theseus/bundled-addons/aegis
Local Dev 3a4f47307c feat(aegis): 0.13.0 — read a seed phrase from a QR image
Import accepts a picture of a QR code. The file is decoded in the panel by
the vendored jsQR, drawn to a canvas: no upload, no network, no camera.

Image, not camera, on purpose. Theseus sets blockCamera + hideMediaDevices
by default and hides device labels from fingerprinting; a camera scanner
would fail silently for everyone until they turned that off globally, and a
wallet should not be the reason a privacy browser gives up the camera. A
photo or screenshot of the code needs no permission at all.

What comes back is classified, never trusted. A QR is opaque to the person
holding it, and "scan this to restore your wallet" is a working phish, so
the decode only chooses which field to fill:

  BIP39-shaped (12/15/18/21/24 lowercase words) -> mnemonic field
  WIF or 32-byte hex                            -> private key field
  anything else                                 -> nothing is filled; the
                                                   decoded text is shown so
                                                   the user can see it was a
                                                   URL, an address, or junk

Nothing auto-submits. The user reads what landed in the box and presses
Import, and the host handler still does the real validation.

jsQR 1.4.0 is vendored at lib/jsqr.js under Apache-2.0 with its LICENSE
beside it, unmodified and unminified — code that touches seed phrases should
be auditable in the shipped add-on, not an opaque blob. It is 57 KB gzipped.

Verified by round-tripping through the shipped path: Aegis's own encoder
builds the QR, it is rasterised to a real PNG File, and decodeQrFile() reads
it back byte-exact; an image with no code returns null rather than throwing;
and driving the actual file input fills the mnemonic for a seed, fills the
key field for a WIF, and leaves every field untouched for a phishing URL.
2026-09-28 00:05:04 +02:00
..
lib feat(aegis): 0.13.0 — read a seed phrase from a QR image 2026-09-28 00:05:04 +02:00
addon.json feat(aegis): 0.13.0 — read a seed phrase from a QR image 2026-09-28 00:05:04 +02:00
electrum-servers.json Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
index.js feat(aegis): 0.12.0 — open the wallet full screen, sidebar becomes the rail 2026-09-27 20:17:08 +02:00
panel.html feat(aegis): 0.13.0 — read a seed phrase from a QR image 2026-09-28 00:05:04 +02:00
panel.js feat(aegis): 0.13.0 — read a seed phrase from a QR image 2026-09-28 00:05:04 +02:00
qr.js Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
wallet-inject.js fix(aegis): 0.9.9 — keep the dapp bridge off Trusted-Types sites 2026-09-24 22:50:36 +02:00