Commit graph

198 commits

Author SHA1 Message Date
Local Dev
e72c0ed96b Aegis: check every BTC/DGB input against its previous transaction
Coin selection, change and the fee on the overlay came from the
Electrum server's listunspent values, and a legacy signature does not
commit to the value it spends. A server that under-reported a P2PKH
coin made Aegis sign away the difference as fee: a 1,000,000 sat coin
reported as 100,000 produced a transaction paying 901,180 sat while
the overlay said 1,180. Segwit v0 commits only to its own input, which
leaves the two-request variant open.

Every non-taproot input's previous transaction is now fetched, its txid
recomputed, and its output's value and script compared with the plan;
the fee of the finalized PSBT must equal the approved one.
2026-10-04 03:49:39 +02:00
Local Dev
3264c6d019 Aegis: WizardConnect relay keys from the real root, overlay names the pairing origin
mountWallet zeroed the vault root after mounting, but the WizardConnect
adapter kept a reference to that same buffer and read it again for
every new pairing's relay key. Every pairing made after mount therefore
got a Nostr identity derived from 32 zero bytes and the pairing URI
alone, so anyone who saw the URI (the QR, a script on the dapp page)
could read the relay traffic, xpubs included, and speak as the wallet.
The adapter now gets, and keeps, its own copy.

The signing overlay and the PIN request named the dapp by its own
userPrompt, so a dapp paired once could present itself as any site.
The pairing origin the host verified is now recorded per URI and shown
instead; the dapp's text is a quoted row with invisible and bidi
characters removed. One sign request per connection may be on screen
at a time, and revoking a site in Aegis ends its pairings too.
2026-10-04 03:45:34 +02:00
Local Dev
561cb122ea Vault PIN: tie it to the TPM and never store it unsealed
Theseus's own quick-unlock PIN had the same limit as Aegis's: once the
DPAPI seal is opened (as the user, or from a disk image plus the
Windows password) the 6-digit PIN falls to an offline search. The PIN
is now also the authorization value of a Platform Crypto Provider TPM
key whose secret is mixed into the wrapping key, so the chip's lockout
bounds guessing; lib/tpm-pin.cjs is the same module Aegis uses.

set() now refuses when there is no real OS keystore (Linux basic_text
included) instead of writing the blob in the clear, an unsealed record
from an older build is deleted, and Settings says what the PIN actually
protects against on this machine.
2026-10-04 03:42:02 +02:00
Local Dev
cda17fc885 Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed
A 6-digit PIN behind PBKDF2 + DPAPI falls in minutes to anything that
can open DPAPI (malware running as the user, a disk image plus the
Windows password). The PIN is now also the authorization value of a
TPM key from the Microsoft Platform Crypto Provider; the key releases a
secret mixed with PBKDF2(pin), so the stored blob alone opens nothing
and the chip's own lockout (32 failures, then one per 10 minutes)
limits guesses however the blob was obtained. Reached through Windows
PowerShell's CNG classes with the PIN on stdin, so no native module.
Machines without a TPM keep the software PIN, and Settings now says
plainly what that protects against.

