The first .bch page now opens with zero user-visible latency and stays fresh
for as long as the browser runs. Four sources conspire in parallel — none of
them can block a navigation:
1. Warm start from disk (sync)
warmFromSnapshot loads the user-cache snapshot first, then falls back to
the copy bundled with the build. sharedIndex is set BEFORE the first
navigation can even fire.
2. Continuous background delta refresh (every 30 s)
startBnsPolling opens one electrum connection, fetches the beacon
history (a single call), and only pulls verbose tx bodies for txids we
don't already have — mergeFreshHistory-style. Merges into memory,
rebuilds the index locally, persists the enlarged snapshot to disk.
Turns a ~60 s full walk into ~1 s per new event.
3. Sia snapshot pull on boot (one-shot, wins the NEXT boot)
refreshSnapshotFromSia downloads the operator's published snapshot from
s3.silentmode.st for the next launch. After a long idle period the
browser resumes from that fresher snapshot instead of walking days of
events.
4. ensureIndex full-walk fallback
Still runs on boot for the case where there's no bundled snapshot AND
the poll hasn't landed yet — very first launch, offline install, etc.
resolveHost now prefers sharedIndex (which the poll keeps live) and, on a
miss with a stale index, triggers pollAndMerge (delta fetch) instead of
ensureIndex (full walk). The old full-walk fallback is only taken if the
delta primitives aren't available (running against an older resolver-web).
Argus/src/lib/resolver-web.js exports connectElectrum so the Theseus poll
can drive its own ad-hoc queries against the pool without duplicating the
Electrum wrapper.
Bundled starter snapshot refreshed: 73 beacon txs, root c37b859682…54e414ba.
Artifacts:
dist-public/TheseusNavigator-Setup-0.0.7.exe (95.4 MB)
sha256 1b0dabcd2b13067aa1fd89c3271708b35ba22dfc7a620e248b35e0487b7a104f
dist-public/TheseusNavigator-0.0.7-portable.exe (92.7 MB)
sha256 706dc01b21a88d3c2fbc3eeced0cab6ace873630bf3edc2d40915ca5be5c8cae
Broad-scope commit sweeping in work from parallel sessions plus this session's
dev-only utilities. No single unifying theme — this is the "commit everything
that's ready" pass. Grouped by area below.
AriadneResolver / mobile
* Small updates to BchFetcher, Bns, MainActivity, AriadneVpnService, and the
Android manifest — from a parallel mobile-resolver session.
* AriadneResolver/mobile/webpreview/ — new local dev webview (index.html +
server.mjs) for iterating on the mobile UI without a device.
Email / SnappyMail
* Email/snappymail-plugin/silentmode-addresses — new SnappyMail plugin
(README, CSS, PHP entry, JS) for surfacing @silentmode.st address
management inside the webmail UI.
Hephaestus (Forgejo + auth-proxy)
* auth-proxy/src/oidc.ts + docker-compose.yml updates.
* scripts/bootstrap-auth.sh — idempotent script that registers the wallet
auth-proxy as Forgejo's OIDC provider after `docker compose up -d`. All
secrets read from .env — no literals in the script.
TheseusNavigator / dev tools
* dev/list-tlds.mjs — enumerate every registered BNS name grouped by TLD via
our own indexer.
* dev/show-tlds-bch.mjs — dump the full records payload of the legacy
tlds.bch name (kept as a diagnostic for the list-in-one-NFT era).
Deviant sites + brand
* site/deviant/ — new microsites (anthemus, potidaea, brand, mindmap, main
index) plus the full brand kit under site/deviant/brand/ (logos, icons,
palette, social exports as SVG source + PNG renders).
* site-sirius-x/portal.html — updates.
Coordination
* _coordination/sessions/mobile-resolver.md — parallel-session notes.
Deliberately excluded from this commit:
* scratchpad/ — this session's temp drafts (Sia doc mockups, tlds UPD payloads).
* TheseusNavigator/_prev/ — ~372 MB of prior release binaries; belongs in
a separate artefacts store, not the git tree. Add to .gitignore next pass.
Four independent pieces of one story — make cold-start .bch resolution fast,
survive individual electrum outages, and turn adding a Silent Mode BNS server
into a checklist run.
* Argus/src/lib/snapshot-name.js — pure, interpretation-free snapshot format
for the name beacon (raw history + verbose tx cache + deterministic root).
* Argus/src/publish-name-mirror.mjs — mirror the snapshot to Sia S3
(floating + content-addressed) and Nostr NIP-33 (kind 30078,
d-tag bns-name-list). Same pattern as publish-tld-mirror.mjs.
* Argus/src/snapshot-name-to-file.mjs — dump the snapshot to a file for
bundling. Writes to TheseusNavigator/snapshots/bns-name-snapshot.json.
* Argus/src/lib/resolver-web.js — new export buildIndexFromSnapshot() runs
the same REG/UPD reduction as buildIndex() but from a pre-fetched snapshot,
no electrum required. Warm-start path in Theseus depends on this.
* TheseusNavigator/main.js — warmFromSnapshot() and refreshSnapshotFromSia()
wired into app.whenReady(). First .bch navigation returns from a warm index
instead of waiting on a full electrum walk.
* TheseusNavigator/package.json — bundles the starter snapshot as an
extraResource so packaged builds ship with a floor.
* TheseusNavigator/snapshots/bns-name-snapshot.json — first starter snapshot
(70 beacon txs, root 8cc859aa…).
* VPS/BNS-SERVER-PLAYBOOK.md — turn-key checklist for spinning up a second
or third Silent Mode BNS server, distilled from what actually worked on
the silentmode box (BCHN 29 [chip]-not-[chipnet], multi-beacon indexer,
wss:// nginx, on-chain publish via electrum.bch, common gotchas table).
* Argus/src/register-electrum-list.mjs — publish the current chipnet
server pool as `el` on electrum.bch. Fits inside the 200-byte OP_RETURN
cap by sizing the record (drops fallback IP pins in favour of URL-only
tokens until they fit). NAME was chosen deliberately: two-part `electrum.bch`
normalises to the bare distinct name `electrum`, whereas the earlier
candidate `electrum.silentmode.bch` collapsed to silentmode.bch and would
have inherited/overwritten that name's records.
