Commit graph

531 commits

Author SHA1 Message Date
Local Dev
449a967e21 Theseus: bundle Pithos 0.3.7 with the music player 2026-10-04 02:23:07 +02:00
Local Dev
4511a933f4 Aegis: a PIN clears only the transaction it was entered for
One global 90 s clearance was opened by every PIN proof. Opening the
wallet or ticking a setting let the next dapp transaction from any site
through without a PIN; a dapp waiting in its poll could take the clearance
the user had just made for their own send; and with two sites waiting the
second one's request was dropped.

Each waiting dapp transaction now has an id, and only a proof naming that
id releases it; a proof given for "transaction" in the panel clears the
panel's next send only; any other proof clears nothing. The panel answers
waiting sites one at a time. Promote to HD now asks for the PIN like any
other spend instead of failing when PIN-per-transaction is on.
2026-10-04 02:23:02 +02:00
Local Dev
2faa3d808a Aegis: a WizardConnect request the overlay cannot read is not signed
wc-sign accepted a flat request (tx and sourceOutputs at the top) that
buildWcApproval does not read, so any paired dapp could get a signature
after an overlay showing only the wallet, an input count and the sighash.
The signer now takes only the nested WizardConnect shape, and the overlay
refuses, without showing anything, a request whose outputs or spent
inputs it cannot decode. Total out now sums every output, not the first 8.
2026-10-04 02:21:11 +02:00
Local Dev
e02d4698ea Aegis: a permit is described from what the signature covers
describePermit read td.message directly, and the EIP-712 encoder ignores
keys a type does not declare. A dapp could put a decoy allowed:false or
details:{amount:"1"} beside an unlimited permit and the overlay showed
the decoy, not risky, under the plain Sign button, with the same digest.

The overlay and the message preview are now built from the declared
fields only, the permit variant is picked from the declared type, and
dropped fields are counted on the overlay. Amounts of 2^96 units and up
are flagged as effectively unlimited, marketplace orders and Safe
transactions get the warning too, and the encoder refuses a non-hex
address instead of signing it as zero bytes.
2026-10-04 02:19:42 +02:00
Local Dev
b85605416e Aegis: the PIN is checked by the host, and guessing ends at five
The panel fetched the PIN blob and decrypted it itself, then reported its
own failures. The lockout therefore counted only what a well-behaved panel
chose to report, a 15-minute timer handed out five more guesses forever,
and anything able to run in the panel could take the blob and search the
million PINs offline in minutes.

