the
URL bar wide enough to squeeze the dock's slot. Two things broken:

1) #extbuttons could wrap: added flex-wrap:nowrap + overflow:hidden so
   the buttons never break to a new line. Same for .extdock's own
   flex container (nowrap + min-width:0 so it can flex-shrink to zero).

2) Collapse was width-based on .bar only — a window wide enough for
   level 0 wouldn't collapse the dock even when the URL-bar override
   left extdock with 0 px. Added a second signal:
   data-extcollapse="1" fires when .bar's contents overflow their slot
   (bar.scrollWidth > bar.clientWidth). Applies alongside the level-3
   collapse; either path shows .extmore instead of the row.

Hysteresis to avoid RO loop: while EXPANDED, cache the row's natural
scrollWidth. While COLLAPSED, re-expand only when summing every other
.bar child leaves at least (naturalWidth + 8 px slack) of room. Both
directions verified across URL widths 400/800/1200/1500/reset — the
row expands / collapses at the right thresholds with no oscillation.
2026-09-07 01:52:03 +02:00