A PIN is no longer stored when there is no real OS keystore (including
Linux's basic_text backend, whose key is a constant); a pre-0.31 plain
blob is sealed or deleted and remembered, so the panel can tell the
user to change the master password if the profile was ever copied.
2026-10-04 03:42:02 +02:00
Local Dev
0514d2d4e3 Merge aegis-pin-view: Aegis 0.31.1 restores the earlier PIN screens 2026-10-04 03:40:18 +02:00
Local Dev
4117a010c4 Aegis 0.31.1: the PIN screens look and behave as they did before 0.31
0.31 moved the PIN check into index.js and, with it, replaced the
15-minute lockout after five wrong PINs by "PIN off until the master
password", with new wording on every PIN screen. The user wants the
screens as they were. The wording, the lockout and the switch to the
master password are back; the check stays in index.js, so the lockout is
now enforced by the host and the panel still never sees the PIN blob.
After the lockout every further wrong PIN locks it again.
2026-10-04 03:40:10 +02:00
Local Dev
d355bbbf87 Theseus: bundle Pithos 0.3.11
New installs carry the same Pithos the extension channel serves, including
drives on Silent Mode and the Sia account card.
2026-10-04 03:36:50 +02:00
Local Dev
399e763745 Theseus: bundle Pithos 0.3.10 2026-10-04 03:29:32 +02:00
Local Dev
556a22b062 Theseus: bundle Pithos 0.3.9 2026-10-04 03:18:25 +02:00
Local Dev
5e67f81a94 Theseus: bundle Pithos 0.3.8 with the menu and Account page 2026-10-04 03:01:00 +02:00
Local Dev
155b445c68 Theseus: bundle Pithos 0.3.8 2026-10-04 02:38:21 +02:00
Local Dev
80146c8c22 Merge aegis-031-fixes: the 0.31.0 audit findings
PIN checked by the host with a hard five-guess limit, permits described
from what is signed, unreadable WizardConnect requests refused, PIN
clearances bound to their request, permissions re-read after the PIN
wait, and the Tron duplicate-field fix (also shipped alone as 0.30.1).
2026-10-04 02:29:32 +02:00
Local Dev
916a748889 Aegis: sends name their wallet, amounts with spaces are refused, BCMR cleanup
- send, sendToken and consolidate now require the wallet id the panel
  reviewed them for; a missing id used to skip the check, and the Solana
  token send sent none, so a selection change under the PIN pad sent from
  another wallet.
- "1 0" was read as 10: a space inside an amount is now refused.
- A BCMR registry list saved before https was enforced is filtered on read,
  and names lose the soft hyphen, Arabic letter mark, Mongolian vowel
  separator, line/paragraph separators and Unicode tag characters too.
2026-10-04 02:26:15 +02:00
Local Dev
7447d57e96 Aegis: a BCH payment re-reads permissions after waiting for the PIN
signAndSend took a permissions snapshot, waited up to two minutes for the
PIN, then wrote the snapshot back. Revoking the site meanwhile still let
the allowance payment go out and restored the revoked allowance, and any
other permission change made during the wait was lost. After the wait it
now re-reads permissions, refuses an allowance payment whose allowance was
revoked, replaced or no longer covers it, and changes only this origin's
sendTx.
2026-10-04 02:24:04 +02:00
Local Dev
449a967e21 Theseus: bundle Pithos 0.3.7 with the music player 2026-10-04 02:23:07 +02:00
Local Dev
4511a933f4 Aegis: a PIN clears only the transaction it was entered for
One global 90 s clearance was opened by every PIN proof. Opening the
wallet or ticking a setting let the next dapp transaction from any site
through without a PIN; a dapp waiting in its poll could take the clearance
the user had just made for their own send; and with two sites waiting the
second one's request was dropped.

Each waiting dapp transaction now has an id, and only a proof naming that
id releases it; a proof given for "transaction" in the panel clears the
panel's next send only; any other proof clears nothing. The panel answers
waiting sites one at a time. Promote to HD now asks for the PIN like any
other spend instead of failing when PIN-per-transaction is on.
2026-10-04 02:23:02 +02:00
Local Dev
2faa3d808a Aegis: a WizardConnect request the overlay cannot read is not signed
wc-sign accepted a flat request (tx and sourceOutputs at the top) that
buildWcApproval does not read, so any paired dapp could get a signature
after an overlay showing only the wallet, an input count and the sighash.
The signer now takes only the nested WizardConnect shape, and the overlay
refuses, without showing anything, a request whose outputs or spent
inputs it cannot decode. Total out now sums every output, not the first 8.
2026-10-04 02:21:11 +02:00
Local Dev
e02d4698ea Aegis: a permit is described from what the signature covers
describePermit read td.message directly, and the EIP-712 encoder ignores
keys a type does not declare. A dapp could put a decoy allowed:false or
details:{amount:"1"} beside an unlimited permit and the overlay showed
the decoy, not risky, under the plain Sign button, with the same digest.

The overlay and the message preview are now built from the declared
fields only, the permit variant is picked from the declared type, and
dropped fields are counted on the overlay. Amounts of 2^96 units and up
are flagged as effectively unlimited, marketplace orders and Safe
transactions get the warning too, and the encoder refuses a non-hex
address instead of signing it as zero bytes.
2026-10-04 02:19:42 +02:00
Local Dev
b85605416e Aegis: the PIN is checked by the host, and guessing ends at five
The panel fetched the PIN blob and decrypted it itself, then reported its
own failures. The lockout therefore counted only what a well-behaved panel
chose to report, a 15-minute timer handed out five more guesses forever,
and anything able to run in the panel could take the blob and search the
million PINs offline in minutes.