The blob now never leaves index.js: pinSet builds it after checking the
master password against the vault, pinUnwrap counts each guess before
trying it, and five wrong guesses switch the PIN off until the master
password is entered. The panel keeps its PIN pads and only sends digits.
A blob from an older build (200k iterations) is re-made at 600k under a
fresh salt on the next correct PIN. Only the topmost PIN pad listens to
typed digits, so two stacked pads cannot both take one entry.
2026-10-04 02:17:26 +02:00
Local Dev
61144e821e Theseus: a widened left panel covers the page instead of squeezing it
Widening an add-on's left panel shrank the open tab to a 120 px strip
and, with the right sidebar open, pushed the sidebar narrower too. Now
the widened panel lies over the tab area like a page of its own, up to
the right sidebar, which keeps its width; the tab underneath keeps its
size. Choosing a tab, opening Settings or a new tab, or using the
address bar narrows the panel back to a bar beside the page, the way a
maximized right sidebar already steps back.
2026-10-04 02:16:23 +02:00
Local Dev
6ba16261ab Theseus: bundle Pithos 0.3.7 2026-10-04 02:16:11 +02:00
Local Dev
bd113f9b47 Aegis 0.30.1: the Tron duplicate-field fix, ahead of 0.31.0
0.30.0 is on the update channel and bundled in Theseus 0.3.75 with a Tron
decoder that a hostile site can use to show one transfer and sign another.
This is 0.30.0 plus that fix only; 0.31.0 is still under review.
2026-10-04 02:11:42 +02:00
Local Dev
1db2c4265b Aegis: refuse a Tron transaction whose fields appear twice
The decoder read the first copy of a singular protobuf field; java-tron
keeps the last. Any.value is opaque bytes, so a TransferContract carrying
two recipients and two amounts hashes to the same txid either way: the
overlay showed "1 TRX to X" while the chain would move 999 TRX to
another address. It also defeated the plan-time and sign-time draft checks
against a hostile node. A repeated singular field, or a known field with
the wrong wire type, now refuses the transaction.
2026-10-04 02:11:41 +02:00
Local Dev
c906e7b8ed Aegis: refuse a Tron transaction whose fields appear twice
The decoder read the first copy of a singular protobuf field; java-tron
keeps the last. Any.value is opaque bytes, so a TransferContract carrying
two recipients and two amounts hashes to the same txid either way: the
overlay showed "1 TRX to X" while the chain would move 999 TRX to
another address. It also defeated the plan-time and sign-time draft checks
against a hostile node. A repeated singular field, or a known field with
the wrong wire type, now refuses the transaction.
2026-10-04 02:10:51 +02:00
Local Dev
80fe82abee Theseus: an add-on can limit which sites get its bridge; vault secrets stay first-party
- Page-inject policy. An add-on may keep { mode, origins } under the
  reserved storage key "__pageInjectPolicy"; in "allowed" mode its bridge is
  injected, and its page messages accepted, only on the listed origins. It
  is read from the store because the decision is made synchronously at
  document start and must hold while an on-demand add-on is still dormant.
  A wallet injected into every page tells every page the user has one.
  api.features.pageInjectPolicy lets an add-on tell an old host apart.
- vault.imports (raw imported seeds and keys, not namespaced per add-on) and
  vault.lifecycle unlock/setup/lock (the master password, and an
  unthrottled oracle for it) are for add-ons that ship with Theseus. A
  community extension with vault-derive could read the wallet's imported
  keys. Others use vault.requestUnlock, where Theseus draws the prompt.
2026-10-04 01:55:40 +02:00
Local Dev
884f3948b8 Aegis: fees that follow the network, connections that come back, its own name on Solana
Still 0.31.0 (unpublished batch).

- ETH nonce. The pending count from a load-balanced RPC often misses a
  transaction this wallet sent seconds ago, so two sends in a row shared a
  nonce and the second failed or replaced the first. The nonce is taken at
  signing, from the RPC or from what the wallet itself last broadcast,
  whichever is higher, and broadcasts are serialised per wallet.
- Chains without EIP-1559 (no baseFeePerGas) get a legacy EIP-155
  transaction; they rejected the type-2 envelope, so a network added by a
  dapp could receive but never send. The tip is clamped to the fee cap.
- Bitcoin and DigiByte take their fee rate from the Electrum server's
  estimate instead of a constant, size each output from its real script
  (a taproot destination was undercounted), and round the size up before
  pricing. Bitcoin inputs signal replace-by-fee. DigiByte keeps its 20
  sat/vB floor and does not signal RBF, which it does not have.
- Electrum: a wallet with live subscriptions went quiet for good when its
  server dropped. The client reconnects with backoff, pings to catch dead
  sockets, times out a silent connect, and hands the replayed subscription
  answers on as notifications so the wallet refreshes. dispose() ends it.
- Max with an SPL token selected did nothing; it now fills the exact token
  balance.
- Removing a wallet retired its derivation index for good. Add wallet now
  takes the lowest free index, so the same wallet comes back.
- Solana: registered through the Wallet Standard as "Aegis" instead of
  setting isPhantom, with silent connect for already-connected sites.
- "Only show the wallet to sites I enable": Aegis keeps the host's
  page-inject allow-list in step with enabled and connected sites.
2026-10-04 01:55:38 +02:00
Local Dev
14d9df31cc fix(theseus/error): show branded error page on BCNR→clearnet fallback failures
flytastic.ru (and any other site where the BCNR lookup NXDOMAINs and
the clearnet fallback fails with a cert / network error) was leaving
the tab blank instead of showing the error page.