* Argus/src/revert-silentmode-bch.mjs — one-off recovery from the earlier
register-electrum-list revision that hit exactly that subdomain-collapse
bug (broadcast an UPD to silentmode.bch and clobbered its s3 record).
Records recovered from the local snapshot cache; safe to leave in the
tree as documentation of what happened.
Setup b740cb033173622b192701ff36f20a97e357fedebf77c3c7ead03d113a9ac229
Portable 782a2ad235a4a1e1491df6a1d16c817fa8542e363e3c6b139c7e04f40846f4c2
New:
- Tabs carry the page favicon (page-favicon-updated -> emitTabs -> the
chrome renders it in the same slot the loading spinner uses).
- Image right-click: Open image in new tab / Save image as... / Copy
image / Copy image address. Save-image-as uses the existing
will-download tracker, so it also shows in the downloads chip.
- Tab cursor: default arrow at rest instead of the always-'grab' hand.
Grab only shows while a tab is being dragged for reorder.
Deployed:
- scp installers + releases-manifest.json to /opt/silent-mode/dl/
- scp tools/ + releases/ index pages to /opt/silent-mode/site/
- sia-upload of ../site to bns/silentmode/
- verified HEAD 200 + manifest 0.0.6, VPS hashes match, tools page
shows 0.0.6 buttons on silentmode.st AND silentmode.bch (Sia mirror).
The 0.0.5 update chip will surface 0.0.6 on existing installs at next
launch (6h manifest poll).
Favicons:
- Each tab stores a favicon URL; wired via wc.on('page-favicon-updated')
to Electron's first-emitted icon URL. Included in the emitTabs
payload; the chrome renderer paints an <img class="fav"> in the
same slot the loading spinner uses (spinner while loading, favicon
once page-favicon-updated fires). No proactive clear on navigation
- mainstream browsers keep the old icon until the new one arrives,
which avoids a flash on every subpage click.
Cursor:
- .tab { cursor: default } instead of the previous 'grab'. Grab looked
like the page was always in the middle of a drag. .tab.dragging
keeps 'grabbing', so the grab hand only appears when the user
actually picks a tab up to reorder it.
Right-click on an image now offers:
- Open image in new tab -> createTab(srcURL)
- Save image as... -> wc.downloadURL(srcURL). The tab's
will-download handler leaves savePath
unset, so Electron shows the native
Save As dialog and the download appears
in the tracker.
- Copy image -> wc.copyImageAt(x, y). Puts the decoded
image on the clipboard (paste into any
image-aware target).
- Copy image address -> clipboard.writeText(srcURL).
Only shown when p.mediaType === "image" && p.srcURL, so text /
link right-clicks are unchanged.
Setup 606529ea9f1de9dc1ec5012534dda31b06919245f19f934ee1b9f4f10385a5bc
Portable ed89547a155e998278beccf21f9807841ac6267f75cdcbbead81b80acfee0adc
Fixes:
- Classic form-GET search engines (Google, Brave, Bing, Startpage,
Yandex, Ecosia, Mojeek, ...) now show results. The tab's
will-navigate intercept was dropping the query string on every
dotted-host navigation, so /search?q=foo landed on /search. DDG
only appeared to work because its in-page search uses pushState +
XHR and never triggered will-navigate.
- Address bar reflects the target URL immediately on Enter instead
of showing the previous page's URL until did-navigate fires.
New:
- Link-hover status bar: Firefox / Chrome-style pill at the bottom-
left of the window showing the href when the pointer is over a
link, hidden when it leaves. Auto-sizes to text, cleared on tab
switch, tracks window resize.
Also on-VPS: bns-gateway auto-index directory paths (f43ec61) so
silentmode.bch/tools/ returns the tools page instead of NoSuchKey.
Deployed:
- scp installers + releases-manifest.json to /opt/silent-mode/dl/
- scp tools/index.html + releases/index.html to /opt/silent-mode/site/
- sia-upload of ../site to bns/silentmode/
- verified: HEAD 200 on both installers, manifest reports 0.0.5,
silentmode.st/tools shows the 0.0.5 buttons, Sia mirror ditto.
The 0.0.4 update-check chip should now surface itself for existing
installs on their next launch.
Two related navigation bugs, both surfacing when a page inside a tab
tries to submit a search:
1. will-navigate rewriter dropped the query string and fragment.
Every dotted host went through
navigateTab(id, parsed.hostname + parsed.pathname)
which stripped ?q=... The classic-form-GET search engines
(Google, Brave, Bing, Startpage, Yandex, Ecosia, Mojeek, ...) all
silently landed on their /search endpoint with no query, so no
results ever showed. DuckDuckGo only appeared to work because its
in-page search uses history.pushState + XHR and never triggered
will-navigate to begin with.
Fix: pass the whole URL (minus scheme) so query + fragment survive.
2. Address bar showed the previous page's URL until the new page's
did-navigate fired. navigateTab called setLoading() -> emitTabs()
BEFORE assigning t.url, so the chrome renderer received the stale
URL and painted it (goURL() blurs the input on Enter, so the
"don't clobber typed text" guard didn't skip the write).
Fix: assign t.url from host+rest immediately, before setLoading.
Firefox / Chrome-style small pill at the bottom-left of the window
showing the href when the pointer hovers a link, hidden when the
pointer leaves. Fed by webContents.update-target-url on every tab;
auto-sizes to its text via an IPC resize channel.
Cleared on tab switch so a lingering hover pill from tab A doesn't
carry across to tab B. Positioned by layout() so it tracks window
resizes.
New files link-status.html + link-status-preload.js registered in
build.files (GOTCHAS.md rule: missing entries silently omit from
the packaged app).
Not shipped yet — bundles into the next Theseus release.
