Skip to content

Desk

A ledger, not a wallet.

Field notes and smoke marks live in Postgres. The gate only protects this editor. It does not protect keys, and notes are public on the changelog.

Read-only catalog · configure DESK_PASSWORD to open the desk.

Desk editing is unavailable. Configure both DATABASE_URL and DESK_PASSWORD; public pages remain available in read-only mode.

Add a field note

Recent notes

  • DOCS

    The deployed dossier is itself a stale clock

    thruwallet.vercel.app — the developer website linked from the Chrome Web Store listing — still serves the pre-merge build of this site as of 2026-10-04: alphanet framing, listing 1.2.0, offered by PWNX0, contract v12, and the auto-lock entry that calls the timer a fixed-period alarm. A reader who clicks Website from the store lands on a page that contradicts the listing above it. The corrected dossier exists only on the open website branch until it merges and redeploys.

    4 Oct 2026, 19:30 UTC

  • DOCS

    Merging the v16 chain re-opens the gap it closes

    The chain rewrites STATUS_AND_ROADMAP.md to describe v16, which fixes the third clock. It does not bump the package number. Merge it as-is and main is contract v16 under the string 1.4.1, while the 1.4.1 in the store is contract v15 — one version string, two builds. Flagged upstream; the fix is a bump in the same change.

    4 Oct 2026, 18:20 UTC

  • RELEASE

    Contract v16 is written and removes two methods

    Read from the heads of #17 (7883219) and #18 (97276a7) on 2026-10-04: CONTRACT_VERSION 16 with 81 methods, down from 83, retiring tx.send and token.transfer now that every shipped caller uses the checked methods. 19 source files change and a storage-migrations suite joins the gate. It is the first contract step that subtracts.

    4 Oct 2026, 18:15 UTC

  • SMOKE

    Smoke count reconciled: 36 rows, 95 checks, 0 ticked

    The extension repo counts 95 checkbox cells; this site counted 36 rows. Same file, same tree, same answer — most rows carry more than one cell because popup and side panel are checked separately, narrow and wide. Both numbers now appear with their units so neither reads as a correction of the other.

    4 Oct 2026, 18:10 UTC

  • DOCS

    Offered by PWNX0 is gone from the listing page

    The Details block no longer carries a publisher row; it now shows a developer website link to thruwallet.vercel.app and the contact email. This site stopped asserting a publisher name rather than quoting a row that is no longer there. extension.md still records the last listing sync as 2026-09-30, which is wrong by five days.

    4 Oct 2026, 14:55 UTC

  • SMOKE

    Published is not verified: 0 of 36

    docs/MANUAL_SMOKE_CHECKLIST.md has 36 rows and none are ticked. The package went merge to store in a day on 20 automated suites. Until someone installs the published package and walks the list, the people installing it are the first browser run — duplicate detection across the pending window, notification delivery, and the dark-mode surfaces most of all.

    4 Oct 2026, 14:50 UTC

  • SECURITY

    The auto-lock contradiction closed from both sides

    The 2026-09-26 note said the source wins until a build changes the behavior and the listing together. That is what happened: 1.4.1 locks on measured inactivity and the listing still says inactivity lock, so for the first time the sentence and the code agree. Keeping the old note on the record — it described the package that was installable at the time.

    4 Oct 2026, 14:45 UTC

  • RELEASE

    1.4.1 is live — the listing finally matches the source

    Live page read 2026-10-04: version 1.4.1, updated October 4, 272 KiB, five screenshots, betanet description naming the token drawer, verified custom tokens, desktop notifications, and Ctrl+L. The store and main at cee006e are the same build. The 1.2.0 alphanet package is gone from the install path.

    4 Oct 2026, 14:40 UTC

  • DOCS

    The merge did not fix the status doc

    docs/STATUS_AND_ROADMAP.md on main at cee006e still opens with contract v12 and 81 methods audited at 4aa55ba on 2026-09-26, three contract steps behind the manifest sitting next to it. The site now renders it as its own track on /status instead of treating it as the baseline.

    3 Oct 2026, 14:15 UTC

  • RELEASE

    1.4.0 was never published, so the release is 1.4.1

    The package submitted this morning did not reach the public page, and the release notes say so outright. Uploading the 1.4.1 package is still a human step, recorded as pending in extension.md, which is why the store track on this site did not move when the source track did.

    3 Oct 2026, 14:10 UTC

  • RELEASE

    PR #16 merged as cee006e and released as v1.4.1

    Merged 13:56 UTC on 2026-10-03, tagged v1.4.1 thirteen seconds later. Main is contract v15, 83 methods, @thru 0.4.1, and a CSP whose only connect-src is the betanet RPC. Store listing re-read the same day: 1.2.0, 209 KiB, September 23, alphanet copy. Released is not installed.