Cause — tab.internalNav was overloaded. loadBns's fallbackToWeb sets
internalNav=true before loadURL("https://host/") so will-navigate
doesn't re-route the programmatic nav back through navigateTab. The
did-fail-load handler was using the SAME flag to suppress recursion
on its own loadFile(error.html) call — so a cert error during the
clearnet fallback was silently swallowed.

Narrow the suppression to its real target: skip did-fail-load only
when the failing URL is file:// (our own error.html / home.html
loads). Clearnet HTTPS failures from a programmatic loadURL now
surface the branded error page like any other failed navigation. The
will-navigate guard (its original purpose) is untouched.
2026-10-04 01:50:31 +02:00
Local Dev
faea4147d2 feat(theseus/error): CF Bot Fight 503 hint with .bch mirror suggestion
When a top-level HTTPS load returns 503, sniff the body for CF Bot
Fight markers (cloudflare + blocked/challenge/attention-required, or
cf-chl). If it matches, replace the CF interstitial with a branded
error page carrying kind=cf-blocked. The page explains why Electron
browsers get 503 (TLS ClientHello fingerprint below HTTP, no user-
agent tweak fixes it) and offers next steps.

If a .bch name has a `p` record proxying the same origin, the page
surfaces it as a one-click retry — preserving the original path, so
/faq becomes /faq on the mirror rather than the mirror's root. Mirror
lookup walks the warm sharedIndex, so it's synchronous and works
offline. If no mirror exists, links to silentmode.st/mirrors where
users can mint one via Sirius.

Guarded against races — the 250 ms delay before body sniff re-checks
that the tab is still on the same URL and not destroyed, both before
and after the executeJavaScript resolves, so a JS-redirect after the
503 doesn't cause misclassification.
2026-10-04 01:50:09 +02:00
Local Dev
2dfa9e9c3e Theseus: an add-on's key namespace cannot be taken by another add-on
- `absorbs` lets one add-on derive under another's vault namespace. A
  community install has the field stripped, but an update of one is placed
  as shipped, so a second version could declare absorbs:["aegis"] and derive
  the wallet's keys. It is now honoured only for ids that ship inside
  Theseus, at the one place that matters: vault.derive.
- The legacy ids Aegis absorbs ("bchwallet", "siawallet") no longer have a
  bundled folder, so nothing stopped a catalog extension from installing
  under one and deriving `bchwallet/...`. They are reserved at install and
  refused at derive.
- A page-to-add-on message is accepted only from the tab's top-level frame.
  The origin shown to the user is the top-level URL, so a subframe that
  reached the channel would have been credited with its parent's origin.
- The approval overlay ignores everything but Cancel for the first 800 ms.
  A page can raise it without a gesture and knows where the primary button
  lands, which made "double-click here" a way to approve a spend.
2026-10-04 01:41:01 +02:00
Local Dev
f27f3d27c9 Aegis: the PIN is enforced by the host, and every spend is confirmed there
PIN
- The PIN blob wraps the vault master password under six digits and sat in
  plain add-on storage, so a copy of the profile reduced the master password
  to a million offline PBKDF2 guesses. It is sealed with the OS keystore
  before it is stored; a plain blob from an older build is sealed on first
  read. New blobs use 600k iterations.
- "Ask for PIN on every transaction" was decided by the host and enforced
  by nobody: `send` never checked it and dapp transactions had no PIN step.
  A gate is now cleared only by the master password the PIN unwraps,
  verified against the vault, which also opens a single-use transaction
  clearance. Panel sends consume one; dapp transactions ask the open panel
  and wait.

