theseus/bundled-addons/vpn
Local Dev 676424db87 feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI
Ships the extension small (~50 KB tarball). No binaries in it — the
platform-matched sing-box is downloaded on first "Turn on" from
bns/theseus.x/vpn-binaries/<platform>/, sha256-verified against the
manifest that ships inside this operator-signed tarball, and cached
under extensions-data/vpn/bin/. Every subsequent launch re-verifies
before spawning; a mismatch redownloads rather than trusts what is on
disk.

Config generator produces a sing-box config from a vless:// URL (the
shape a 3x-UI VLESS+Reality inbound produces), plus a SOCKS5 inbound
on 127.0.0.1:<ephemeral>. api.setSessionProxy points every Theseus
request at that port while the tunnel is up; child.on("exit") clears
it if sing-box dies. Off again clears the proxy back to whatever the
browser had.

Panel is a big on/off toggle with a status pill, a paste-and-save
endpoint box, and an Advanced disclosure with "auto-on at browser
start", "re-download binary" and "clear cache". Any user with a
vless:// URL can flip it on today; the free tier and the Silent Mode
exit inbound are the server-side half, documented under DESIGN.md.

Binary manifest ships with PENDING sha256s until the binaries are
uploaded to Sia — ensureBinary refuses to activate on a platform whose
sha256 is PENDING, so a user cannot flip it on against an unverified
download.
2026-09-21 23:39:32 +02:00
..
addon.json feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI 2026-09-21 23:39:32 +02:00
binary-manifest.json feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI 2026-09-21 23:39:32 +02:00
DESIGN.md feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI 2026-09-21 23:39:32 +02:00
index.js feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI 2026-09-21 23:39:32 +02:00
panel.html feat(theseus/vpn): VPN extension scaffold — sing-box under our own UI 2026-09-21 23:39:32 +02:00