Bumps version so the chip actually surfaces itself on 0.0.3 installs
(the version-newer check requires a strict semver bump — same-version
rebuilds don't trigger the chip). From this release on, whenever the
manifest names a newer Theseus, users get a one-click download.
Mechanism
- main.js checkForUpdate() fetches https://dl.silentmode.st/releases-
manifest.json on startup (5s timeout, cache: no-store) + every 6h.
Finds the theseus-navigator release, compares version to
app.getVersion() with a numeric a.b.c comparator that handles
"0.10.0 > 0.9.9" correctly.
- On a match → stores { version, setupUrl, portableUrl, setupHash,
portableHash, date } and emits update-available to chrome. Cleared
after the user upgrades + relaunches (same-version → null).
- Re-emits on chrome's did-finish-load in case the fetch beats the
chrome view.
Chip UI (chrome.html)
- Acid-yellow pill between the downloads button and the Tor toggle:
"↓ Update to X.Y.Z" + a ✕. Main body opens setupUrl in the system
browser via shell.openExternal (origin-validated to
https://dl.silentmode.st/ or https://silentmode.st/). ✕ dismisses
for the current session — you'll see it again next launch if still
behind.
Trust anchor
- No signing / no cryptographic verification of the download in this
phase. releases.silentmode.bch publishes the SAME manifest URL, so
users who want to verify can cross-check the manifest hash against
what BCNR returns. The proper auto-updater with signature checks is
the follow-on to this cheap version.
Non-goals in phase 1
- No delta downloads; the user clicks and gets a full installer.
- No auto-install; download → user runs the installer themselves.
- No "check now" button in Settings; the periodic timer suffices.
- No portable-vs-installed detection; the chip prefers setupUrl (the
installer upgrades in place). Right-click for portable is future work.
- password-vault: createVault takes { messengerRootHex } opt; unlockVault
surfaces messengerRoot (null on legacy vaults, so nothing regresses);
saveVault persists it; bindMessengerRoot mutates an unlocked state for a
later attach-mnemonic-to-existing-vault flow.
- main.js password-setup: when the user provides a mnemonic, ALSO compute
seedToPurposeRoot(seed, "messenger/0") and store it. Random-seed vaults
stay as-is (no mnemonic = no messenger root to store).
- main.js hermes-init: two modes now — { mnemonic } (unchanged) or
{ useVault: true } (uses vaultState.messengerRoot directly, no mnemonic).
Response includes source: "vault" | "mnemonic" for the panel to badge.
- main.js hermes-can-use-vault: cheap availability probe used by the panel
to decide whether to show the vault sign-in shortcut.
- hermes.js: nostrKeyFromRoot(root) accepts 32-byte Uint8Array or 64-char
hex; produces the same {sk, pkHex, npub} as nostrKeyFromMnemonic for the
same seed (unit-verified: derivation paths converge on f2c92519...67f4).
- Messages panel: "Sign in with password vault" button appears above the
mnemonic entry iff the vault is unlocked AND was set up from a mnemonic.
The mnemonic path stays as the always-available fallback — bind is
genuinely optional, not required.
- Hermes/proof/: standalone keystone — BIP-39→Nostr, NIP-17 wrap/unwrap,
name-addressed send/receive verified end-to-end via public relay
- Argus/src/lib/hermes-derive.js: HKDF(silentmode/messenger/0) using libauth
so the registrar can compute np without pulling nostr-tools into Argus
- Argus/src/register-hermes-chipnet.mjs: idempotent REG/UPD script; publishes
np (Nostr pubkey) and nr (relay) records for a chipnet name
- TheseusNavigator/lib/hermes.js: same derivation + wrap/unwrap + record
parsing, canonical for Theseus; guarded by lib/package.json type:module
- TheseusNavigator/messages.html + messages-preload.js: Messages panel UI
(identity from mnemonic, live inbox, compose by .bch name), .bch suffix
stripped from displayed names
- TheseusNavigator/main.js: HERMES_MOD + loadHermesLib next to VAULT_MOD;
ipc handlers (hermes-status/init/close/inbox/send/open), per-relay
subscription with auto-reconnect, status pushed on WS open/close,
reverse-resolve pk -> .bch name via cached BNS index, Ctrl+Shift+M shortcut
via web-contents-created (works from any tab)
- Chipnet hermes.bch registered with np=f2c92519...67f4 nr=wss://nos.lol
(txid 7fc6de4544c13b782f163fdb892ea6749785886d05a336282fa659d722c7e92b);
end-to-end verified in Theseus
The VPS hosts multiple projects (Silent Mode gateway, mail, BNS indexer,
per-project s3d instances), not just Coinspectrum — rename the VPS folder
and update all cross-refs (VPS, Email, Storage, DEPLOY, packaging prompt)
to match the hostname change on the box.
Also add Storage/SIA-STORAGE-ROADMAP.md capturing the design for an
end-user Sia-storage product: two-tier trust model (Sovereign / Managed),
BCH-CashScript payment + Google-style free-tier inactivity policy,
identity model with Vultisig-style threshold recovery, and the decisions
made so far. CLIENT-OPTIONS.md gets a scoping note so future readers know
"hosted proxy = never" is about operator credentials, not end-user tiers.
Six user-visible improvements + supporting infra, all uncommitted from
the earlier session-in-progress state. Ships together in one release.
Chrome / tabs
- Same-size tabs: flex 1 1 0 with max 200px, min 60px. Container gets
overflow: hidden so many tabs shrink evenly instead of scrolling out.
- Drag-and-drop tab reordering. HTML5 drag events on each .tab; drop
side chosen by pointer x within target (Chrome UX). New move-tab IPC
splices the tabs array + re-emits.
Address bar
- Persistent history at userData/history.json capped at 500 LRU. Ranked
by host-prefix > url-prefix > contains > title-contains > recency.
- Floating suggestions dropdown (addressPicker WebContentsView) anchored
under the URL bar. Debounced 80ms input; ArrowUp/Down forward to the
picker via address-cursor IPC; Enter fires goURL; blur closes after
160ms so click-through registers. New files address-picker.html +
address-picker-preload.js. Cleared by existing clearHistoryOnQuit.
