theseus/bundled-addons/vpn
Local Dev e31c685550 vpn: lease a credential from the key-issuer instead of expecting one in the catalogue
Found by driving the add-on in a real Theseus rather than reasoning
about it. turnOn() failed with "Silent Mode · 1 is not yet configured
(ready)" — resolveEndpoint required the catalogue entry to carry a
vless URL, but the gateway catalogue deliberately ships none, because a
vless URL is the credential and that endpoint is public. The add-on
predates the key-issuer and was never taught to ask for a lease.

It now POSTs to /api/vpn/session for any ready exit that has no URL of
its own, and caches the lease under its serverId until a minute before
expiry. Baked-in and subscription entries still use their own URL and
never hit the network.
2026-09-27 20:45:47 +02:00
..
addon.json vpn 0.1.3 → 0.1.4: an https:// paste imports as a subscription 2026-09-23 23:21:51 +02:00
binary-manifest.json vpn 0.1.0 → 0.1.1: pin sing-box 1.14.1 sha256s 2026-09-22 00:09:18 +02:00
DESIGN.md docs(vpn): runbook for the key-issuer, and the gap it leaves open 2026-09-27 19:06:58 +02:00
index.js vpn: lease a credential from the key-issuer instead of expecting one in the catalogue 2026-09-27 20:45:47 +02:00
panel.html vpn 0.1.3 → 0.1.4: an https:// paste imports as a subscription 2026-09-23 23:21:51 +02:00
server-list.json vpn 0.1.3 → 0.1.4: an https:// paste imports as a subscription 2026-09-23 23:21:51 +02:00