Spending and signing
- Consolidate emptied wallets on the panel's confirmation alone, defaulted
  to every sibling when no list was sent, and swept into whatever was
  selected at click time. It now needs explicit sources and the previewed
  destination, and shows the whole batch on the host overlay.
- Typed data for a chain other than the connected one is refused. Permit
  and Permit2 signatures name the spender, tokens, amounts and expiry, and
  an unlimited one gets the danger action. Previews are no longer cut at
  600/400 characters without saying so.
- eth.rpc relayed any eth_* call for sites that never connected.
- The WizardConnect overlay lists the tokens being spent and received.

Send form
- "0,5" was read as 5: the parser deleted commas. Amounts are parsed
  exactly; a decimal comma is a decimal, ambiguous or non-numeric input is
  refused, extra decimals are an error instead of being dropped.
- Send submits the request the summary was computed for, never a fresh read
  of the form, and stays off while a plan is pending or stale.
- Switching wallet resets the form instead of leaving a live button on the
  previous wallet's plan.
- The unlock field kept the master password after unlocking; the PIN pad
  kept its digits and kept counting keystrokes typed elsewhere as PIN
  attempts; an idle lock left a revealed key or seed form on screen.
- Enter confirmed a dialog even with focus on Cancel.
2026-10-04 01:38:53 +02:00
Local Dev
9e7e9d5e8b Aegis 0.31.0: chain adapters stop trusting what they should check
Start of the next batch; 0.30.0 is published.

- Tron panel sends signed whatever /wallet/createtransaction returned while
  the approval showed the local request. The returned bytes are now decoded
  and must be one transfer from this wallet, to that address, for that
  amount, with a matching txID - checked at plan time and again at signing.
- Importing a Solana wallet from a seed phrase threw on every attempt (a
  mis-parenthesised `new require("crypto").createHmac` plus a bare require
  of an ESM-only subpath). SLIP-0010 now uses Node's HMAC, as chain-sol does.
- Imported BCH wallets put token-bearing UTXOs into coin selection. They are
  excluded, as in the HD wallet, and the balance counts what can be spent.
- WizardConnect dropped the token from each spent output before signing, so
  under SIGHASH_UTXOS every signature of a token transaction was invalid.
- A wallet disposed while a refresh was in flight re-armed its poll timer.
- BCMR registry content is bounded before it reaches the panel: control and
  bidi characters stripped, lengths capped, decimals 0-18, icons https/ipfs
  only, registries https only.
2026-10-04 01:38:50 +02:00
Local Dev
84a37b26bf Aegis: README and MPL-2.0 license for its own repository
Aegis is getting a standalone forge repo (silentmode/aegis) split from
this folder. Inside Theseus it was covered by the root LICENSE; on its
own it needs the license and a description in the folder itself.
2026-10-04 00:24:01 +02:00
Local Dev
3de25581b3 Theseus: bundle Pithos 0.3.6
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-04 00:09:55 +02:00
Local Dev
1244dae25e Theseus: bundle Pithos 0.3.5
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-04 00:05:50 +02:00
Silent Mode
5f02973597 Theseus: Settings language dropdown — supported first, in their own optgroup
The dropdown mixed supported and unsupported languages in one list ranked
by global speakers, so the six languages the translator actually handles
today (en, es, fr, de, el, ru) were scattered between greyed rows. The
user had to scan every entry to find the ones they could pick. The
dropdown is now partitioned into two <optgroup>s — "Supported today"
first with the enabled languages, "Translator coming later (Accept-
Language only)" below with the greyed rows — so the top of the list
is actionable and the roadmap is still visible underneath.
2026-10-03 23:27:05 +02:00
Local Dev
8b74f5cbf9 Merge branch 'master' into claude/zen-archimedes-463527 2026-10-03 23:02:46 +02:00
Local Dev
7185509355 Theseus 0.3.75: previous tabs reopen, extensions start on first use
Ships 2437506 (the restore setting was a no-op with the default quit
clear), the first-use loader for extensions with Aegis 0.29.0 bundled
(~0.7 s less main-thread work at launch, ETH/SOL bridge fixed), the
language picker as an overlay, Pithos 0.3.4 and the Ariadne status row.
2026-10-03 23:02:25 +02:00
Local Dev
7bea16aa28 Merge restore-fix: previous tabs reopen again 2026-10-03 23:02:03 +02:00
Local Dev
71f0c96e93 Theseus: reopen the previous tabs even when history is cleared on quit
"Open previous windows and tabs" and "Clear history on quit" both default
to on, and the quit clear deleted session.json along with the history, so
every launch started from the start page and the restore setting did
nothing. The open tabs are what the user asked to reopen, not history:
while restore is on, the quit clear keeps them and still drops back/forward
and address-bar history. With restore off, the tab list is deleted as
before.
2026-10-03 23:01:56 +02:00
Local Dev
03b497dcae Aegis: DigiByte addresses follow the chosen address family
WalletKeys.entry() built a bech32 p2wpkh address whatever the account
path's purpose, so picking Legacy (D...), Wrapped SegWit (S...) or
Taproot (dgb1p...) in Settings showed a dgb1q address from the BIP44/
49/86 key tree, one no other wallet restoring that path would find.
Each family now derives its own address and script, and spending
supplies what its inputs need (previous tx for P2PKH, redeem script for
P2SH-P2WPKH, tap-tweaked key for Taproot, which is active on DigiByte),
with per-family fee sizes. Unknown purposes are refused instead of
falling back to BIP84.