The blob now never leaves index.js: pinSet builds it after checking the
master password against the vault, pinUnwrap counts each guess before
trying it, and five wrong guesses switch the PIN off until the master
password is entered. The panel keeps its PIN pads and only sends digits.
A blob from an older build (200k iterations) is re-made at 600k under a
fresh salt on the next correct PIN. Only the topmost PIN pad listens to
typed digits, so two stacked pads cannot both take one entry.
2026-10-04 02:17:26 +02:00
Local Dev
6ba16261ab Theseus: bundle Pithos 0.3.7 2026-10-04 02:16:11 +02:00
Local Dev
c906e7b8ed Aegis: refuse a Tron transaction whose fields appear twice
The decoder read the first copy of a singular protobuf field; java-tron
keeps the last. Any.value is opaque bytes, so a TransferContract carrying
two recipients and two amounts hashes to the same txid either way: the
overlay showed "1 TRX to X" while the chain would move 999 TRX to
another address. It also defeated the plan-time and sign-time draft checks
against a hostile node. A repeated singular field, or a known field with
the wrong wire type, now refuses the transaction.
2026-10-04 02:10:51 +02:00
Local Dev
884f3948b8 Aegis: fees that follow the network, connections that come back, its own name on Solana
Still 0.31.0 (unpublished batch).

- ETH nonce. The pending count from a load-balanced RPC often misses a
  transaction this wallet sent seconds ago, so two sends in a row shared a
  nonce and the second failed or replaced the first. The nonce is taken at
  signing, from the RPC or from what the wallet itself last broadcast,
  whichever is higher, and broadcasts are serialised per wallet.
- Chains without EIP-1559 (no baseFeePerGas) get a legacy EIP-155
  transaction; they rejected the type-2 envelope, so a network added by a
  dapp could receive but never send. The tip is clamped to the fee cap.
- Bitcoin and DigiByte take their fee rate from the Electrum server's
  estimate instead of a constant, size each output from its real script
  (a taproot destination was undercounted), and round the size up before
  pricing. Bitcoin inputs signal replace-by-fee. DigiByte keeps its 20
  sat/vB floor and does not signal RBF, which it does not have.
- Electrum: a wallet with live subscriptions went quiet for good when its
  server dropped. The client reconnects with backoff, pings to catch dead
  sockets, times out a silent connect, and hands the replayed subscription
  answers on as notifications so the wallet refreshes. dispose() ends it.
- Max with an SPL token selected did nothing; it now fills the exact token
  balance.
- Removing a wallet retired its derivation index for good. Add wallet now
  takes the lowest free index, so the same wallet comes back.
- Solana: registered through the Wallet Standard as "Aegis" instead of
  setting isPhantom, with silent connect for already-connected sites.
- "Only show the wallet to sites I enable": Aegis keeps the host's
  page-inject allow-list in step with enabled and connected sites.
2026-10-04 01:55:38 +02:00
Local Dev
f27f3d27c9 Aegis: the PIN is enforced by the host, and every spend is confirmed there
PIN
- The PIN blob wraps the vault master password under six digits and sat in
  plain add-on storage, so a copy of the profile reduced the master password
  to a million offline PBKDF2 guesses. It is sealed with the OS keystore
  before it is stored; a plain blob from an older build is sealed on first
  read. New blobs use 600k iterations.
- "Ask for PIN on every transaction" was decided by the host and enforced
  by nobody: `send` never checked it and dapp transactions had no PIN step.
  A gate is now cleared only by the master password the PIN unwraps,
  verified against the vault, which also opens a single-use transaction
  clearance. Panel sends consume one; dapp transactions ask the open panel
  and wait.

Spending and signing
- Consolidate emptied wallets on the panel's confirmation alone, defaulted
  to every sibling when no list was sent, and swept into whatever was
  selected at click time. It now needs explicit sources and the previewed
  destination, and shows the whole batch on the host overlay.
- Typed data for a chain other than the connected one is refused. Permit
  and Permit2 signatures name the spender, tokens, amounts and expiry, and
  an unlimited one gets the danger action. Previews are no longer cut at
  600/400 characters without saying so.
- eth.rpc relayed any eth_* call for sites that never connected.
- The WizardConnect overlay lists the tokens being spent and received.

