theseus/bundled-addons/aegis
Local Dev f27f3d27c9 Aegis: the PIN is enforced by the host, and every spend is confirmed there
PIN
- The PIN blob wraps the vault master password under six digits and sat in
  plain add-on storage, so a copy of the profile reduced the master password
  to a million offline PBKDF2 guesses. It is sealed with the OS keystore
  before it is stored; a plain blob from an older build is sealed on first
  read. New blobs use 600k iterations.
- "Ask for PIN on every transaction" was decided by the host and enforced
  by nobody: `send` never checked it and dapp transactions had no PIN step.
  A gate is now cleared only by the master password the PIN unwraps,
  verified against the vault, which also opens a single-use transaction
  clearance. Panel sends consume one; dapp transactions ask the open panel
  and wait.

Spending and signing
- Consolidate emptied wallets on the panel's confirmation alone, defaulted
  to every sibling when no list was sent, and swept into whatever was
  selected at click time. It now needs explicit sources and the previewed
  destination, and shows the whole batch on the host overlay.
- Typed data for a chain other than the connected one is refused. Permit
  and Permit2 signatures name the spender, tokens, amounts and expiry, and
  an unlimited one gets the danger action. Previews are no longer cut at
  600/400 characters without saying so.
- eth.rpc relayed any eth_* call for sites that never connected.
- The WizardConnect overlay lists the tokens being spent and received.

Send form
- "0,5" was read as 5: the parser deleted commas. Amounts are parsed
  exactly; a decimal comma is a decimal, ambiguous or non-numeric input is
  refused, extra decimals are an error instead of being dropped.
- Send submits the request the summary was computed for, never a fresh read
  of the form, and stays off while a plan is pending or stale.
- Switching wallet resets the form instead of leaving a live button on the
  previous wallet's plan.
- The unlock field kept the master password after unlocking; the PIN pad
  kept its digits and kept counting keystrokes typed elsewhere as PIN
  attempts; an idle lock left a revealed key or seed form on screen.
- Enter confirmed a dialog even with focus on Cancel.
2026-10-04 01:38:53 +02:00
..
lib Aegis 0.31.0: chain adapters stop trusting what they should check 2026-10-04 01:38:50 +02:00
addon.json Aegis 0.31.0: chain adapters stop trusting what they should check 2026-10-04 01:38:50 +02:00
electrum-servers.json Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
index.js Aegis: the PIN is enforced by the host, and every spend is confirmed there 2026-10-04 01:38:53 +02:00
LICENSE Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
panel.html perf(aegis): 251 KB off every panel open — jsQR loads when it is wanted 2026-10-03 16:39:45 +02:00
panel.js Aegis: the PIN is enforced by the host, and every spend is confirmed there 2026-10-04 01:38:53 +02:00
qr.js Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
README.md Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
wallet-inject.js Aegis: only the page's own scripts can reach the wallet relay 2026-10-03 22:54:59 +02:00

Aegis

The multi-chain wallet built into Theseus. Aegis runs as a Theseus add-on: it lives in the browser's sidebar and gives web pages a wallet without a separate extension.

  • Chains: Bitcoin Cash (with CashTokens and BCMR metadata), Bitcoin, DigiByte, Ethereum and EVM chains added through wallet_addEthereumChain, Solana, Tron and Siacoin.
  • Keys: every wallet is derived from the Theseus vault, so one master password protects them all. Seeds and private keys can also be imported.
  • Dapps: pages get window.bitcoincash, window.wizardconnect, window.ethereum (EIP-1193), window.solana and window.tronWeb / window.tronLink. Every connection and every signature goes through a Theseus approval overlay that shows what is being signed, decoded from the bytes that get signed.
  • WizardConnect: pair BCH dapps on the same device without scanning a QR.

Layout

addon.json        add-on manifest (id, version, capabilities, update URL)
index.js          the add-on: wallet runtimes, panel messages, dapp bridges
panel.html/.js    the sidebar UI
wallet-inject.js  page-side bridges (isolated world + injected main-world script)
lib/              chain adapters (chain-*.js), transaction and encoding helpers
lib/dgb/          vendored DigiByte address and PSBT modules

Aegis loads its heavier dependencies (@noble/*, @scure/bip32, bitcoinjs-lib, @wizardconnect/*, @bitauth/libauth) from Theseus's dependency tree through the add-on API, so this folder runs only inside Theseus.

Releases

Aegis has its own version and its own update channel, separate from Theseus releases. Theseus checks the signed feed in addon.json's updateURL, verifies the Ed25519 signature and the SHA-256 of the package, and applies the update on the next launch. Each Theseus release also bundles the current Aegis for new installs.

This repository mirrors TheseusNavigator/bundled-addons/aegis from the Theseus source tree, with its history.

License

Mozilla Public License 2.0, see LICENSE. lib/jsqr.js is jsQR, Apache-2.0, see lib/jsqr.LICENSE. WizardConnect (LGPL-3.0-or-later) is not included here; Aegis loads it from Theseus as a separate module.