    3 Oct 2026, 14:05 UTC

  • NOTE

    PR #16 head moved to 9086b22

    Four commits after the audited tip: @thru/sdk and @thru/programs synced to 0.4.1, a warm header gradient with frosted pill borders, a fixed-width account pill with 6...6 address truncation, and a balance-hero refresh hover fix. Contract stays v15 with 83 methods and the manifest stays 1.4.0.

    3 Oct 2026, 09:45 UTC

  • RELEASE

    1.4.0 is in Chrome review, not published

    The betanet package was submitted with the rewritten description and the notifications justification. The live listing page still reports 1.2.0 from 2026-09-23, which is what review looks like from outside. This site flips site.listing only when the public page moves.

    3 Oct 2026, 09:30 UTC

  • DOCS

    The extension's own status doc is behind its code

    docs/STATUS_AND_ROADMAP.md on the pending branch still opens with contract v12 and 81 methods at 4aa55ba, while src/shared/contract/manifest.js exports CONTRACT_VERSION 15 with 83 methods. This site quotes the code for pending facts and the status doc for the audited baseline, and labels which is which.

    2 Oct 2026, 19:10 UTC

  • SECURITY

    Auto-lock: the source caught up with the listing

    The pending build stamps lastActivityAt on every API request and locks on measured idleness, and background sync no longer refreshes the clock. The 2026-09-26 note stays on the record: it described the shipped package, which still runs the fixed-period alarm.

    2 Oct 2026, 18:55 UTC

  • RELEASE

    Betanet build is reviewed, not published

    PR #16 at 1338380 carries package 1.4.0: betanet RPC, @thru 0.4.0 managed program addresses, contract v15 with 83 methods, a token drawer, custom tokens verified on-chain, and desktop notifications. It is mergeable with CI green. Until it merges and a new package is submitted, Chrome still installs 1.2.0.

    2 Oct 2026, 18:40 UTC

  • SECURITY

    Auto-lock wording disagrees with the source

    The Chrome Web Store overview calls the 15-minute lock an inactivity lock. The extension repository describes a fixed-period alarm. The source wins until a build changes the behavior and the listing together.

    26 Sept 2026, 12:10 UTC

  • DOCS

    Do not collapse the listing into contract v12

    The store package is dated 2026-09-23. The status baseline audited on 2026-09-26 describes contract v12 and 81 methods at commit 4aa55ba. Say which one you mean.

    26 Sept 2026, 11:30 UTC

  • RELEASE

    Chrome Web Store is the public install path

    Packaged installs should use the listing: https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok — extension id ocahgpmgfeapjnceaknkikanjikhjgok, version 1.2.0, offered by PWNX0. Source installs remain for people who need to audit or rebuild dist/.

    23 Sept 2026, 16:00 UTC

Smoke marks

Mark a row pass only after a real Chrome run. Saving here does not change the extension.

Popup layout, narrow

Toolbar popup at the shipped 400px width. No clipped actions, balances, or review rows.

Side panel, wide

User-resized side panel. Body caps to the available width. Do not assume a 408px layout.

Side panel opens from Settings

Settings > Window > Open side panel calls chrome.sidePanel.open from a user gesture.

Toolbar still opens the popup

Nothing calls setPanelBehavior. The toolbar icon must keep opening the popup.

Popup and panel mutual exclusion

Opening one context closes the other. The close listener registers before asynchronous boot.

Password dialog focus trap

Tab wraps inside the dialog, Escape cancels, and focus returns to the control that opened it.

QR canvas paints

Receive route canvas actually draws. A shim cannot prove this.

Clipboard prompt

Copy address surfaces the browser permission prompt and does not write secrets anywhere else.

MV3 worker eviction

Reload the extension, not only the popup. Confirm restart, timeouts, and side-panel mode restore.

Lock on refresh

Check reported session-storage behavior in the target browser. A Node harness cannot certify it.

Token drawer opens from the balance box

Shipped in 1.4.1, unverified in a browser. Click, Enter, and Space on the balance box all slide the drawer up. Search filters it. No inline token ledger returns.

Add a custom token by contract address

Shipped in 1.4.1, unverified in a browser. The chain supplies symbol and decimals through token.readMint. A bad address fails visibly instead of adding a token with typed metadata.

Desktop notification on confirm and fail

Shipped in 1.4.1, unverified in a browser. Chrome must actually post it, the Settings toggle must suppress it, and the body must carry no amount, address, or signature.

Auto-lock measures real idleness

Shipped in 1.4.1, unverified in a browser. Leave the wallet idle past the window and confirm it locks; keep using it and confirm it does not. Background sync must not count as activity.

Repeat transfer is caught before signing

Shipped in 1.4.1, contract v15. Send the same amount to the same recipient twice inside 30 seconds and confirm the second one requires an explicit confirmation.