Also: inputs were signed in selection order but the PSBT orders them by
BIP69, so a spend from two addresses tried to sign each input with the
other's key. They are now signed in the PSBT's order.
2026-10-03 23:01:15 +02:00
Local Dev
03140fae9d Aegis: WizardConnect signing requests can be approved
approvalRequest passed approve/reject keys the host overlay does not
know, so it showed a lone "OK" button whose id never equalled
"approve": every WizardConnect signing request was refused, and the
HTML body was shown as literal markup. It now passes a Sign action and
plain rows: wallet, input count, each output decoded to a cashaddr on
the wallet's network (or OP_RETURN / raw script), total, and who
broadcasts.
2026-10-03 23:01:15 +02:00
Local Dev
5769d837bd Aegis: load the DigiByte deps module as ESM in a dev checkout
lib/dgb/deps.js is ESM, but in a dev checkout the nearest package.json
is TheseusNavigator's, which says "type": "commonjs"; the import threw
and DigiByte was silently unavailable whenever Theseus ran from the
repo. Shipped installs have no package.json above the add-on, so they
were unaffected. lib/dgb/core and lib/dgb/psbt already carry the same
marker.
2026-10-03 23:00:47 +02:00
Local Dev
3d2e3c784b Theseus: bundle Pithos 0.3.4
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:57:47 +02:00
Local Dev
f57cf4c894 Aegis: only the page's own scripts can reach the wallet relay
The isolated-world relay accepted any postMessage carrying the fixed
tag "aegis-aegis", including one from a cross-origin iframe (an ad,
an embed), and attributed it to the top-level origin and its grants.
The tag now carries a per-load random nonce that only the injected
main-world bridge knows, and both listeners drop events whose source
is not this window. The document_start install path is unchanged.
2026-10-03 22:54:59 +02:00
Local Dev
206f54edd2 Aegis: Tron signing overlay comes from the bytes being signed
The overlay for tronWeb-built transactions was built from the dapp's
raw_data JSON, which need not match raw_data_hex: a site could show
"1 TRX to X" and get a signature over anything. lib/tron-decode.js
decodes Transaction.raw from raw_data_hex (contract type, owner, to,
amount, TRC-20 transfer/approve calldata, fee limit, memo); the txID
must match the bytes, every contract's owner must be this wallet, and
unlimited approvals or permission/resource delegation get a danger
action.

