Client and storage
What the shell writes on the device, what a same-origin script can read, and what the PWA caches. Product page: Devices and storage. Persistence mechanics: Persistence.
Stores
| Store | Contents | Unlock |
|---|---|---|
| Mailbox (OPFS on web, filesystem on native) | Public rows + @encrypted documents (including per-contact git tokens) | Connect password → Argon2id → AES-256-GCM |
api-core Session | Password, RSA keys, protocol secrets, remotes | Process lifetime |
glitr:connect | Remotes, CORS, workdir — not unlock password or git tokens | sessionStorage on wasm; session files on native GUI |
glitr:device-id | Opaque device id | localStorage / kv |
glitr:profiles | Native mailbox paths (wasm persist is a no-op) | Local files |
Legacy plaintext tokens in glitr:connect are wiped on load (for_persist). Tokens stay in the sealed Contact store or session memory.
GLITR-2026-020 — CSP and vendored isomorphic-git
Info
Production build-pwa.sh injects a Content-Security-Policy meta tag. script-src still allows unsafe-eval / wasm-unsafe-eval for Dioxus bridges. isomorphic-git is served same-origin from assets/vendor/isomorphic-git; the service worker no longer pins esm.sh.
GLITR-2026-006 — document.eval bridges
Low · Confirmed
glitr-client web_storage.rs talks to storage through Dioxus document::eval. That is why CSP keeps unsafe-eval.
Residual. The bridge is a trusted path inside the origin.
GLITR-2026-012 — escaped chat text
Info
whatsup-ui message_bubble.rs interpolates message text as a text node.
GLITR-2026-013 — unlock password and tokens not in glitr:connect
Info
GUI persist_saved and TUI persist_settings write via SavedConnect::for_persist() (empty encryption_password and tokens). Legacy blobs are scrubbed on load. The user retypes unlock and git credentials each session (or uses sealed Contact tokens after unlock).
GLITR-2026-016 — no Web Push
Info
register-sw.js does not subscribe to Web Push.
Fixes: Remediation. Catalog: Findings.
