Skip to main content

Client and storage

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

What the shell writes on the device, what a same-origin script can read, and what the PWA caches. Product page: Devices and storage. Persistence mechanics: Persistence.

Stores​

StoreContentsUnlock
Mailbox (OPFS on web, filesystem on native)Public rows + @encrypted documents (including per-contact git tokens)Connect password → Argon2id → AES-256-GCM
api-core SessionPassword, RSA keys, protocol secrets, remotesProcess lifetime
glitr:connectRemotes, CORS, workdir — not unlock password or git tokenssessionStorage on wasm; session files on native GUI
glitr:device-idOpaque device idlocalStorage / kv
glitr:profilesNative mailbox paths (wasm persist is a no-op)Local files

Legacy plaintext tokens in glitr:connect are wiped on load (for_persist). Tokens stay in the sealed Contact store or session memory.

GLITR-2026-020 — CSP and vendored isomorphic-git​

Info

Production build-pwa.sh injects a Content-Security-Policy meta tag. script-src still allows unsafe-eval / wasm-unsafe-eval for Dioxus bridges. isomorphic-git is served same-origin from assets/vendor/isomorphic-git; the service worker no longer pins esm.sh.

GLITR-2026-006 — document.eval bridges​

Low · Confirmed

glitr-client web_storage.rs talks to storage through Dioxus document::eval. That is why CSP keeps unsafe-eval.

Residual. The bridge is a trusted path inside the origin.

GLITR-2026-012 — escaped chat text​

Info

whatsup-ui message_bubble.rs interpolates message text as a text node.

GLITR-2026-013 — unlock password and tokens not in glitr:connect​

Info

GUI persist_saved and TUI persist_settings write via SavedConnect::for_persist() (empty encryption_password and tokens). Legacy blobs are scrubbed on load. The user retypes unlock and git credentials each session (or uses sealed Contact tokens after unlock).

GLITR-2026-016 — no Web Push​

Info

register-sw.js does not subscribe to Web Push.

Fixes: Remediation. Catalog: Findings.