theseus/dev
Local Dev 828100e2ce Theseus: warn before opening a name a blocklist flags
The blocklist consumer existed in the resolver library and the gateway, but
the browser opened a flagged name without comment. Now the indexer process
reads the subscribed lists from the chain every ten minutes and hands the
flags to main. A flagged name loads a warning page naming the reason, the
list and the report; the user may continue, and that is remembered per name.

Two gates, because content is reached two ways. loadBns shows the real
interstitial. serveBns refuses with an inline page on every path that skips
it: reload, back and forward, bns:// links, web app windows. The inline page
has no button, since a page at the site's own origin must not be able to
approve itself; only blocked.html may ask to continue, checked by file URL.

Settings › Naming has the policy: warn (default), never open, or ignore the
lists. The csam reason is never offered a way through. A list that cannot be
read keeps the last known flags and never stops a name from resolving.

The gateway put its own warning in front of flagged sites, which this
browser could not get past: it fetches files itself, with no cookie jar. It
now sends x-bns-policy: client and the gateway stays out of the way for a
client that says it decides for itself.

dev/blocklist-selftest.js runs the real protocol handler and decision
functions against a scratch profile.
2026-10-04 15:50:35 +02:00
..
bcnr-selftest.js Ship Theseus 0.0.8: window.bcnr dApp API + eTLD+1 permission origins 2026-08-31 01:38:55 +02:00
blocklist-selftest.js Theseus: warn before opening a name a blocklist flags 2026-10-04 15:50:35 +02:00
list-tlds.mjs Sweep: mobile Ariadne updates, Deviant brand + sites, Hephaestus bootstrap, snappymail 2026-08-30 10:38:49 +02:00
origin-selftest.mjs Ship Theseus 0.0.8: window.bcnr dApp API + eTLD+1 permission origins 2026-08-31 01:38:55 +02:00
probe-site.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
README.md Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
registry-decide.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
rescheck.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
selftest.js Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
show-tlds-bch.mjs Sweep: mobile Ariadne updates, Deviant brand + sites, Hephaestus bootstrap, snappymail 2026-08-30 10:38:49 +02:00
test-directip.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
test-our-indexer.mjs Resolver 3438d558: ASCII-clean install.ps1 + multi-TLD NRPT + VPS-first electrum 2026-07-31 23:09:23 +02:00

Theseus dev/test harness

Two ways to drive Theseus's resolution + content path headlessly, for testing and debugging without clicking through the GUI. Both use the real resolver (Argus/src/lib/resolver-web.js) and gateway path the shipped app uses.

selftest.js — full render (Electron)

Runs the actual serveBns protocol handler (imported from main.js) in a hidden offscreen Electron window, loads a bns:// name, lets its JavaScript execute, then reports what really rendered and writes a screenshot.

npx electron dev/selftest.js hello.bch
npx electron dev/selftest.js coinspectrum.deviant.bch     # JS-driven Sia site
THESEUS_SETTLE=8000 npx electron dev/selftest.js <name>   # wait longer for data

Output: a JSON report (title, badge, stylesheet/script counts, local vs external broken-image counts, visible-text length, failed loads, verdict) plus dev-out/render.png and dev-out/render.html. Exit 0 = PASS. The verdict counts only the site's own bns:// assets — external CDN images are informational.

This is the faithful version of manual tests #2 (Sia-via-gateway rendering) and #3 (multi-TLD badge). main.js exports its handler and skips auto-launch when THESEUS_NO_AUTOSTART=1, which the harness sets.

probe-site.mjs — content path only (Node, no Electron)

Fast check with no display or Electron: resolves a name, fetches the index through the gateway exactly as serveBns does (with the <base> strip), and fetches each static same-origin asset, reporting status/content-type.

node dev/probe-site.mjs coinspectrum.deviant.bch

Limitation: static-HTML only. It cannot see assets a page builds at runtime in JavaScript — use selftest.js for JS-driven sites.

dev-out/

Generated render artifacts (screenshot + HTML dump). Safe to delete; regenerated on each selftest.js run.