Send form
- "0,5" was read as 5: the parser deleted commas. Amounts are parsed
  exactly; a decimal comma is a decimal, ambiguous or non-numeric input is
  refused, extra decimals are an error instead of being dropped.
- Send submits the request the summary was computed for, never a fresh read
  of the form, and stays off while a plan is pending or stale.
- Switching wallet resets the form instead of leaving a live button on the
  previous wallet's plan.
- The unlock field kept the master password after unlocking; the PIN pad
  kept its digits and kept counting keystrokes typed elsewhere as PIN
  attempts; an idle lock left a revealed key or seed form on screen.
- Enter confirmed a dialog even with focus on Cancel.
2026-10-04 01:38:53 +02:00
Local Dev
9e7e9d5e8b Aegis 0.31.0: chain adapters stop trusting what they should check
Start of the next batch; 0.30.0 is published.

- Tron panel sends signed whatever /wallet/createtransaction returned while
  the approval showed the local request. The returned bytes are now decoded
  and must be one transfer from this wallet, to that address, for that
  amount, with a matching txID - checked at plan time and again at signing.
- Importing a Solana wallet from a seed phrase threw on every attempt (a
  mis-parenthesised `new require("crypto").createHmac` plus a bare require
  of an ESM-only subpath). SLIP-0010 now uses Node's HMAC, as chain-sol does.
- Imported BCH wallets put token-bearing UTXOs into coin selection. They are
  excluded, as in the HD wallet, and the balance counts what can be spent.
- WizardConnect dropped the token from each spent output before signing, so
  under SIGHASH_UTXOS every signature of a token transaction was invalid.
- A wallet disposed while a refresh was in flight re-armed its poll timer.
- BCMR registry content is bounded before it reaches the panel: control and
  bidi characters stripped, lengths capped, decimals 0-18, icons https/ipfs
  only, registries https only.
2026-10-04 01:38:50 +02:00
Local Dev
84a37b26bf Aegis: README and MPL-2.0 license for its own repository
Aegis is getting a standalone forge repo (silentmode/aegis) split from
this folder. Inside Theseus it was covered by the root LICENSE; on its
own it needs the license and a description in the folder itself.
2026-10-04 00:24:01 +02:00
Local Dev
3de25581b3 Theseus: bundle Pithos 0.3.6
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-04 00:09:55 +02:00
Local Dev
1244dae25e Theseus: bundle Pithos 0.3.5
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-04 00:05:50 +02:00
Local Dev
8b74f5cbf9 Merge branch 'master' into claude/zen-archimedes-463527 2026-10-03 23:02:46 +02:00
Local Dev
03b497dcae Aegis: DigiByte addresses follow the chosen address family
WalletKeys.entry() built a bech32 p2wpkh address whatever the account
path's purpose, so picking Legacy (D...), Wrapped SegWit (S...) or
Taproot (dgb1p...) in Settings showed a dgb1q address from the BIP44/
49/86 key tree, one no other wallet restoring that path would find.
Each family now derives its own address and script, and spending
supplies what its inputs need (previous tx for P2PKH, redeem script for
P2SH-P2WPKH, tap-tweaked key for Taproot, which is active on DigiByte),
with per-family fee sizes. Unknown purposes are refused instead of
falling back to BIP84.

Also: inputs were signed in selection order but the PSBT orders them by
BIP69, so a spend from two addresses tried to sign each input with the
other's key. They are now signed in the PSBT's order.
2026-10-03 23:01:15 +02:00
Local Dev
03140fae9d Aegis: WizardConnect signing requests can be approved
approvalRequest passed approve/reject keys the host overlay does not
know, so it showed a lone "OK" button whose id never equalled
"approve": every WizardConnect signing request was refused, and the
HTML body was shown as literal markup. It now passes a Sign action and
plain rows: wallet, input count, each output decoded to a cashaddr on
the wallet's network (or OP_RETURN / raw script), total, and who
broadcasts.
2026-10-03 23:01:15 +02:00
Local Dev
5769d837bd Aegis: load the DigiByte deps module as ESM in a dev checkout
lib/dgb/deps.js is ESM, but in a dev checkout the nearest package.json
is TheseusNavigator's, which says "type": "commonjs"; the import threw
and DigiByte was silently unavailable whenever Theseus ran from the
repo. Shipped installs have no package.json above the add-on, so they
were unaffected. lib/dgb/core and lib/dgb/psbt already carry the same
marker.
2026-10-03 23:00:47 +02:00
Local Dev
3d2e3c784b Theseus: bundle Pithos 0.3.4
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:57:47 +02:00
Local Dev
f57cf4c894 Aegis: only the page's own scripts can reach the wallet relay
The isolated-world relay accepted any postMessage carrying the fixed
tag "aegis-aegis", including one from a cross-origin iframe (an ad,
an embed), and attributed it to the top-level origin and its grants.
The tag now carries a per-load random nonce that only the injected
main-world bridge knows, and both listeners drop events whose source
is not this window. The document_start install path is unchanged.
2026-10-03 22:54:59 +02:00
Local Dev
206f54edd2 Aegis: Tron signing overlay comes from the bytes being signed
The overlay for tronWeb-built transactions was built from the dapp's
raw_data JSON, which need not match raw_data_hex: a site could show
"1 TRX to X" and get a signature over anything. lib/tron-decode.js
decodes Transaction.raw from raw_data_hex (contract type, owner, to,
amount, TRC-20 transfer/approve calldata, fee limit, memo); the txID
must match the bytes, every contract's owner must be this wallet, and
unlimited approvals or permission/resource delegation get a danger
action.