Password autofill (A.2 MVP)
- Green key chip in the address bar appears when the vault is UNLOCKED
and the active tab's host has matching credentials (exact hostname
match for phase 1; eTLD+1 upgrade queued as A.2.5).
- Click chip → floating picker of usernames. Click a match → main.js
runs a small script in the active tab: finds first visible
input[type=password]:not([disabled]), walks the same form for a
visible text/email/tel/url/search input whose name/id/autocomplete
matches /username|user|email|login|account|id/, fills both via the
native value setter + dispatches input/change so React/Vue-controlled
inputs update. New files pw-fill.html + pw-fill-preload.js.
- emitPwAvailability fires from pushNav + vault setup/unlock/lock so
the chip's visibility + count stays accurate.
Bookmarks bar
- Right-click context menu on the favorites bar. On empty area:
"Add current page" (or "Remove current page" if already saved). On a
specific bookmark: "Open", "Edit title…" (prompt), "Remove", plus
the add/remove-current entry. Uses a shared .ctxmenu style mirroring
the settings ctxmenu (dark/light aware).
- Empty-state text updated to mention right-click.
Home page
- Larger responsive card grid: auto-fill minmax(260-280px, 1fr) with
breakpoints at 600/900/1200. Cards have a subtitle line, a colored
badge (on-chain / Sia / server / custom), and edit affordances that
reveal only in Edit mode.
- User-editable set: Edit toggle reveals per-card ✎/✕ + a dashed "+ Add
card" tile. Modal for add/edit with title / URL / subtitle / badge.
Reset-to-defaults button.
- Persisted at userData/home-cards.json. New home-preload.js exposes
window.home = { getCards, setCards, resetCards, navigate }. IPC
handlers in main.js validate sender.getURL() matches our own
home.html — third-party pages see the API shape via the preload but
can't act on the user's local cards.
- Fallback set of 2 cards renders when window.home is unavailable
(e.g. opening home.html directly outside Electron for preview) so
the grid is never blank.
Docs
- TheseusNavigator/ROADMAP-identity-wallet.md — the phased plan for
the two independent strands (password manager A.2/3, browser wallet
B.1-6). Committed earlier this session; re-listed here for context.
- TheseusNavigator/SESSION-PROMPT-identity-wallet.md — pastable
kickoff for the next session picking up either strand.
Files added to build.files: address-picker.html,
address-picker-preload.js, pw-fill.html, pw-fill-preload.js,
home-preload.js.
Uncovered by the 2026-08-13 subdomain-inheritance fix: once
`checkers.game.x` correctly picked the parent's `ip` record instead of
`s3`, the ip branch itself failed. Two reasons:
1. `fetch("http://<ip>/", { headers: { host: name } })` follows the
site's :80→:443 redirect into `https://<name>.<tld>/`, which isn't
in ICANN DNS → "fetch failed".
2. The site's cert is signed by a per-machine BNS root, not a public
CA; standard TLS validation rejects it.
Both are fixed by connecting to the IP with SNI = name, pinning the
presented cert's SHA-256 against the on-chain `tls` record, and only
then issuing the HTTPS request over the same socket. The on-chain
fingerprint is the trust anchor BNS uses everywhere else (see
Argus/src/lib/ca.js).
Gateway (public-gateway.mjs): new pinnedHttpsGet + httpGet + ipRequest
helpers; case "ip" delegates. No silent HTTP fallback on pin failure
(a mismatch means "not the site the chain says it is").
Theseus (main.js): parallel port of the same helpers, Tor-aware
(routes through SocksProxyAgent when Tor is on). serveBns's inner
serveIp() delegates to ipRequest.
Verified live: `curl -sI https://navigate.st/bns/checkers.game.x/`
returns 200 OK with the checkers game (1,179,215 bytes, apex
`game.x` unchanged, served from Sia).
- TheseusNavigator/package.json: 0.0.2 → 0.0.3. Address-bar fix (main.js refreshTabUrl,
in 9b9c93c) makes silentmode.bch subpage clicks update the URL correctly.
- site/tools/index.html: collapsed the two-flagship-cards row into one Theseus
Navigator panel with a shared description and two version sub-blocks (Windows
+ Android) inside a divider grid. Same-product-two-platforms framing.
- site/index.html: Tools card copy updated to match (Theseus Windows + Android;
built-in Ariadne; also relay, extension, standalone resolver).
- site/releases/index.html + releases-manifest.json: Theseus 0.0.3 entry with the
new hashes; Android section corrected to v0.8 (was previously showing v0.8
filename with a v0.2 hash — the linter had gone half-way).
Rebuild + redeploy of the prior commit (9b9c93c). Version bumped from
0.0.1 to 0.0.2 (parallel-session bump in package.json). New hashes live
on dl.silentmode.st + Sia bns/silentmode/:
TheseusNavigator-Setup-0.0.2.exe
sha256 b62ecf528dc672a07a144af5a8bbb5772b2853b4ad5eec5926bdc6247792ad53
TheseusNavigator-0.0.2-portable.exe
sha256 ba80a808446bd75a6b649d93094af9e21be38476dd23980bad7ac0e228a6ce76
Also snapshotted the parallel-session 0.0.1 (81831c08 / b4807aa1) that
was live just before this ship into /opt/silent-mode/dl/_prev/ so it's
available as a rollback alongside the earlier 418e7bba / 208b059a /
036e94c7 builds.
Manifest hashes were previously updated by the parallel session to a
STALE 0.0.2 build (b3a81047 / 37679d29) that never made it live; those
have been overwritten with the actual live hashes now.
On-chain pointer at releases.silentmode.bch unchanged — publishes the
manifest URL, so BCNR clients see the new hashes automatically without
a wallet spend.
PENDING.md updated with the new rollback list.
Three follow-up asks from the previous ship:
1. Shield "secure" colour bumped from #4fd1a5 (mint) to #3fb950 — the
GitHub-style saturated green, matches the +N/-N diff colour the user
pointed at as reference.
