Methodology
This page says how the draft in-house review was done. It is not a rules-of-engagement letter from a firm, and it is not a claim that every path was executed at runtime. The catalog describes the current app; it is not a changelog of prior drafts.
| Field | Value |
|---|---|
| Date | 4 October 2026 |
| Subject | Assembled client starting at whatsup (current tree) |
| Method | Static review of workspace source, schemas, and tests |
| Not done | Independent firm, live pentest, side-channel lab, hosted-header inspection |
What was reviewed
The review started at /whatsup and followed Cargo.toml path dependencies and ApiHandle::dispatch routes. Sibling crates were read only as far as the shell uses them.
| Review unit | Primary evidence |
|---|---|
| Identity | POST /profile/setup, POST /peer/hello, safety_number, Pair now / onion adopt |
| Recipient cascade | api-core cascade_msg, crypto-cascade product / wire (product path; not mls-layer) |
| Password at rest | db-core encryption, SavedConnect, TUI merge_mailbox |
| Git delivery | messages_send / messages_poll, PeerReader, git-web.js |
| Live data channel | whatsup live.rs, webrtc-peer.js, webrtc-core chat / RPC |
| Device pair | device_pair.rs, GET /devices/snapshot, merge apply |
| Tor | tor-core session, glitr-client tor_native / proxy |
| Web / PWA | sw.js, register-sw.js, sessionStorage bridge, CSP meta injected by build-pwa.sh (unsafe-eval for Dioxus), vendored isomorphic-git |
| Local vs Peer authz | require_local, RequestSource::Peer, generated /resources/* |
Threat-model pages were treated as the intent catalog. This folder records whether the current code matches that intent, and where it adds a finding the leftover list already named.
What was not done
| Activity | Why it is absent |
|---|---|
| Independent third-party audit | Not commissioned. This folder does not stand in for one. |
| Dynamic penetration test of a hosted mailbox | No engagement against a live git host, CORS proxy, or STUN operator |
| Side-channel / constant-time lab | Relies on dalek, libcrux, and aes-gcm; no project-wide policy |
| Hosted Content-Security-Policy header inspection | Meta CSP is injected at PWA build time; deploy hosts may still add headers |
| Binary / WASM reproducible-build check | Not claimed on the roadmap |
| Fuzzing the assembled messenger | Library fuzz targets exist; they are not a product program |
| Review of gallery-only ICE / TURN presets | Marked Out of scope unless whatsup ships them |
A green CI job on a handshake library is not a review of send, poll, or merge. The verification report already draws that line.
How findings were written
Each finding has an ID (GLITR-2026-NNN), a severity, a status, a one-line impact, and a surface page. Evidence is a path and a function. Recommended fixes live on Remediation.
Severity is impact on a shipped path, not a CVSS calculator:
| Severity | Used when |
|---|---|
| Critical | Long-term keys or the mailbox password are shared, reused, or written where a same-origin script or a completed pair can take them |
| High | A third party on a default path sees credentials or can weaken a handshake layer |
| Medium | A control is missing, platform-specific, or easy to bypass without immediately handing over long-term keys |
| Low | Hygiene, platform spike, or a correlatable artifact |
| Info | Positive control, or an explicit non-finding |
Confirmed means the code was read in this workspace on the report date. This draft describes the current app only — fixed issues are omitted from the catalog rather than kept as history. Mitigated is reserved if a Confirmed row is later fixed while the section remains an open draft. If a pass weakens a claim, drop or downgrade the row.
Honesty rule
You may cite this folder as a draft in-house implementation review. You may not cite it as an independent audit, a pentest report, or a reason to put sensitive details in the demo.
How this method and the Glitr bar sit next to OWASP ASVS/MASVS, NIST SSDF, and named protocol specs: Standards comparison.
Start of this folder: Security audit. Dated view: Report.
