theseus/dev
Local Dev 3243add70e Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID
Pages of Silent Mode projects can now sign the user in with their Theseus
ID instead of a wallet phrase typed into the page. Theseus writes the
sign-in message itself, takes the origin from the committed top frame, and
signs as a project only on an origin that project's list includes, so a
phishing page cannot get another project's signature and no page can use
the ID key to sign anything else.

- lib/theseus-id.cjs: the policy (first sign-in always asks and lets the
  user pick a private or One ID; Silent Mode projects are silent after
  that while the vault is open; per-site "always"; 10 silent signatures per
  minute per origin), the per-project record encrypted under a key derived
  from the vault, origin-list fetching with a 1 h cache and a 7-day stale
  fallback, and ID moves that send a proof signed by both keys and only
  finish once the project confirms.
- A locked vault is unlocked only for a page the user just clicked or typed
  in: navigator.userActivation alone is true on load for pages opened with
  loadURL, which would let a page pop the vault prompt by itself.
- Settings › Theseus ID: default mode, One ID, automatic sign-in toggle,
  signed-in projects (always, change ID, new ID, revoke) and a recovery key
  behind a fresh PIN / password check.
- TheseusID/registry/projects.json is the first-party list (Hephaestus,
  Sirius, Pithos); it and TheseusID/lib ship as extraResources.
- Token-aware cashaddrs (BNS owners) now decode for owner-signed lists.

Verified on a scratch profile against a local test project whose server
checks signatures with TheseusID/lib/verify.mjs: locked vault on load gives
"locked" with no prompt, first sign-in prompt, silent second sign-in, a
claimed foreign project refused without a prompt, an ID move that keeps the
project's account, and the recovery key behind the confirm prompt.
2026-10-04 20:48:07 +02:00
..
bcnr-selftest.js Ship Theseus 0.0.8: window.bcnr dApp API + eTLD+1 permission origins 2026-08-31 01:38:55 +02:00
blocklist-selftest.js Theseus: warn before opening a name a blocklist flags 2026-10-04 15:50:35 +02:00
list-tlds.mjs Sweep: mobile Ariadne updates, Deviant brand + sites, Hephaestus bootstrap, snappymail 2026-08-30 10:38:49 +02:00
origin-selftest.mjs Ship Theseus 0.0.8: window.bcnr dApp API + eTLD+1 permission origins 2026-08-31 01:38:55 +02:00
probe-site.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
README.md Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
registry-decide.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
rescheck.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
selftest.js Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
show-tlds-bch.mjs Sweep: mobile Ariadne updates, Deviant brand + sites, Hephaestus bootstrap, snappymail 2026-08-30 10:38:49 +02:00
signin-sites.test.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00
test-directip.mjs Initial commit — Silent Mode baseline (2026-07-29) 2026-07-29 13:54:34 +02:00
test-our-indexer.mjs Resolver 3438d558: ASCII-clean install.ps1 + multi-TLD NRPT + VPS-first electrum 2026-07-31 23:09:23 +02:00
theseus-id.test.cjs Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID 2026-10-04 20:48:07 +02:00
vault-pin.test.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00

Theseus dev/test harness

Two ways to drive Theseus's resolution + content path headlessly, for testing and debugging without clicking through the GUI. Both use the real resolver (Argus/src/lib/resolver-web.js) and gateway path the shipped app uses.

selftest.js — full render (Electron)

Runs the actual serveBns protocol handler (imported from main.js) in a hidden offscreen Electron window, loads a bns:// name, lets its JavaScript execute, then reports what really rendered and writes a screenshot.

npx electron dev/selftest.js hello.bch
npx electron dev/selftest.js coinspectrum.deviant.bch     # JS-driven Sia site
THESEUS_SETTLE=8000 npx electron dev/selftest.js <name>   # wait longer for data

Output: a JSON report (title, badge, stylesheet/script counts, local vs external broken-image counts, visible-text length, failed loads, verdict) plus dev-out/render.png and dev-out/render.html. Exit 0 = PASS. The verdict counts only the site's own bns:// assets — external CDN images are informational.

This is the faithful version of manual tests #2 (Sia-via-gateway rendering) and #3 (multi-TLD badge). main.js exports its handler and skips auto-launch when THESEUS_NO_AUTOSTART=1, which the harness sets.

probe-site.mjs — content path only (Node, no Electron)

Fast check with no display or Electron: resolves a name, fetches the index through the gateway exactly as serveBns does (with the <base> strip), and fetches each static same-origin asset, reporting status/content-type.

node dev/probe-site.mjs coinspectrum.deviant.bch

Limitation: static-HTML only. It cannot see assets a page builds at runtime in JavaScript — use selftest.js for JS-driven sites.

dev-out/

Generated render artifacts (screenshot + HTML dump). Safe to delete; regenerated on each selftest.js run.