On a host with api.vault.pin, Aegis no longer keeps a PIN of its own: its lock-screen, reveal and transaction pads send the digits to the Theseus vault PIN, which is checked in main against the one strike counter Settings, the unlock prompt and Pithos also use. The vault is opened there, and the panel receives a single-use proof (two minutes) where it used to receive the master password; vaultUnlock, revealSecret and pinGateSatisfied accept it, still bound to the request it was entered for. The master password no longer passes through Aegis or its panel for a PIN entry. An existing Aegis PIN moves to the vault PIN on its first correct entry. If Theseus already has a different PIN, the user is asked once which one to keep. Setting and removing the PIN act on the vault PIN, and Settings says that it is shared. Hosts without the API (Theseus 0.3.74-0.3.76) keep Aegis's own PIN exactly as before. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||