Live and WebRTC
Online path: SDP + ICE, then a DTLS data channel, then application frames. Product page: Live links. Shell: whatsup live.rs, assets/webrtc-peer.js.
There is no Glitr signaling server. Git-brokered offer/answer rows are cascaded to the contact. When a contact has tor and webrtc enabled and a peer onion is known, auto git-signaling offers are skipped so onion can carry live setup faster. Pair-now invites remain OOB.
GLITR-2026-003 — ICE/media may still be direct
Medium · Confirmed
Per-contact STUN dropdown and force-STUN (host-candidate filter) are on contact details. Default STUN remains Google’s public server when unset. Onion-preferred signaling does not put ICE/media on Tor. Without TURN, force-STUN cannot force a true relay path.
Residual. Documented on the contact-details prefs copy. Anonymity for live media is a non-goal.
GLITR-2026-011 — peer RPC ciphertext
Accepted
RequestSource::Peer may list non-@encrypted outbound / profile-public / receipts. Peer list/get redacts plaintext body on outbound rows. Peers retrieve ciphertext they can decrypt for themselves — intentional mailbox semantics on the live link.
GLITR-2026-004 — Linux WebKit permissions
Low · Confirmed
whatsup linux_webrtc.rs auto-allows camera / mic / device-info requests.
GLITR-2026-017 — gallery TURN
Out of scope
Gallery OpenRelay TURN is not the Glitr / whatsup default ICE set.
GLITR-2026-018 — per-contact transport prefs
Info
Contact fields gitEnabled / torEnabled / webrtcEnabled (default on), stunUrl, forceStun. UI on contact details. allow_git_url uses parsed host equality (not prefix match).
Tor split residual: GLITR-2026-003 (same ICE residual).
Fixes: Remediation. Catalog: Findings.
