theseus/lib
Local Dev 08beadcf8f Theseus: close the Settings-tab vault leak and the add-on update signer bypass
A preload belongs to the WebContents, not the page: a website loaded into
the Settings tab kept window.cfg and could read every vault password, flip
settings and install extensions without consent. Settings and add-on tabs
now never load web content, and the channels behind settings-preload check
their sender. `navigate` no longer accepts calls from web pages.

Add-on updates trusted any publisherSig, whatever name it carried, even for
bundled add-ons. The trust root is now the installed addon.json (publisher,
or the operator key when there is none); versions must be plain dotted
numbers; a community install can't take over a bundled or foreign id.

Also:
- autofill matches and fills against the live URL, not a stale prov.host
- bns:// forwards the raw request path (..%2F escaped the name's bucket)
- clipboard-read denied, openExternal asks; forged collision choices ignored
- web pages can't window.open file:/chrome:/theseus:; data:/blob: no longer
  go to the search engine; the quick-links panel loses home-preload
- clear-history-on-quit is awaited and removes history.json too
- update helper takes its paths from the environment (non-ASCII profiles)
- electrum poll has a deadline; misses wait at most 2.5 s
- p records go through Tor; add-on proxy credentials are actually used
- whole-folder require-cache bust on add-on version change; failed
  activate() no longer leaks its request filter
- approvals released when the window closes; web-app ids stay on-origin
2026-10-03 09:50:10 +02:00
..
hermes.js Hermes: optional bind to password vault (skip the second mnemonic prompt) 2026-08-19 00:38:52 +02:00
package.json Hermes: wire NIP-17 messaging into Theseus, provision chipnet hermes.bch 2026-08-18 20:14:43 +02:00
publisher-sig.mjs feat: community extensions — publish with a BCDN name, install from Settings, theseus.x catalog 2026-09-20 15:26:30 +02:00
update-helper.cjs Theseus: close the Settings-tab vault leak and the add-on update signer bypass 2026-10-03 09:50:10 +02:00