Desk
A ledger, not a wallet.
Field notes and smoke marks live in Postgres. The gate only protects this editor. It does not protect keys, and notes are public on the changelog.
Read-only catalog · configure DESK_PASSWORD to open the desk.
Desk editing is unavailable. Configure both DATABASE_URL and DESK_PASSWORD; public pages remain available in read-only mode.
Add a field note
Recent notes
- DOCS
The deployed dossier is itself a stale clock
thruwallet.vercel.app — the developer website linked from the Chrome Web Store listing — still serves the pre-merge build of this site as of 2026-10-04: alphanet framing, listing 1.2.0, offered by PWNX0, contract v12, and the auto-lock entry that calls the timer a fixed-period alarm. A reader who clicks Website from the store lands on a page that contradicts the listing above it. The corrected dossier exists only on the open website branch until it merges and redeploys.
4 Oct 2026, 19:30 UTC
- DOCS
Merging the v16 chain re-opens the gap it closes
The chain rewrites STATUS_AND_ROADMAP.md to describe v16, which fixes the third clock. It does not bump the package number. Merge it as-is and main is contract v16 under the string 1.4.1, while the 1.4.1 in the store is contract v15 — one version string, two builds. Flagged upstream; the fix is a bump in the same change.
4 Oct 2026, 18:20 UTC
- RELEASE
Contract v16 is written and removes two methods
Read from the heads of #17 (7883219) and #18 (97276a7) on 2026-10-04: CONTRACT_VERSION 16 with 81 methods, down from 83, retiring tx.send and token.transfer now that every shipped caller uses the checked methods. 19 source files change and a storage-migrations suite joins the gate. It is the first contract step that subtracts.
4 Oct 2026, 18:15 UTC
- SMOKE
Smoke count reconciled: 36 rows, 95 checks, 0 ticked
The extension repo counts 95 checkbox cells; this site counted 36 rows. Same file, same tree, same answer — most rows carry more than one cell because popup and side panel are checked separately, narrow and wide. Both numbers now appear with their units so neither reads as a correction of the other.
4 Oct 2026, 18:10 UTC
- DOCS
Offered by PWNX0 is gone from the listing page
The Details block no longer carries a publisher row; it now shows a developer website link to thruwallet.vercel.app and the contact email. This site stopped asserting a publisher name rather than quoting a row that is no longer there. extension.md still records the last listing sync as 2026-09-30, which is wrong by five days.
4 Oct 2026, 14:55 UTC
- SMOKE
Published is not verified: 0 of 36
docs/MANUAL_SMOKE_CHECKLIST.md has 36 rows and none are ticked. The package went merge to store in a day on 20 automated suites. Until someone installs the published package and walks the list, the people installing it are the first browser run — duplicate detection across the pending window, notification delivery, and the dark-mode surfaces most of all.
4 Oct 2026, 14:50 UTC
- SECURITY
The auto-lock contradiction closed from both sides
The 2026-09-26 note said the source wins until a build changes the behavior and the listing together. That is what happened: 1.4.1 locks on measured inactivity and the listing still says inactivity lock, so for the first time the sentence and the code agree. Keeping the old note on the record — it described the package that was installable at the time.
4 Oct 2026, 14:45 UTC
- RELEASE
1.4.1 is live — the listing finally matches the source
Live page read 2026-10-04: version 1.4.1, updated October 4, 272 KiB, five screenshots, betanet description naming the token drawer, verified custom tokens, desktop notifications, and Ctrl+L. The store and main at cee006e are the same build. The 1.2.0 alphanet package is gone from the install path.
4 Oct 2026, 14:40 UTC
- DOCS
The merge did not fix the status doc
docs/STATUS_AND_ROADMAP.md on main at cee006e still opens with contract v12 and 81 methods audited at 4aa55ba on 2026-09-26, three contract steps behind the manifest sitting next to it. The site now renders it as its own track on /status instead of treating it as the baseline.
3 Oct 2026, 14:15 UTC
- RELEASE
1.4.0 was never published, so the release is 1.4.1
The package submitted this morning did not reach the public page, and the release notes say so outright. Uploading the 1.4.1 package is still a human step, recorded as pending in extension.md, which is why the store track on this site did not move when the source track did.
3 Oct 2026, 14:10 UTC
- RELEASE
PR #16 merged as cee006e and released as v1.4.1
Merged 13:56 UTC on 2026-10-03, tagged v1.4.1 thirteen seconds later. Main is contract v15, 83 methods, @thru 0.4.1, and a CSP whose only connect-src is the betanet RPC. Store listing re-read the same day: 1.2.0, 209 KiB, September 23, alphanet copy. Released is not installed.
3 Oct 2026, 14:05 UTC
- NOTE
PR #16 head moved to 9086b22
Four commits after the audited tip: @thru/sdk and @thru/programs synced to 0.4.1, a warm header gradient with frosted pill borders, a fixed-width account pill with 6...6 address truncation, and a balance-hero refresh hover fix. Contract stays v15 with 83 methods and the manifest stays 1.4.0.
3 Oct 2026, 09:45 UTC
- RELEASE
1.4.0 is in Chrome review, not published
The betanet package was submitted with the rewritten description and the notifications justification. The live listing page still reports 1.2.0 from 2026-09-23, which is what review looks like from outside. This site flips site.listing only when the public page moves.
3 Oct 2026, 09:30 UTC
- DOCS
The extension's own status doc is behind its code
docs/STATUS_AND_ROADMAP.md on the pending branch still opens with contract v12 and 81 methods at 4aa55ba, while src/shared/contract/manifest.js exports CONTRACT_VERSION 15 with 83 methods. This site quotes the code for pending facts and the status doc for the audited baseline, and labels which is which.
2 Oct 2026, 19:10 UTC
- SECURITY
Auto-lock: the source caught up with the listing
The pending build stamps lastActivityAt on every API request and locks on measured idleness, and background sync no longer refreshes the clock. The 2026-09-26 note stays on the record: it described the shipped package, which still runs the fixed-period alarm.
2 Oct 2026, 18:55 UTC
- RELEASE
Betanet build is reviewed, not published
PR #16 at 1338380 carries package 1.4.0: betanet RPC, @thru 0.4.0 managed program addresses, contract v15 with 83 methods, a token drawer, custom tokens verified on-chain, and desktop notifications. It is mergeable with CI green. Until it merges and a new package is submitted, Chrome still installs 1.2.0.
2 Oct 2026, 18:40 UTC
- SECURITY
Auto-lock wording disagrees with the source
The Chrome Web Store overview calls the 15-minute lock an inactivity lock. The extension repository describes a fixed-period alarm. The source wins until a build changes the behavior and the listing together.
26 Sept 2026, 12:10 UTC
- DOCS
Do not collapse the listing into contract v12
The store package is dated 2026-09-23. The status baseline audited on 2026-09-26 describes contract v12 and 81 methods at commit 4aa55ba. Say which one you mean.
26 Sept 2026, 11:30 UTC
- RELEASE
Chrome Web Store is the public install path
Packaged installs should use the listing: https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok — extension id ocahgpmgfeapjnceaknkikanjikhjgok, version 1.2.0, offered by PWNX0. Source installs remain for people who need to audit or rebuild dist/.
23 Sept 2026, 16:00 UTC
Smoke marks
Mark a row pass only after a real Chrome run. Saving here does not change the extension.