2. Engine-picker "Search settings…" now opens the Search section
directly instead of General. New IPC channel `focus-section` fires
from main after picker-open-settings, carried through
settings-preload as `onFocusSection`, and the settings.html sidebar
handler exposes showSection(sec) so any section can be focused
programmatically. Works for both a fresh settings tab (fires on
did-finish-load) and an already-open one (fires immediately).
3. Toggle no longer removes an engine from the list. Two-tier state:
INSTALLED (visible in the Settings list) and ENABLED (toggled on in
the toolbar dropdown). Toggling off keeps the row visible with an
.off class (dimmed 55%). Right-click any row → new context menu with
"Remove from list" is what actually removes an engine (built-ins go
back to the catalog, customs are dropped entirely).
Model changes:
- New settings.installedEngines persistent array (defaults to
DEFAULT_ENABLED). enabledEngines becomes a subset of installedEngines.
- isInstalled(id) helper; allEngines() carries `installed: bool` alongside
`enabled`.
- New IPC `remove-from-list` (right-click action); exposed as
removeFromList in settings-preload.
- set-engine-enabled now also INSTALLS when enabling (the catalog "+ Add"
flow), preserves installed state when disabling.
- add-engine (custom URL) auto-adds the new id to enabledEngines too.
- remove-engine (custom delete) prunes from enabledEngines as well.
- Never-empty invariant kept: enabledEngines falls back to ["duckduckgo"]
if everything gets removed.
Settings UI:
- Enabled list shows all INSTALLED engines (was: only enabled), rendered
with toggle reflecting enabled state; rows carry data-builtin so the
context menu picks the right remove IPC.
- Catalog panel and Discover-more pane filter on !installed instead of
!enabled — a toggled-off engine stays in the enabled list, not here.
- Ctxmenu is a floating .ctxmenu div; closes on outside click / Escape.
- .eng.off dims the row and mutes the name colour.
Preview harness stubs updated to include the `installed` field on every
engine + `removeFromList` and `onFocusSection` no-op stubs so
_settings-preview.html renders the new UI accurately.
Bump to 0.0.2; publish new installer/portable hashes across the download
site (tools + releases pages), releases-manifest.json (Theseus entry only —
Ariadne Resolver/Android entries preserved), and RELEASE-HANDOFF.md.
Artifacts rebuilt reproducibly (SOURCE_DATE_EPOCH=1785888000, unsigned).
Setup b3a810472b06273c1cc846adcb84366ad9114276a984bed7347c26f019497c56
Portable 37679d293715b9e1881d38ee7e92a5a7448f3c523a14919637afe732e2478ce1
Captcha-gated testnet faucets in the faucet hub set session cookies with
no SameSite attribute; Chromium defaults those to Lax and withholds them
inside cross-site iframes, so cookie-bound captcha endpoints 500
(tbch.googol.cash /captcha: 500 cookieless, 200 with the session cookie).
applyEmbedCookieShim() rewrites Set-Cookie on an allowlist of embed hosts
to append "; SameSite=None; Secure" so the cookie is frame-eligible.
Allowlist-scoped only — SameSite is CSRF protection, never relaxed globally.
BCDN pages now show https:// in the address bar (was bare 'host/', briefly bns://).
Rationale: BCNR replaces DNS (name resolution), NOT HTTP. Under the hood the
delivery IS HTTPS for s3/ip/p records; the on-chain h record has no transport
at all, but https:// is the least-surprising display. BCDN/ICANN badge is the
sole source-of-truth for which registry served us; scheme stays a convention.
Registry chip is now a proper segmented control:
- Two-chip toggle (collision candidates): single rounded pill, split in half
with a divider — active side filled (acid green for BCDN, blue for ICANN),
inactive side transparent + clickable. Feels like an on/off toggle.
- Single chip (pure ICANN or BCNR-unique TLD): standalone pill in the
registry's colour. No toggle affordance since there's no alternative.
Same acid-glow-green (#d6ff3d) and blue (#4c9eff) as the collision.html prompt
so the whole registry palette is consistent across chrome + interstitial.
Adds a will-prevent-unload handler on each tab. When a page has a beforeunload
handler that returns non-null (typical for forms with unsaved input, in-browser
editors with a dirty document, etc.), Electron would silently cancel any
navigation attempt. Now we show a native two-button dialog — 'Stay on page' /
'Leave anyway' — matching how mainstream browsers behave.
Works for both user-initiated navigation (link clicks) AND our own programmatic
loads (address bar, chip switcher, in-tab collision prompt). Answers the
operator's ask: 'only if there is unsaved work that can be lost, should a
warning appear' (2026-08-02).
Chip switcher now bypasses navigateTab/loadBns entirely and calls loadURL
directly. Rationale: the user explicitly clicked a registry chip; that IS the
choice. Routing through navigateTab -> loadBns was reaching the collision
decision path in some races and could re-show the soft-mode 'Open with...'
prompt as an unwanted extra step. Direct load guarantees the switch is atomic.
Prov is updated inline using entries.get(host) for the BCDN case (source/records/
category), same shape loadBns would have produced. internalNav flag guards the
programmatic load from the will-navigate handler (redirect chains stay clean).
Also: address bar blurs on Enter so the tabs-event handler can update it to
the actual loaded URL (search keyword no longer sticks in the address bar
after search results load).
Rebuild + redeploy of the prior commit (5ef4bba). New hashes live on
dl.silentmode.st + Sia bns/silentmode/:
TheseusNavigator-Setup-0.0.1.exe
sha256 418e7bbaa08c248cebdf4b9137eaf0351139c2f328fc788bcf5d08888bba2ec3
TheseusNavigator-0.0.1-portable.exe
sha256 93d579639affa6108d9ad80fd0a20eb183fc156b7d954a7acd525ed74d9e1ccf
Two rollback points on the VPS at /opt/silent-mode/dl/_prev/:
208b059a (pre-shield, from earlier today)
036e94c7 (two revisions back)
On-chain pointer at releases.silentmode.bch is unchanged — publishes
the manifest URL so this build is reachable through BCNR without a
wallet spend.
