Git mailbox
A git-URL contact’s reliable path is push, fetch, and poll. You never write into someone else’s repository. You write outbound on yours. They keep a fetch-only clone and ingest what is addressed to them.
This page is that path as a threat surface. The user story is Git as your mailbox. File shapes are on Data structures. Host how-to: Using GitHub, GitLab, and Codeberg.
There is no Glitr account server. Poll authentication is local session middleware on in-process api-core.
What the host can read
| On the remote | What it is | Host sees |
|---|---|---|
profile-public.json | RSA public key and protocol bundles | Documented — needed so a contact can encrypt the first message |
outbound/ | Cascade (or hybrid) ciphertext addressed to a recipientId | Ciphertext, sizes, dates, who it is for |
readreceipts/ | “This outbound id was read” | Documented — ticks need a readable row |
signaling/ | One file per contact while you are connected | The file is visible; inner SDP is cascaded to the contact |
devices/ | Local device rows, including this device’s onion | Ordinary JSON. A clone can read it. A peer poll does not fetch it |
Sealed folders (contacts, inbox, sent, groups, protocol-sessions, file-transfers, profile-secrets) | Password envelopes | Envelope bytes, not the JSON |
Sealing is not end-to-end messaging. Your connect password opens your documents. Peers never open those folders. They decrypt outbound and signaling with their keys.
What the host can infer anyway
Even with bodies cascaded:
- That you have a mailbox repository.
- How often it changes, and roughly how large it is.
- Who you gave read access to (collaborators, deploy keys, tokens).
- IP addresses on push and fetch (normal git hosting logs).
- On the web, a user-supplied CORS proxy (empty by default) sits on the path and sees git HTTP. Desktop and TUI skip that proxy for local-only; they can send git HTTPS through Tor SOCKS instead.
Threat model in one line: protect message content from the host; do not expect the host to be unaware that you chat.
Intentionally readable
If everything were sealed with only your password, nobody else could start a conversation.
- Public profile — Pending → Active is a fetch of this file.
- Outbound ciphertext — mail for them, not a document for the host.
- Read receipts — so the sender can turn ticks blue after a later poll.
- Signaling files — so git can broker a live link. Logout deletes the row.
Handshake limits on git
Git cannot consume one-time prekeys off a peer repository the way a live prekey server would. The signed prekey is the last-resort path. Handshake wording: Signal and post-quantum.
Old outbound rows that still look like { wrappedKey, nonce, ciphertext } still decrypt (RSA hybrid fallback). New sends use cascade v3: only the outer ML-KEM blob is on the wire; inner handshakes sit inside the RSA + ML-KEM wrap.
Groups
A group is delivery fan-out, not a shared repository. Chat plaintext is one N-party MLS ciphertext; each other member still gets their own sealed outbound copy carrying the same groupId. Groups stay on git. There is no live group channel.
The host can see how many outbound files a group send produced. That is metadata, not bodies.
Host policy
GitHub, GitLab, and Codeberg may treat mailbox use as against their terms. They may throttle, block, or close the repo. That is a denial-of-service and availability threat, not an afterthought.
A first-party git server as part of the service is a later possibility, not something this model waits on. Extra remotes stay in sync as backups of the same history; each remote is another copy of the public tree.
What we can see
We do not host your repository. We do not receive a copy of your token. glitr.io is this documentation site. If you use a public CORS proxy or a public try experience, that infrastructure sees what any web proxy sees.
Git tokens you type into connect are host credentials. The GUI stores them with the rest of SavedConnect. Revoke them on the host.
| Attacker | Content of outbound / signaling | Sealed folders | Metadata / IPs |
|---|---|---|---|
| Git host without your password | Ciphertext to a contact — Mitigated | Envelope — Mitigated | Visible — Documented |
| Git host with your password | Still not their inbox | Opens — Open | Visible |
| CORS proxy (web) | Same git HTTP the host sees | Same as the host for pushed files | Visible |
| Peer with your public profile | Can encrypt to you; decrypts their mail | Cannot open | Sees what you published |
Next: Live links — the path that does not wait on a poll.