sendRawTransaction relayed any signed transaction a site handed it;
it now broadcasts only txids Aegis itself signed.
2026-10-03 22:53:58 +02:00
Local Dev
0e7d6cc3c4 Aegis: Solana bridge signs the real bytes and shows what they do
- signAndSendTransaction signed String(Uint8Array) ("1,2,3,..."), so
  every dapp transaction got an invalid signature. Adapters gain
  signBytes(), which signs the exact message bytes.
- v0 (VersionedTransaction) messages were parsed with the version byte
  as the header; the shared parser handles legacy and v0.
- window.solana.signTransaction went through signMessage and its
  "moves no SOL" overlay. It now has its own handler and overlay, and
  signMessage refuses bytes that parse as a transaction (Phantom's rule),
  since such a signature is a valid transaction signature.
- Overlays decode System transfers and SPL transfer / approve /
  set-authority, and list everything else as not decoded.
2026-10-03 22:52:41 +02:00
Local Dev
314bce0905 Aegis: EVM bridge signs what the dapp asked for, chain per site
- eth_sendTransaction dropped the calldata, gas and fee fields, so an
  ERC-20 transfer went out as a 0-value send to the token contract and
  any contract call was broadcast as something else. plan() now carries
  data/gas/fee caps/nonce, estimates gas for calls, and the overlay
  decodes transfer/approve/permit/setApprovalForAll, flags unlimited
  approvals and calldata to a non-contract, and shows estimated vs max
  fee.
- personal_sign signed the hex string ethers/viem send as literal text;
  it now signs the decoded bytes.
- wallet_switchEthereumChain flipped the global selected wallet, so any
  site could move every connected dapp to another chain. Chain is now
  per origin; the sidebar selection no longer redirects a dapp.
- wallet_addEthereumChain silently persisted a connection for chains
  Aegis already had, handing the address to any site. Adding a chain
  no longer grants anything, and RPC URLs must be https.
- eth_sign (blind hash signing) is disabled, as in MetaMask.
2026-10-03 22:51:05 +02:00
Local Dev
4c3d27f1b3 Aegis: a plain Connect now lasts for the session
Connecting without ticking "Always allow" stored nothing, so the
site's very next call (personal_sign, signTransaction, ...) failed with
"not connected". Plain Connect now grants the origin in memory until
Theseus restarts; "Always allow" still persists. Every bridge (BCH,
Tron, EVM, Solana) checks grants the same way, revoke clears both, and
the connected-sites list shows EVM/Solana grants and which ones are
session-only.
2026-10-03 22:49:15 +02:00
Local Dev
da56187b39 Aegis 0.30.0: start the dapp-bridge audit batch
The 2026-09-13 audit of the dapp bridges found real signing bugs whose
fixes were never committed; 0.30.0 carries them, ported onto the current
add-on.
2026-10-03 22:47:48 +02:00
Local Dev
4f745406d8 Settings > Ariadne's Thread: Refresh/Install/Update live in the Status row
They had a row of their own with nothing else in it, which read as an
empty card with a stray button. Same layout as the Plug-ins list row now:
buttons beside the on/off switch.
2026-10-03 22:43:30 +02:00
Local Dev
282884092d Merge theseus-lazy-start: extensions and Aegis start on first use
Bundles Aegis 0.29.0, which starts on first use and fixes the ETH/SOL
bridge that went missing on most pages.
2026-10-03 22:40:13 +02:00
Local Dev
9710a22d7a Theseus: bundle Pithos 0.3.3
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:12:45 +02:00
Local Dev
e150cfb442 Theseus: bundle Pithos 0.3.2
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 22:10:01 +02:00
Silent Mode
fa50f97e6f Theseus: language picker is a floating overlay now, not a native menu
The globe-chip menu was a native Electron menu — square corners, system
font, no theming beyond the OS's own context-menu paint. Replaces it with
a floating overlay WebContentsView (lang-picker.html + preload),
following the same pattern the engine picker and the popover already
use: rounded 12px surface, acid-tint accents on the current pin, soft
shadow, dark + light scheme, flush under the chip's bottom-right.

