theseus/lib
Local Dev 7cc66ce680 Theseus: community extensions run in their own sandboxed process
An extension was require()d into the browser's main process. Its declared
capabilities bound only an honest one: there it could load electron, hook
the unlock prompt for the master password, read the vault files and the
wallet's store, call the OS keystore, and reach every tab.

Extensions that do not ship with Theseus now run in a separate process, in
Node mode under Node's permission model: read access to their own folder,
write access to a scratch folder, no child processes, no workers, no native
add-ons, no Electron, and none of the browser's memory. They reach the
browser only through an allow-listed message API that calls the same
functions, with the same capability checks, as before. Built-in add-ons are
unchanged and stay in-process.

For extension authors: host calls return promises (tabs.active included);
api.require / api.import are gone, so dependencies must be bundled;
registerRequestFilter and registerSiteRoute are not offered; the store is
handed over at start and written through, so storage.get stays synchronous.
An approval raised while handling a page message is still tied to that
page's tab. If the sandbox cannot start, the extension does not run.

The channel is JSON with tagged bytes: the binary IPC format depends on the
exact V8 build on both ends.
2026-10-05 22:54:26 +02:00
..
addon-sandbox-runner.cjs Theseus: community extensions run in their own sandboxed process 2026-10-05 22:54:26 +02:00
addon-store.cjs Theseus: add-on stores live in memory — no more 16 s "Not Responding" at launch 2026-10-03 16:08:22 +02:00
hermes.js Hermes: optional bind to password vault (skip the second mnemonic prompt) 2026-08-19 00:38:52 +02:00
package.json Hermes: wire NIP-17 messaging into Theseus, provision chipnet hermes.bch 2026-08-18 20:14:43 +02:00
publisher-sig.mjs feat: community extensions — publish with a BCDN name, install from Settings, theseus.x catalog 2026-09-20 15:26:30 +02:00
signin-sites.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00
theseus-id.cjs Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID 2026-10-04 20:48:07 +02:00
tpm-pin.cjs Vault PIN: tie it to the TPM and never store it unsealed 2026-10-04 03:42:02 +02:00
update-helper.cjs Theseus: close the Settings-tab vault leak and the add-on update signer bypass 2026-10-03 09:50:10 +02:00
vault-pin.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00