Skip to main content

Git mailbox

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

A git-URL contact’s reliable path is push, fetch, and poll. You never write into someone else’s repository. You write outbound on yours. They keep a fetch-only clone and ingest what is addressed to them.

This page is that path as a threat surface. The user story is Git as your mailbox. File shapes are on Data structures. Host how-to: Using GitHub, GitLab, and Codeberg.

There is no Glitr account server. Poll authentication is local session middleware on in-process api-core.

What the host can read​

On the remoteWhat it isHost sees
profile-public.jsonRSA public key and protocol bundlesDocumented — needed so a contact can encrypt the first message
outbound/Cascade (or hybrid) ciphertext addressed to a recipientIdCiphertext, sizes, dates, who it is for
readreceipts/“This outbound id was read”Documented — ticks need a readable row
signaling/One file per contact while you are connectedThe file is visible; inner SDP is cascaded to the contact
devices/Local device rows, including this device’s onionOrdinary JSON. A clone can read it. A peer poll does not fetch it
Sealed folders (contacts, inbox, sent, groups, protocol-sessions, file-transfers, profile-secrets)Password envelopesEnvelope bytes, not the JSON

Sealing is not end-to-end messaging. Your connect password opens your documents. Peers never open those folders. They decrypt outbound and signaling with their keys.

What the host can infer anyway​

Even with bodies cascaded:

  • That you have a mailbox repository.
  • How often it changes, and roughly how large it is.
  • Who you gave read access to (collaborators, deploy keys, tokens).
  • IP addresses on push and fetch (normal git hosting logs).
  • On the web, a user-supplied CORS proxy (empty by default) sits on the path and sees git HTTP. Desktop and TUI skip that proxy for local-only; they can send git HTTPS through Tor SOCKS instead.

Threat model in one line: protect message content from the host; do not expect the host to be unaware that you chat.

Intentionally readable​

If everything were sealed with only your password, nobody else could start a conversation.

  • Public profile — Pending → Active is a fetch of this file.
  • Outbound ciphertext — mail for them, not a document for the host.
  • Read receipts — so the sender can turn ticks blue after a later poll.
  • Signaling files — so git can broker a live link. Logout deletes the row.

Handshake limits on git​

Git cannot consume one-time prekeys off a peer repository the way a live prekey server would. The signed prekey is the last-resort path. Handshake wording: Signal and post-quantum.

Old outbound rows that still look like { wrappedKey, nonce, ciphertext } still decrypt (RSA hybrid fallback). New sends use cascade v3: only the outer ML-KEM blob is on the wire; inner handshakes sit inside the RSA + ML-KEM wrap.

Groups​

A group is delivery fan-out, not a shared repository. Chat plaintext is one N-party MLS ciphertext; each other member still gets their own sealed outbound copy carrying the same groupId. Groups stay on git. There is no live group channel.

The host can see how many outbound files a group send produced. That is metadata, not bodies.

Host policy​

GitHub, GitLab, and Codeberg may treat mailbox use as against their terms. They may throttle, block, or close the repo. That is a denial-of-service and availability threat, not an afterthought.

A first-party git server as part of the service is a later possibility, not something this model waits on. Extra remotes stay in sync as backups of the same history; each remote is another copy of the public tree.

What we can see​

We do not host your repository. We do not receive a copy of your token. glitr.io is this documentation site. If you use a public CORS proxy or a public try experience, that infrastructure sees what any web proxy sees.

Git tokens you type into connect are host credentials. The GUI stores them with the rest of SavedConnect. Revoke them on the host.

AttackerContent of outbound / signalingSealed foldersMetadata / IPs
Git host without your passwordCiphertext to a contact — MitigatedEnvelope — MitigatedVisible — Documented
Git host with your passwordStill not their inboxOpens — OpenVisible
CORS proxy (web)Same git HTTP the host seesSame as the host for pushed filesVisible
Peer with your public profileCan encrypt to you; decrypts their mailCannot openSees what you published

Next: Live links — the path that does not wait on a poll.