sendRawTransaction relayed any signed transaction a site handed it;
it now broadcasts only txids Aegis itself signed.
2026-10-03 22:53:58 +02:00
Local Dev
0e7d6cc3c4 Aegis: Solana bridge signs the real bytes and shows what they do
- signAndSendTransaction signed String(Uint8Array) ("1,2,3,..."), so
  every dapp transaction got an invalid signature. Adapters gain
  signBytes(), which signs the exact message bytes.
- v0 (VersionedTransaction) messages were parsed with the version byte
  as the header; the shared parser handles legacy and v0.
- window.solana.signTransaction went through signMessage and its
  "moves no SOL" overlay. It now has its own handler and overlay, and
  signMessage refuses bytes that parse as a transaction (Phantom's rule),
  since such a signature is a valid transaction signature.
- Overlays decode System transfers and SPL transfer / approve /
  set-authority, and list everything else as not decoded.
2026-10-03 22:52:41 +02:00
Local Dev
314bce0905 Aegis: EVM bridge signs what the dapp asked for, chain per site
- eth_sendTransaction dropped the calldata, gas and fee fields, so an
  ERC-20 transfer went out as a 0-value send to the token contract and
  any contract call was broadcast as something else. plan() now carries
  data/gas/fee caps/nonce, estimates gas for calls, and the overlay
  decodes transfer/approve/permit/setApprovalForAll, flags unlimited
  approvals and calldata to a non-contract, and shows estimated vs max
  fee.
- personal_sign signed the hex string ethers/viem send as literal text;
  it now signs the decoded bytes.
- wallet_switchEthereumChain flipped the global selected wallet, so any
  site could move every connected dapp to another chain. Chain is now
  per origin; the sidebar selection no longer redirects a dapp.
- wallet_addEthereumChain silently persisted a connection for chains
  Aegis already had, handing the address to any site. Adding a chain
  no longer grants anything, and RPC URLs must be https.
- eth_sign (blind hash signing) is disabled, as in MetaMask.
2026-10-03 22:51:05 +02:00
Local Dev
4c3d27f1b3 Aegis: a plain Connect now lasts for the session
Connecting without ticking "Always allow" stored nothing, so the
site's very next call (personal_sign, signTransaction, ...) failed with
"not connected". Plain Connect now grants the origin in memory until
Theseus restarts; "Always allow" still persists. Every bridge (BCH,
Tron, EVM, Solana) checks grants the same way, revoke clears both, and
the connected-sites list shows EVM/Solana grants and which ones are
session-only.
2026-10-03 22:49:15 +02:00
Local Dev
da56187b39 Aegis 0.30.0: start the dapp-bridge audit batch
The 2026-09-13 audit of the dapp bridges found real signing bugs whose
fixes were never committed; 0.30.0 carries them, ported onto the current
add-on.
2026-10-03 22:47:48 +02:00
Local Dev
282884092d Merge theseus-lazy-start: extensions and Aegis start on first use
Bundles Aegis 0.29.0, which starts on first use and fixes the ETH/SOL
bridge that went missing on most pages.
2026-10-03 22:40:13 +02:00
Local Dev
9710a22d7a Theseus: bundle Pithos 0.3.3
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:12:45 +02:00
Local Dev
e150cfb442 Theseus: bundle Pithos 0.3.2
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:10:01 +02:00
Local Dev
987aca57a8 Theseus: bundle Pithos 0.3.1
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 21:25:25 +02:00
Local Dev
9f46d932b6 Aegis 0.29.0: start on first use, not at every Theseus launch
Aegis was most of what was left of launch cost: its crypto and
WizardConnect deps block the main thread for ~0.6 s right after the first
frame. It now declares its panel and "activation": "on-demand"; the
dapp bridges are still on every page from the start, and the first page
call, panel open or wiz:// link starts it.

