theseus/lib
Local Dev 9d6d8c3cc5 Theseus: one PIN — the vault PIN, offered to Aegis through api.vault.pin
Theseus and Aegis each wrapped the same master password under their
own PIN: two offline targets, two guess budgets, and two PINs to keep
in step. The vault PIN is now the only one. Built-in add-ons get
api.vault.pin {status, unlock, set, clear} (advertised by
features.vaultPin); unlock(pin) opens the vault in main and answers
only { ok } or why not, so the master password stays in main.

The policy is the one Aegis's PIN screens describe: five wrong PINs
lock the PIN for 15 minutes, every further wrong one locks it again,
and the master password always works. The unlock prompt uses the same
PIN pad and the same wording as Aegis, and Settings says so.
2026-10-04 04:15:15 +02:00
..
addon-store.cjs Theseus: add-on stores live in memory — no more 16 s "Not Responding" at launch 2026-10-03 16:08:22 +02:00
hermes.js Hermes: optional bind to password vault (skip the second mnemonic prompt) 2026-08-19 00:38:52 +02:00
package.json
publisher-sig.mjs feat: community extensions — publish with a BCDN name, install from Settings, theseus.x catalog 2026-09-20 15:26:30 +02:00
tpm-pin.cjs Vault PIN: tie it to the TPM and never store it unsealed 2026-10-04 03:42:02 +02:00
update-helper.cjs Theseus: close the Settings-tab vault leak and the add-on update signer bypass 2026-10-03 09:50:10 +02:00
vault-pin.cjs Theseus: one PIN — the vault PIN, offered to Aegis through api.vault.pin 2026-10-04 04:15:15 +02:00