Files
amethyst/nappletHost
Vitor PamplonaandClaude Opus 5.5 b6a72d6754 feat(browser): readable load-error page, Try without Tor, onion guard
The full-screen browser showed the WebView's built-in error page: an
Android robot over raw text, unreadable in dark mode, no retry. Over Tor
every failure reads net::ERR_SOCKS_CONNECTION_FAILED, so a misspelled
address looked like a proxy problem.

- PageLoadFailure (commons) groups main-frame errors by what the user
  can do: not found, unreachable, Tor not running, timed out, offline,
  certificate, redirect loop, cleartext blocked, onion without Tor.
  ERR_ABORTED shows nothing.
- PageLoadError (commonsUI) covers the built-in page in the app theme
  with the cause in words, the raw code in small print, and Try again.
  It stays up through a retry, showing a spinner, and leaves only when a
  page actually paints, so the robot page never flashes. A dead name
  over Tor fails again within ~1ms, so the spinner is held for 700ms.
- Try without Tor: offered only for unreachable/timed-out failures on a
  page that chose Tor, never for an onion, and only when no other
  surface also claims Tor (the route is shared and Tor wins). It flips
  the same remembered per-site switch as the pill, and says the site
  will see the user's IP.
- Onion guard: a main-frame link to a .onion from a page with Tor off
  used to leave on the open web. It now switches the page to Tor first,
  as a typed onion address already did, and the window's first load is
  checked the same way. With no Tor available it shows "This site needs
  Tor" instead of "doesn't exist".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 11:45:42 -04:00
..