PENDING.md updated with the new rollback list.
Replaces the padlock in the address bar with a heraldic shield outline
that changes colour to communicate the connection state at a glance:
neutral (--dim) home / resolving — no site or pending
secure (#4fd1a5) BCDN chain-verified (kind:"ok") OR https:// clearnet
insecure (#f6768a) nxdomain / resolver error / plain http://
Single-path SVG with fill=currentColor, so state-class CSS toggles the
tint without touching the geometry. The shape matches the reference
image the user provided — flared shoulders at the top, concave flanks
tapering to a sharp bottom point (bounds x:2 y:1.2 w:12 h:13.8 in the
16x16 viewBox).
setBadge() gets one extra branch: for kind:"web" it now inspects
d.url's scheme so plain HTTP shows insecure red instead of the previous
neutral. The legacy .warn class is kept but unused by the standard
states — any lingering caller keeps working (orange).
Green/red match the download-tracker palette so the visual system stays
consistent across the toolbar.
Rebuild + redeploy of the prior commit (4654940). New hashes:
TheseusNavigator-Setup-0.0.1.exe
sha256 208b059a14c8ddf10cf553e530e77f34129cf8ba999b697da08720ffc3685d22
TheseusNavigator-0.0.1-portable.exe
sha256 bf08976500978dcd0d7305b04cc1480e63da54a24a71253cf4cfd9c910431a89
Verified all runtime-loaded files present in app.asar (downloads.html,
downloads-preload.js, engine-picker.html, popover.html — the trap from
the earlier 6bbccf9c build).
Live on dl.silentmode.st + Sia bns/silentmode/. Manifest date bumped to
2026-08-02. Previous build backed up on the VPS at
/opt/silent-mode/dl/_prev/ so rollback is `cp` away if the new build
misbehaves. On-chain pointer at releases.silentmode.bch is unchanged —
it publishes {"u":"https://dl.silentmode.st/releases-manifest.json"} so
new hashes are reachable through BCNR too, no wallet spend needed.
PENDING.md drained — this session's group is empty now.
Bundle of UX + feature work. Split from packaging by intent so the diff
is reviewable; the next Theseus rebuild ships it.
Features
- Download tracker (new): session.on("will-download") → per-item state
{id, filename, url, mime, total, received, state, savePath, startedAt}
with updated/done event handlers. New downloadsPop WebContentsView
loads downloads.html (new file) + downloads-preload.js (new file);
panel positioned under a new #downloads toolbar button between search
and Tor. Full IPC: downloads-get, toggle/close/resize-downloads,
download-open/show/cancel/clear, downloads-clear-all. In-memory only —
cross-session persistence is a future addition. Button badge shows
active count + spin/done/err color.
- Search engines split by kind + tier:
* kind: "search" | "llm" — separate headers in picker + settings
("Search with" / "Ask an AI"). Empty sections hidden.
* tier: "catalog" | "extra" — Settings now has THREE panes behind the
"+ Add search engine" button: curated catalog, wider discoverable
bank filtered by a live search input, custom URL form.
* DEFAULT_ENABLED unchanged (5 major engines).
* Custom user-added engines carry tier="custom" (never in catalog/extra
panes).
- 9 tier="extra" engines added (all non-login ?q=): Marginalia, Stract,
Yep, Presearch, MetaGer, Qwant, Swisscows, Naver, Baidu. Same rot rule
as LLMs: if one starts bouncing to a login gate, drop it.
Bug fixes
- Loadbar collapses to 0px when idle (was reserving a permanent 2px
strip below the address bar). .loadbar {height:0} + .loadbar.on
{height:2px} + 120ms transition.
- Native <select> popup theme sync via :root { color-scheme: dark } +
@media(prefers-color-scheme: light). nativeTheme.themeSource already
drives prefers-color-scheme, so the OS popup color follows the app
theme automatically (fixed light popup on dark app / vice versa).
- .ctl layout flipped to flex-direction: row with flex-wrap so
anti-fingerprint mode + value fields fit side-by-side.
Settings restructure
- General section: Startup group at the top ("Open previous windows and
tabs" toggle), then Appearance below with three visual THEME CARDS
(System / Light / Dark) — small mock-browser previews per theme,
Firefox-style, active card gets a blue ring. System pipes through to
nativeTheme.themeSource = "system".
- Search promoted to a top-level sidebar item between General and
Naming. Search-engine controls moved out of General into Search.
- Search section: enabled list shows only enabled engines, grouped by
kind, drag-reorder within a kind. "+ Add search engine" opens the
catalog/extras/custom-URL panel.
Search engine catalog trims (already flagged in prior work)
- Removed ChatGPT / Claude / You.com (login-gated ?q=).
- Removed SearXNG (federated; every single-instance default rots).
Docs
- TheseusNavigator/PENDING.md and GOTCHAS.md born with this work
(see the HANDOFF.md commit for the convention).
- PENDING.md's own "session: 2026-08-02:theseus-ux-polish" group will be
emptied after this ship lands.
Preview harness
- _preview.html + _settings-preview.html stubs updated with kind + tier
+ downloads seed + tier="extra" samples so the preview reflects reality.
Both files are gitignored — local only.
Coordination
- Parallel session's collision-policy work (chrome.html registry chips,
popover switcher, Naming section, in-tab collision prompt) already
landed in commits 256079d/42b340f/b0d6375/78dddda. This commit adds
cleanly on top.
Two related bugs both caused by the tab's will-navigate handler racing with
programmatic loads:
Bug A (chip switch BCDN -> ICANN shows blank page, BCDN-priority mode):
fallbackToWeb() calls webContents.loadURL('https://<host>/') to serve the
ICANN version. That fired will-navigate, which saw a dotted host, ran
isBnsHost() -> true, and RE-INVOKED navigateTab() recursively — but the
transient='icann' override had already been consumed, so the recursive call
fell back to bcnr-first, canceling the fallback mid-flight. Tab showed blank
because both loads collided.
Fix: mark programmatic loads with t.internalNav so will-navigate skips them.
