The main-world bridge was pushed into every https page as a text script.
Sites that enforce Trusted Types refuse that and report the attempt to
their CSP endpoint — Google's sign-in pages among them, which then have
every reason to call the browser insecure. No dapp lives on those
origins: a static list of the big enforcing sites is skipped outright,
any other origin that rejects the bridge once is remembered and skipped
from then on, and where Trusted Types exist unenforced a policy keeps
the assignment clean.
The browser — the consumer face of the stack. Native .bch support with the
resolver built in, so a user installs one app instead of modifying their
operating system. Named for the thread through the labyrinth: the chain is the
thread.
Scope
Electron shell (Chromium engine, no forking): tabs, address bar, history.
In-process .bch resolution — no system daemon, no NRPT, no OS
trust-store changes; reuses bns.js from the BNS repo as a library.
Record handling: h render, ip connect, p/s3 via in-app gateway,
u redirect.
TLS via cert-verify hook (Electron setCertificateVerifyProc) against the
BNS root / on-chain tls fingerprints — no OS store touched.
Provenance indicator: shows whether a page came from the chain / Sia / a
direct server, with NFT category and record type — the decentralized padlock.
Status: not started
Build it in its own session/repo. The ready-to-paste brief is
BROWSER-PROMPT.md (a reference copy in this folder; canonical source is
D:\Dev\NameCoin\BROWSER-PROMPT.md — if they diverge, NameCoin wins). It points
here and reuses the resolver core. theseus.bch is registered and should
eventually serve the browser's own homepage over the protocol it implements.