theseus/lib
Local Dev de7735feb3 Theseus: quick-unlock PIN for the vault, shared with extensions
The vault re-locks on every restart and only the master password opened
it, so every extension that needs it (Aegis, now Pithos) either asked for
the master password itself or grew its own PIN. Theseus now owns one:

- Settings > Passwords sets, changes or removes a 6-digit PIN. The PIN
  wraps the master password (PBKDF2-SHA256, 600k iterations, AES-256-GCM)
  and the result is sealed with the OS keystore (safeStorage: DPAPI /
  Keychain / libsecret), so a copied vault-pin.json cannot be brute-forced
  elsewhere. Every unlock still ends at the master password.
- Three wrong PINs in a row require the master password. The strike count
  lives in the same file, so a restart does not reset it; a successful
  master-password unlock does. A PIN whose password no longer opens the
  vault (password changed) is dropped.
- unlock.html is Theseus's own prompt, over the whole window: PIN pad, or
  the master password. Extensions call api.vault.requestUnlock({ reason })
  (vault-derive capability) and get { ok } back; what the user typed never
  reaches them. Settings' locked screen offers "Unlock with PIN" through
  the same prompt.
2026-10-03 20:33:26 +02:00
..
addon-store.cjs Theseus: add-on stores live in memory — no more 16 s "Not Responding" at launch 2026-10-03 16:08:22 +02:00
hermes.js Hermes: optional bind to password vault (skip the second mnemonic prompt) 2026-08-19 00:38:52 +02:00
package.json Hermes: wire NIP-17 messaging into Theseus, provision chipnet hermes.bch 2026-08-18 20:14:43 +02:00
publisher-sig.mjs feat: community extensions — publish with a BCDN name, install from Settings, theseus.x catalog 2026-09-20 15:26:30 +02:00
update-helper.cjs Theseus: close the Settings-tab vault leak and the add-on update signer bypass 2026-10-03 09:50:10 +02:00
vault-pin.cjs Theseus: quick-unlock PIN for the vault, shared with extensions 2026-10-03 20:33:26 +02:00