Git mailbox
Delivery that is not a live data channel: push and poll through a git remote the user configured. Product page: Git mailbox. How-it-works: Git mailbox.
api-core is not a network mailbox server. The intermediary is the git host — and, on web, an optional CORS proxy the user configures.
What lands on the remote
Send writes an OutboundMessage whose body is cascade ciphertext (messages_send), then push_local. Poll clones or fetches the peer tip and ingest decrypts rows addressed to the local profile.
Sealed local types (@encrypted in messaging.graphql) are Argon2id then AES-GCM. They are not what the host must see. Intentionally readable on the remote include profile-public (keys and protocolBundles), outbound ciphertext files, signaling ciphertext, devices, and read receipts.
Committer identity on push is db / db@local (db-core git.rs).
CORS on web
DEFAULT_CORS is empty. git-web.js remoteExtras sets corsProxy only when the user supplied a non-empty value. Connect / attach copy warns that a public proxy sees git URLs and credentials. Cross-origin remotes without a proxy fail CORS in the browser; native / linked-device / self-hosted proxy remain the supported paths.
GLITR-2026-007 — fixed committer
Low · Confirmed
Every push we traced uses Signature::new("db", "db@local"). Hosts that show committer identity will correlate Glitr mailboxes with each other. This is not a confidentiality break of message bodies.
GLITR-2026-008 — host metadata
Accepted
A git host sees commit times, ref updates, object sizes, collaborator or token access, and the client IP (or the CORS / Tor exit IP). recipientId / senderId on coordination rows are readable by design so a peer can work without your password.
Already the product leftover. Anonymity is a non-goal. Listed for the catalog.
Tokens and remotes
GUI and TUI persist SavedConnect through for_persist(), which clears unlock password and git tokens (glitr-client connect.rs). Legacy plaintext tokens are wiped on load (GLITR-2026-013). Peer-clone credentials stay in the sealed Contact mailbox or session memory after unlock.
allow_git_url on the browser↔native proxy uses parsed host equality (not a git-host finding).
Force-push is an explicit UX when histories diverge. That is a social / availability risk on a shared remote, not a cascade bug.
Prekeys on a mailbox
Git is not a Signal prekey server. The product publishes an OTPK pool and can rotate, but a remote tip cannot atomically burn a one-time prekey for every fetcher. See Cryptography and Residual risk.
Fixes: Remediation. Catalog: Findings.
