theseus/lib
Local Dev 3243add70e Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID
Pages of Silent Mode projects can now sign the user in with their Theseus
ID instead of a wallet phrase typed into the page. Theseus writes the
sign-in message itself, takes the origin from the committed top frame, and
signs as a project only on an origin that project's list includes, so a
phishing page cannot get another project's signature and no page can use
the ID key to sign anything else.

- lib/theseus-id.cjs: the policy (first sign-in always asks and lets the
  user pick a private or One ID; Silent Mode projects are silent after
  that while the vault is open; per-site "always"; 10 silent signatures per
  minute per origin), the per-project record encrypted under a key derived
  from the vault, origin-list fetching with a 1 h cache and a 7-day stale
  fallback, and ID moves that send a proof signed by both keys and only
  finish once the project confirms.
- A locked vault is unlocked only for a page the user just clicked or typed
  in: navigator.userActivation alone is true on load for pages opened with
  loadURL, which would let a page pop the vault prompt by itself.
- Settings › Theseus ID: default mode, One ID, automatic sign-in toggle,
  signed-in projects (always, change ID, new ID, revoke) and a recovery key
  behind a fresh PIN / password check.
- TheseusID/registry/projects.json is the first-party list (Hephaestus,
  Sirius, Pithos); it and TheseusID/lib ship as extraResources.
- Token-aware cashaddrs (BNS owners) now decode for owner-signed lists.

Verified on a scratch profile against a local test project whose server
checks signatures with TheseusID/lib/verify.mjs: locked vault on load gives
"locked" with no prompt, first sign-in prompt, silent second sign-in, a
claimed foreign project refused without a prompt, an ID move that keeps the
project's account, and the recovery key behind the confirm prompt.
2026-10-04 20:48:07 +02:00
..
addon-store.cjs Theseus: add-on stores live in memory — no more 16 s "Not Responding" at launch 2026-10-03 16:08:22 +02:00
hermes.js Hermes: optional bind to password vault (skip the second mnemonic prompt) 2026-08-19 00:38:52 +02:00
package.json Hermes: wire NIP-17 messaging into Theseus, provision chipnet hermes.bch 2026-08-18 20:14:43 +02:00
publisher-sig.mjs feat: community extensions — publish with a BCDN name, install from Settings, theseus.x catalog 2026-09-20 15:26:30 +02:00
signin-sites.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00
theseus-id.cjs Theseus ID in Theseus: window.theseusId.signIn and Settings › Theseus ID 2026-10-04 20:48:07 +02:00
tpm-pin.cjs Vault PIN: tie it to the TPM and never store it unsealed 2026-10-04 03:42:02 +02:00
update-helper.cjs Theseus: close the Settings-tab vault leak and the add-on update signer bypass 2026-10-03 09:50:10 +02:00
vault-pin.cjs Vault: PIN setup steps, 6-8 digit PINs, save and offer logins, keep sign-ins 2026-10-04 20:23:43 +02:00