The content is organised around the user's intent — translate first,
pick a language second. The "Translate this page" row sits at the top
when it is actionable (web tab + supported source + supported target),
with the detected source and the target under the label so the user can
tell what the backend will do before they click. Once a page is
translated, that row flips to "Show original (<source>)". Below the
action strip is Automatic + the six supported languages, each with a
two-letter code chip in the left slot and a ✓ on the current pin.
Unsupported languages are hidden by default inside a collapsible "More
languages (translator coming later)" group — click to expand, click to
collapse; a pinned-unsupported auto-expands so its ✓ stays visible.

Plumbing matches engine-picker: deferred-load WebContentsView,
closeOnClickAway, setBounds anchored under the chip, picker renderer
reports its own content height after each render so the overlay
contracts and expands with the "More languages" toggle. State pushes
come from emitTranslateState (so the Translate / Show-original row
updates when a page finishes auto-translating with the picker open)
and from broadcastSettings (so a Settings-side language change
re-paints the ✓).

Verified end-to-end: picker loads, shows Automatic + 6 supported in the
default list and 18 greyed in the "More" group, repaints to "⟲ Show
original (Spanish)" after an auto-translate completes.
2026-10-03 21:33:16 +02:00
Local Dev
987aca57a8 Theseus: bundle Pithos 0.3.1
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 21:25:25 +02:00
Silent Mode
a2c43d6a22 Theseus: language menu stays short, language change always re-translates
The chip menu showed every entry in WEBSITE_LANGUAGE_QUICK (24 rows, most
greyed with "— translator coming later") and the picker read as a wall
of coming-soon noise. The top strip now carries only the languages the
translator actually handles — Automatic plus the six supported ones
(en, es, fr, de, el, ru) — and everything else moves into a "More
languages (translator coming later)" submenu where the greyed rows live
without crowding the main menu. If the user's current pin is one of the
unsupported ones, it stays visible at the top so the ✓ reads at a
glance, not two levels deep.

Translation didn't follow a language change reliably:
- A page with no `<html lang>` left pageLang empty, which the auto-
  translate hook took as "no translation needed" and skipped the entire
  page. Now an empty source is still translated (the backend auto-detects
  the real language), and the hook only skips when pageLang is known AND
  matches the user's target.
- Changing the pin via Settings or the chip reloaded the active tab but
  did not re-translate — the hook needs auto-offer on, and even then
  a `pending` latch set by setWebsiteLanguage was wiped by the reload's
  did-start-navigation reset. The `pending` bit now survives that reset,
  so the did-finish-load hook translates unconditionally for an explicit
  language switch (the user ASKING for a new language IS the request to
  translate the current page too). A translated page is reverted before
  the reload so the fresh HTML lands on original DOM, not a mix of old
  translated nodes and new content. Verified end-to-end: an es→en auto-
  translate followed by a pin to French takes the page to French in one
  shot without the chip being touched.
2026-10-03 21:24:43 +02:00
Local Dev
9f46d932b6 Aegis 0.29.0: start on first use, not at every Theseus launch
Aegis was most of what was left of launch cost: its crypto and
WizardConnect deps block the main thread for ~0.6 s right after the first
frame. It now declares its panel and "activation": "on-demand"; the
dapp bridges are still on every page from the start, and the first page
call, panel open or wiz:// link starts it.

activate() returns a promise the host waits on, so the call that woke
Aegis finds WizardConnect and the mounted wallets. With a locked vault it
does not wait for the mount (derive blocks until unlock), so the page gets
the usual locked answer in ~0.7 s instead of after the host's 5 s limit.

Two things only work while Aegis runs: a live WizardConnect pairing (no one
else listens on its relays) and "stay unlocked" (which also opens
Settings > Passwords). While either is on, Aegis asks the host to start it
at launch, and withdraws the request when both are off. Pairings left
behind by a removed wallet do not count.