activate() returns a promise the host waits on, so the call that woke
Aegis finds WizardConnect and the mounted wallets. With a locked vault it
does not wait for the mount (derive blocks until unlock), so the page gets
the usual locked answer in ~0.7 s instead of after the host's 5 s limit.

Two things only work while Aegis runs: a live WizardConnect pairing (no one
else listens on its relays) and "stay unlocked" (which also opens
Settings > Passwords). While either is on, Aegis asks the host to start it
at launch, and withdraws the request when both are off. Pairings left
behind by a removed wallet do not count.

Boot trace, same profile, 3 warm runs: main thread blocked in the first
6 s 970-1040 ms -> 300-320 ms, longest block 605-667 ms -> 227-244 ms,
toolbar 1.34-1.61 s -> 0.83-0.87 s.
2026-10-03 21:17:39 +02:00
Local Dev
129e4c6729 Aegis: the ETH and SOL bridge went missing on most pages, for good
The main-world bridge is appended at document_start, which often runs
before the page has an <html> element. The append threw on null, and the
catch marked the origin as Trusted-Types-blocked in localStorage, so every
later visit skipped window.ethereum, window.solana and the EIP-6963
announcement on that site. On example.com it failed on 6 of 6 loads.

Wait for <html> with a MutationObserver (it fires at the microtask
checkpoint before the first parser-inserted script, so the bridge is still
first), remember only real Trusted Types refusals, and use a new key so the
origins wrongly marked by the old one get the bridge back.
2026-10-03 21:17:38 +02:00
Local Dev
278da658ce Merge extensions-on-first-use: add-ons start when first used, not at launch
The left-edge panels landed meanwhile, so a panel record now carries both
its side and replace-by-id; a manifest-declared panel may say side:left too,
or a dormant add-on would show its panel on the wrong edge until it starts.
2026-10-03 21:07:44 +02:00
Local Dev
e65c5bea52 Merge Aegis 0.28.1: bundle the wallet users already get over the air
Fresh installs started on Aegis 0.9.0 and froze on large stores until the
OTA caught up. Bundling 0.28.1 makes the first launch the fixed one.
2026-10-03 21:07:11 +02:00
Local Dev
7087ab57ca Theseus: extension panels on the left edge
Extensions could only put panels in the right sidebar. An add-on can now
register a panel with side: "left": its icon joins the quick-links strip
(above the web-app links), and it opens in the strip's panel slot in its
own view with the sidebar preload, so the add-on bridge, events and the
widen/narrow controls work as on the right. A left panel and a quick-link
web app never share the slot; reopening keeps the panel's page and state.
Left panels drop out of the right sidebar and its dock. With the strip
turned off they fall back to the right sidebar so they stay reachable.

Pithos is the first: bundled copy rebuilt with side: "left".
2026-10-03 20:48:55 +02:00
Local Dev
a3d7c90b78 Theseus: bundle Pithos 0.3.0 (PIN gate, vault-derived phrase, guided setup)
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 20:42:23 +02:00
Local Dev
8186407b61 Theseus: bundle Pithos 0.2.0 (sidebar panel)
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs. Pithos moves from a toolbar menu that opened a loopback tab to a left-sidebar panel. Existing installs get the same version over the extension update channel.
2026-10-03 19:34:55 +02:00
Local Dev
4ad95b3c7a Theseus: bundle the Pithos add-on
Ships Pithos (the s3d control panel) as a built-in extension: the dock
menu opens it in a tab served from a loopback port, and "Stop s3d"
shuts the gateway down. Generated by Pithos/scripts/build-theseus-addon.mjs.

yaml is vendored under vendor/yaml/lib rather than node_modules/ or
dist/, because Theseus git-ignores both and a clean-worktree release
build would otherwise ship the add-on without its only dependency.
2026-10-03 19:03:05 +02:00