An extension was require()d into the browser's main process. Its declared
capabilities bound only an honest one: there it could load electron, hook
the unlock prompt for the master password, read the vault files and the
wallet's store, call the OS keystore, and reach every tab.
Extensions that do not ship with Theseus now run in a separate process, in
Node mode under Node's permission model: read access to their own folder,
write access to a scratch folder, no child processes, no workers, no native
add-ons, no Electron, and none of the browser's memory. They reach the
browser only through an allow-listed message API that calls the same
functions, with the same capability checks, as before. Built-in add-ons are
unchanged and stay in-process.
For extension authors: host calls return promises (tabs.active included);
api.require / api.import are gone, so dependencies must be bundled;
registerRequestFilter and registerSiteRoute are not offered; the store is
handed over at start and written through, so storage.get stays synchronous.
An approval raised while handling a page message is still tied to that
page's tab. If the sandbox cannot start, the extension does not run.
The channel is JSON with tagged bytes: the binary IPC format depends on the
exact V8 build on both ends.
The browser — the consumer face of the stack. Native .bch support with the
resolver built in, so a user installs one app instead of modifying their
operating system. Named for the thread through the labyrinth: the chain is the
thread.
Scope
Electron shell (Chromium engine, no forking): tabs, address bar, history.
In-process .bch resolution — no system daemon, no NRPT, no OS
trust-store changes; reuses bns.js from the BNS repo as a library.
Record handling: h render, ip connect, p/s3 via in-app gateway,
u redirect.
TLS via cert-verify hook (Electron setCertificateVerifyProc) against the
BNS root / on-chain tls fingerprints — no OS store touched.
Provenance indicator: shows whether a page came from the chain / Sia / a
direct server, with NFT category and record type — the decentralized padlock.
Status: not started
Build it in its own session/repo. The ready-to-paste brief is
BROWSER-PROMPT.md (a reference copy in this folder; canonical source is
D:\Dev\NameCoin\BROWSER-PROMPT.md — if they diverge, NameCoin wins). It points
here and reuses the resolver core. theseus.bch is registered and should
eventually serve the browser's own homepage over the protocol it implements.