Boot trace, same profile, 3 warm runs: main thread blocked in the first
6 s 970-1040 ms -> 300-320 ms, longest block 605-667 ms -> 227-244 ms,
toolbar 1.34-1.61 s -> 0.83-0.87 s.
2026-10-03 21:17:39 +02:00
Local Dev
129e4c6729 Aegis: the ETH and SOL bridge went missing on most pages, for good
The main-world bridge is appended at document_start, which often runs
before the page has an <html> element. The append threw on null, and the
catch marked the origin as Trusted-Types-blocked in localStorage, so every
later visit skipped window.ethereum, window.solana and the EIP-6963
announcement on that site. On example.com it failed on 6 of 6 loads.

Wait for <html> with a MutationObserver (it fires at the microtask
checkpoint before the first parser-inserted script, so the bridge is still
first), remember only real Trusted Types refusals, and use a new key so the
origins wrongly marked by the old one get the bridge back.
2026-10-03 21:17:38 +02:00
Local Dev
278da658ce Merge extensions-on-first-use: add-ons start when first used, not at launch
The left-edge panels landed meanwhile, so a panel record now carries both
its side and replace-by-id; a manifest-declared panel may say side:left too,
or a dormant add-on would show its panel on the wrong edge until it starts.
2026-10-03 21:07:44 +02:00
Local Dev
e65c5bea52 Merge Aegis 0.28.1: bundle the wallet users already get over the air
Fresh installs started on Aegis 0.9.0 and froze on large stores until the
OTA caught up. Bundling 0.28.1 makes the first launch the fixed one.
2026-10-03 21:07:11 +02:00
Local Dev
61153481a6 Theseus 0.3.74: vault PIN, extension panels on the left, Pithos 0.3.0
Ships 08b101f (a quick-unlock PIN for the vault, shared with extensions
through api.vault.requestUnlock), 3fd0fe3 (extensions can open from the
left edge, beside the quick links), Pithos 0.3.0 bundled (c2df6e3: guided
setup, PIN gate, recovery phrase from the vault, on the left) and e1c5d91
(one language chip with "Translate this page" and automatic translation).
2026-10-03 20:49:51 +02:00
Local Dev
7087ab57ca Theseus: extension panels on the left edge
Extensions could only put panels in the right sidebar. An add-on can now
register a panel with side: "left": its icon joins the quick-links strip
(above the web-app links), and it opens in the strip's panel slot in its
own view with the sidebar preload, so the add-on bridge, events and the
widen/narrow controls work as on the right. A left panel and a quick-link
web app never share the slot; reopening keeps the panel's page and state.
Left panels drop out of the right sidebar and its dock. With the strip
turned off they fall back to the right sidebar so they stay reachable.

Pithos is the first: bundled copy rebuilt with side: "left".
2026-10-03 20:48:55 +02:00
Local Dev
a3d7c90b78 Theseus: bundle Pithos 0.3.0 (PIN gate, vault-derived phrase, guided setup)
Rebuilt from Pithos/ with scripts/build-theseus-addon.mjs.
2026-10-03 20:42:23 +02:00
Local Dev
de7735feb3 Theseus: quick-unlock PIN for the vault, shared with extensions
The vault re-locks on every restart and only the master password opened
it, so every extension that needs it (Aegis, now Pithos) either asked for
the master password itself or grew its own PIN. Theseus now owns one:

- Settings > Passwords sets, changes or removes a 6-digit PIN. The PIN
  wraps the master password (PBKDF2-SHA256, 600k iterations, AES-256-GCM)
  and the result is sealed with the OS keystore (safeStorage: DPAPI /
  Keychain / libsecret), so a copied vault-pin.json cannot be brute-forced
  elsewhere. Every unlock still ends at the master password.
- Three wrong PINs in a row require the master password. The strike count
  lives in the same file, so a restart does not reset it; a successful
  master-password unlock does. A PIN whose password no longer opens the
  vault (password changed) is dropped.
- unlock.html is Theseus's own prompt, over the whole window: PIN pad, or
  the master password. Extensions call api.vault.requestUnlock({ reason })
  (vault-derive capability) and get { ok } back; what the user typed never
  reaches them. Settings' locked screen offers "Unlock with PIN" through
  the same prompt.
2026-10-03 20:33:26 +02:00