Bug B ('Ask each time' -> Open BCDN doesn't load):
Was going through a meta-refresh from bns://collision-choose/ to
bns://<host>/?_collision=bcnr. The meta-refresh bypassed navigateTab, so the
chrome/prov state was never updated (address bar, badges stayed stale).
Fix: will-navigate now catches bns://collision-choose/ FIRST, applies the
remember flag, sets t.collisionOverride, and routes via navigateTab so
chrome + prov update correctly.
Removed the serveBns collision-choose handler + the ?_collision URL-param
path in loadBns (both dead now that will-navigate handles it).
Result:
- Soft-mode 'Open with...' -> Open BCDN loads the BCDN site cleanly.
- Chip switcher flips BCDN <-> ICANN with no blank flash, correct chrome.
Three UX fixes based on operator feedback (2026-08-02):
1) 'Open with…' is now a FULL-PAGE in-tab interstitial (was a modal window).
- loadBns loads collision.html via loadFile with query params instead of
opening a BrowserWindow.
- collision.html is navigation-based: buttons redirect to a special
bns://collision-choose/?host=…&choice=…&remember=…&resturl=… URL.
- serveBns handles that URL: persists remember=name/tld choice, then returns
a meta-refresh to the real target. For BCDN it appends ?_collision=bcnr
one-shot marker; for ICANN it redirects to https://<host><path>.
- loadBns strips and honors the ?_collision one-shot marker so BCDN
redirects don't re-trigger the prompt.
- Old modal path (collisionPromptOnce) removed.
2) Auto-switch from the address-bar chip: clicking BCDN/ICANN chip sets a
transient per-tab collisionOverride that loadBns consumes ONCE for this
navigation only, bypassing the soft-mode prompt entirely.
3) Address-bar toggle: chips stay visible during 'resolving' (no more
flash-and-reappear); active chip is colored (acid green for BCDN, blue for
ICANN — matching collision.html's palette); inactive is greyed with border,
clickable to switch. Feels like a proper toggle.
Settings > Registries copy: operator's exact wording adopted (title stays
'Registries', body uses 'BCNR-unique' term for TLDs that only exist on BCNR).
Terminology (user-facing labels now match the product/registry distinction):
- BCDN = Bitcoin Cash Domain Names (the product — what you view)
- BCNR = Bitcoin Cash Name Registry (the on-chain system that backs it)
Chrome badge, popover, Settings section and 'Open with…' prompt all show BCDN
for a resolved name. BCNR stays only where the registry itself is the subject.
'Open with…' prompt (collision.html):
- Larger window (640x520, was 480x340)
- Radio-select pattern with explicit Open / Cancel buttons (was auto-fire on click)
- Enter = Open, Esc = Cancel, keyboard-first
- Body copy per operator spec (no product-name-in-parens; blockchain-generic)
- Card titles kept short: 'BCNR / BCDN' + 'ICANN / IANA'
Address-bar chip:
- Says BCDN (not BCNR) for on-chain names; ICANN for web
- Dropped the '·.tld' suffix — TLD is already in the URL bar
- On collision candidates: shows BOTH chips (BCDN | ICANN) with active
highlighted; clicking the inactive one flips the tab (via collision-switch)
Settings section renamed Naming → Registries. Copy rewritten in the same
BCDN/BCNR frame; policy labels are now 'BCDN first' / 'ICANN first' / 'Ask
each time'.
Passive 'also on BCNR' bar copy updated to BCDN.
Verified: all preload/settings/main/chrome JS + HTML parse; no secrets in
staging.
Theseus soft-mode UX: 'Open with...' modal on collision, per-name/per-TLD
overrides, live per-tab switcher in the site-info popover, and a Naming section
in Settings for policy + reset. Backed by an on-chain root TLD certificate
(tlds.bch) that resolver-web.js discovers via fetchBcnrTlds()/isBcnrNativeTld().
Companion pieces:
- Argus/src/indexer/ELECTRUM-SOURCE-README.md — the featherweight VPS variant
(no BCHN node, no Fulcrum) now live as bns-indexer.service.
- Argus/DESIGN-root-tld-cert.md — clarified: NOT a governance workflow, just
ordinary key management (single wallet MVP -> 2-of-3 multisig). List gates
registration / surgical NRPT / soft-mode classifier — never resolution.
- ROADMAP-IDEAS.md — recorded SiaGit/GitHub.sia + user-friendly Sia UI ideas.
Full spec: Argus/DESIGN-collision-modes.md (already tracked).
Site manifest and download pages point at the rebuilt resolver:
AriadneResolver-Setup-0.1.0.exe
sha256 cb9e8ea0dcffaa60607ff1781e160199956dcf2d7dd69cd13986aba75fcf0fb1
Bumps release date to 2026-08-01. This build is the one that carries the
EDNS OPT-echo fix from the prior commit into what dl.silentmode.st
serves; users on the daemon should stop seeing "Server Not Found" for
normal ICANN names in Firefox / anything using getaddrinfo.
TheseusNavigator/package.json: adds engine-picker.html,
engine-picker-preload.js, popover.html, popover-preload.js to the
electron-builder `files` array. Because that list is explicit,
electron-builder shipped only what was listed, so in the packaged 0.0.1
build the WebContentsView created for the search-engine dropdown loaded
a nonexistent file and rendered blank -- visually identical to "the
button does nothing". `npm start` worked because dev reads from the
source tree. Fix restores the picker; needs a Theseus rebuild + redeploy
to reach users, then TheseusNavigator-Setup-0.0.1.exe's SHA-256 has to
be re-published here.
Ariadne hash still needs to be published on-chain to
releases.silentmode.bch (wallet spend, user's action).
Dropped the OpenSearch "+" item from the engine dropdown and the per-page
OpenSearch scan that fed it (it ran a fetch on every page load). Users add
engines via Settings instead.
- Address-bar security badge + popover lock redesigned to match Firefox's
padlock (shackle + rounded body + keyhole).
- Added AI/LLM answer engines to the catalog: ChatGPT, Claude, Phind, You.com
(Perplexity already present) — all accept a URL query. Off by default; enable
in Settings.
