Theseus Navigator — Silent Mode's Electron browser with the Ariadne resolver built in.
PIN - The PIN blob wraps the vault master password under six digits and sat in plain add-on storage, so a copy of the profile reduced the master password to a million offline PBKDF2 guesses. It is sealed with the OS keystore before it is stored; a plain blob from an older build is sealed on first read. New blobs use 600k iterations. - "Ask for PIN on every transaction" was decided by the host and enforced by nobody: `send` never checked it and dapp transactions had no PIN step. A gate is now cleared only by the master password the PIN unwraps, verified against the vault, which also opens a single-use transaction clearance. Panel sends consume one; dapp transactions ask the open panel and wait. Spending and signing - Consolidate emptied wallets on the panel's confirmation alone, defaulted to every sibling when no list was sent, and swept into whatever was selected at click time. It now needs explicit sources and the previewed destination, and shows the whole batch on the host overlay. - Typed data for a chain other than the connected one is refused. Permit and Permit2 signatures name the spender, tokens, amounts and expiry, and an unlimited one gets the danger action. Previews are no longer cut at 600/400 characters without saying so. - eth.rpc relayed any eth_* call for sites that never connected. - The WizardConnect overlay lists the tokens being spent and received. Send form - "0,5" was read as 5: the parser deleted commas. Amounts are parsed exactly; a decimal comma is a decimal, ambiguous or non-numeric input is refused, extra decimals are an error instead of being dropped. - Send submits the request the summary was computed for, never a fresh read of the form, and stays off while a plan is pending or stale. - Switching wallet resets the form instead of leaving a live button on the previous wallet's plan. - The unlock field kept the master password after unlocking; the PIN pad kept its digits and kept counting keystrokes typed elsewhere as PIN attempts; an idle lock left a revealed key or seed form on screen. - Enter confirmed a dialog even with focus on Cancel. |
||
|---|---|---|
| addon-build/docx-editor | ||
| bundled-addons | ||
| dev | ||
| docs | ||
| engine-icons | ||
| lib | ||
| nsis | ||
| scripts | ||
| snapshots | ||
| addon-inject-preload.js | ||
| addon-tab-preload.js | ||
| addon-update-pubkeys.js | ||
| addon-updater.js | ||
| addons-host.js | ||
| address-picker-preload.js | ||
| address-picker.html | ||
| approval-preload.js | ||
| approval.html | ||
| auth-prompt-preload.js | ||
| auth-prompt.html | ||
| bcnr-origin.js | ||
| bcnr-preload.js | ||
| bns-indexer.js | ||
| BROWSER-PROMPT.md | ||
| chrome.html | ||
| collision-preload.js | ||
| collision.html | ||
| DESIGN-bns-indexer-service.md | ||
| DESIGN-integrated-wallet.md | ||
| DESIGN-password-manager.md | ||
| DESIGN-wallet-multi-account-amendment.md | ||
| downloads-preload.js | ||
| downloads.html | ||
| engine-picker-preload.js | ||
| engine-picker.html | ||
| error-preload.js | ||
| error.html | ||
| GOTCHAS.md | ||
| home-preload.js | ||
| home.html | ||
| js-dialog-preload.js | ||
| js-dialog.html | ||
| lang-picker-preload.js | ||
| lang-picker.html | ||
| LICENSE | ||
| link-status-preload.js | ||
| link-status.html | ||
| main.js | ||
| messages-preload.js | ||
| messages.html | ||
| package-lock.json | ||
| package.json | ||
| PACKAGING-PROMPT.md | ||
| PENDING.md | ||
| popover-preload.js | ||
| popover.html | ||
| preload.js | ||
| pw-fill-preload.js | ||
| pw-fill.html | ||
| quicklinks-preload.js | ||
| quicklinks.html | ||
| README.md | ||
| RELEASE-HANDOFF.md | ||
| ROADMAP-identity-wallet.md | ||
| SESSION-PROMPT-identity-wallet.md | ||
| settings-preload.js | ||
| settings.html | ||
| sidebar-preload.js | ||
| test-installer.wsb | ||
| THIRD-PARTY-NOTICES.md | ||
| TRADEMARKS.md | ||
| unlock-preload.js | ||
| unlock.html | ||
| webapps.js | ||
Theseus Navigator
The browser — the consumer face of the stack. Native .bch support with the
resolver built in, so a user installs one app instead of modifying their
operating system. Named for the thread through the labyrinth: the chain is the
thread.
Scope
- Electron shell (Chromium engine, no forking): tabs, address bar, history.
- In-process
.bchresolution — no system daemon, no NRPT, no OS trust-store changes; reusesbns.jsfrom the BNS repo as a library. - Record handling:
hrender,ipconnect,p/s3via in-app gateway,uredirect. - TLS via cert-verify hook (Electron
setCertificateVerifyProc) against the BNS root / on-chaintlsfingerprints — no OS store touched. - Provenance indicator: shows whether a page came from the chain / Sia / a direct server, with NFT category and record type — the decentralized padlock.
Status: not started
Build it in its own session/repo. The ready-to-paste brief is
BROWSER-PROMPT.md (a reference copy in this folder; canonical source is
D:\Dev\NameCoin\BROWSER-PROMPT.md — if they diverge, NameCoin wins). It points
here and reuses the resolver core. theseus.bch is registered and should
eventually serve the browser's own homepage over the protocol it implements.
Roadmap
BUILD-ROADMAP.md Stage 5.