- Favicons now load from DuckDuckGo's icon service (one privacy-respecting host,
returns an icon for ANY domain) instead of guessing /favicon.ico per site,
which failed for several engines and fell back to emoji. Verified loading.
The search box's dropdown button now displays the current engine's favicon
(emoji fallback) + a caret, instead of a generic magnifier — and updates when
the engine changes.
Parallel session was right — the previously-shipped f94834b5 pre-dated:
1. the ASCII em-dash sweep in setup/install.ps1 (Inno's [Run] uses
powershell.exe / PS 5.1; em-dashes in the file crashed the parser
under UAC, so the installer copied files but never registered the
scheduled task or NRPT rule)
2. the multi-TLD NRPT expansion (added .p2p .bit .nav alongside .bch)
3. the VPS-primary electrum server list — resolver-web.js now dials
wss://coinspectrum.duckdns.org:50011 first (Silent Mode's own
BCHN-backed BNS-only indexer), public servers as fallback
Result: a real user installing 3438d558 on a fresh Windows box now gets
a working system-wide resolver with no manual steps.
Deployed to dl.silentmode.st and mirrored to Sia bns/silentmode/.
Each engine row in Settings has a drag handle (⠿) and is draggable; dropping
onto another row reorders and persists via setEngineOrder, driving the
toolbar dropdown order. Visual drag/over states included.
- Search engines can be reordered (▲/▼ per row); order persists in
settings.engineOrder and drives the toolbar dropdown order.
- Manual anti-fingerprinting values are now dropdown-or-type (datalist):
timezone (common IANA zones), language (common locales), and a city picker
for location that fills exact lat/lon — each still accepts free typing.
- Privacy fix: enumerateDevices() leaked speaker (audiooutput) labels + device/
group IDs even with camera/mic blocked. New "Hide media devices" (default on)
blanks every device's label/deviceId/groupId and collapses to one per kind,
matching Firefox — closes the WebRTC device-fingerprinting leak.
- Anti-fingerprinting moved into the Privacy section (own sidebar item removed).
- Location spoof: pick a world region (Europe/Asia/N&S America/Africa/Middle
East/Australia) → representative coordinates, or Manual for exact lat/lon.
- Language spoof: pick from the top-10 world languages, or Manual for any locale.
- Custom engine dropdown as a floating overlay view (engine-picker.html) that
renders REAL favicons per engine — a native <select> can't show images.
- Larger catalog (DuckDuckGo/Google/Brave/Bing/Startpage/Yandex/Ecosia/Mojeek/
SearXNG/Wikipedia/Perplexity); Settings has a favicon checklist to choose
which appear in the dropdown (enabledEngines), plus manual add/remove.
- OpenSearch "scan": pages advertising a search engine surface an
"Add <site>'s search" entry in the dropdown.
- Toolbar search box now just a magnifier button that opens the dropdown
(no per-engine icon in the bar).
- Each search engine shows a symbol in the toolbar dropdown, the placeholder,
and Settings (🦆 DuckDuckGo, 🦁 Brave, 🔵 Google, 🔎 Bing, 🛡️ Startpage,
🔴 Yandex); custom engines take an optional symbol (defaults to 🔍).
- Fix: light-theme @media blocks for settings/popover/home were placed before
the base rules and lost the cascade (sidebar stayed dark) — moved them last.
- Light/dark/system theme (Settings > General) via nativeTheme.themeSource
driving prefers-color-scheme across chrome, settings, popover, and home.
- Search box redesigned: a magnifier icon opens the engine dropdown, the rest
is a wider typing field; styled to match the browser (was a raw <select>).
- Trimmed built-in engines to DuckDuckGo/Google/Brave/Bing/Startpage/Yandex;
custom engines still add/remove via "Add / edit engines…".
- WebRTC: the "WebRTC Network Limiter" extension can't run in Electron
(chrome.privacy API is unavailable), so its function is now a native
4-mode WebRTC IP policy in Settings > Privacy.
- Address-bar placeholder: "Ask a search engine or enter web address".
- Security popover redesigned to resemble Firefox's site-info panel:
lock/shield hero, "Connection secure" status, host, plain-language
subtitle, and a details grid; the overlay view auto-sizes to content.
- Search-engine picker returned to the toolbar with an "Add / edit engines…"
entry that opens Settings; added Ecosia, Mojeek, Presearch.
- Custom search engines: add (name + URL template with %s) / remove in
Settings > General; used by address-bar search.
- Address-bar placeholder: "Ask a search engine or enter web address".
- Performance: cache the chain index (was rebuilt on every navigation) and
warm it at startup — .bch pages open near-instantly after the first.
- Loading indicator: indeterminate bar under the toolbar, per-tab spinner,
and reload⇄stop button (driven by did-start/stop-loading + BNS resolve).
- Chrome cleanup: removed the bottom status bar and the redundant search
box; security padlock now always present at the front of the address bar;
minimal ICANN/BCNR pill at the end; favorites bar shows only on new-tab.
- Search: added Yandex; engine picker moved into Settings > General.
- Settings redesigned with a left sidebar (General / Performance / Privacy /
Anti-fingerprinting). Anti-fingerprinting now Show/Hide/Spoof/Manual for
timezone, language, AND location (geolocation coords overridden in-page).
Theseus Navigator:
- Firefox-style toolbar: SVG back/fwd/reload/home buttons
- security padlock badge in the address bar opens a floating site-info
overlay VIEW (on top of the page, never pushes content down)
- Edge-style favorites bar (shown only on the new-tab/home page)
- search-engine picker (DuckDuckGo/Google/Bing/Brave/Startpage)
- Theseus logo moved right, opens Settings; native menu removed
- address bar doubles as search; bottom resolver status line
Argus:
- BNS-only indexer: an electrum endpoint over a bare BCHN node
(watches just the beacon, caches txs so no txindex needed) + test
- registry lifecycle / portfolio / name-index modules
Site restructure (nav/apps/store/hermes/choose) + runbook notes.