byGalax c3e0c47d32 feat(call): native screen-capture pipeline + faster picker
Picker speed (Phase 1+2):
- screen_sources.rs split into list_screen_sources (metadata only,
  returns in ~10ms) + capture_screen_source_thumbnail (single source,
  by id). ScreenSourcePicker now shows names + placeholders instantly
  and streams thumbnails in as each capture lands. Total wall-clock
  is bounded by the slowest source instead of the serial sum.
- enumerate_screen_sources kept as a dead_code fallback so any
  rollout regression can switch the frontend back without code loss.

Native capture (Phase 3):
- New src-tauri/src/screen_capture.rs. start_screen_capture spawns a
  Rust thread per share that grabs frames via xcap, downscales to the
  user's quality preset, JPEG-encodes at Q72, and streams each frame
  through a Tauri Channel<FramePayload>. stop_screen_capture signals
  the stop flag and joins the worker.
- Worker re-resolves the xcap handle inside the thread because
  xcap::Window holds a !Send HWND — passing the source id string
  across the thread boundary sidesteps that.
- New lib/screenCapture.ts: decodes each frame into an ImageBitmap,
  draws to an offscreen canvas, exposes canvas.captureStream() as the
  MediaStream LiveKit publishes. Latest-wins frame queue drops stale
  frames when the JS side falls behind the Rust producer. 3s first-
  frame timeout so a silently-failing source (locked screen, DRM
  window) surfaces as a clean NativeCaptureUnavailable and we fall
  back to getDisplayMedia.
- CallContext.startScreenShare takes the native path first when the
  picker provided a sourceId and system audio wasn't requested. The
  old chromeMediaSourceId attempt and final setScreenShareEnabled
  fallback stay in place for the audio case + non-Tauri runtimes.
- stopScreenShare kills the native handle first, then unpublishes any
  manually-published ScreenShare/ScreenShareAudio tracks, then falls
  back to setScreenShareEnabled(false). disconnectRoom also stops
  the handle so we don't leak Rust threads across calls.

Scope note: native path is video-only. System-audio capture needs
WASAPI-loopback (Windows) or ScreenCaptureKit-audio (macOS); until
those are wired, requesting audio in the picker falls through to
the getDisplayMedia path and shows the OS picker for that one case.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-22 21:42:52 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00

chat-app

Private, end-to-end encrypted chat app for a small circle. Self-hosted Supabase backend, clients on iOS, Android, macOS, Windows, and Linux.

Server is zero-knowledge: it only stores ciphertexts and metadata needed to route them.

Milestone Roadmap

  1. Milestone 1 — Text Chat (current): auth, identity keys, 1:1 encrypted messaging, local history, push.
  2. Milestone 2 — Voice Calls: libsodium-secured WebRTC signaling via Supabase Realtime.
  3. Milestone 3 — Video Calls: same stack, add video tracks + bandwidth handling.
  4. Milestone 4 — Desktop Polish: feature parity with mobile, tray, notifications.
  5. Milestone 5 — Groups & Channels: Discord-like group channels with shared ratchet keys.

Repository Layout

apps/
  mobile/      Expo + React Native (iOS / Android)
  desktop/     Tauri v2 + React + Vite + Tailwind (macOS / Windows / Linux)
packages/
  shared/      Business logic: Supabase client, libsodium crypto, auth, chat
  db-types/    Generated Supabase database types
  ui-web/      React web components shared by desktop (not by React Native)
infra/
  supabase/    Self-hosting docs, client env, SQL migrations
.github/workflows/  CI + build placeholders

Tech Stack

  • Mobile: Expo SDK 52, Expo Router, expo-secure-store, expo-sqlite, expo-notifications, react-native-libsodium.
  • Desktop: Tauri v2, React 18, Vite, Tailwind, tauri-plugin-stronghold, tauri-plugin-sql, tauri-plugin-notification, Zustand.
  • Backend: Supabase self-hosted (Postgres + GoTrue + PostgREST + Realtime + Storage + Edge Functions) on Hetzner, Caddy reverse proxy.
  • Crypto: X25519 identity keys, XChaCha20-Poly1305 envelopes (libsodium / NaCl).
  • Auth: email magic-link, invite-only.

Prerequisites

  • Node 22+ (see .nvmrc)
  • pnpm 9+
  • Rust + Cargo (Tauri): https://rustup.rs
  • Docker + Docker Compose (for running Supabase locally or on the VPS)
  • Platform toolchain per target:
    • iOS: Xcode
    • Android: Android Studio + SDK
    • macOS/Linux/Windows Tauri: see apps/desktop/README.md

Setup

# 1. Node + pnpm (macOS)
brew install pnpm
corepack enable

# 2. Clone + install
git clone <this repo>
cd chat-app
pnpm install

# 3. Env
cp infra/supabase/.env.example apps/mobile/.env
cp infra/supabase/.env.example apps/desktop/.env
# Fill in SUPABASE_URL and SUPABASE_ANON_KEY from your self-hosted stack.

See infra/supabase/README.md for spinning up the backend.

Common Scripts (run from repo root)

Script Purpose
pnpm dev Start every workspace's dev task (Turborepo).
pnpm build Build every workspace.
pnpm lint ESLint across workspaces.
pnpm typecheck TypeScript project-wide type check.
pnpm test Vitest across workspaces.
pnpm format Prettier write.
pnpm format:check Prettier check.
pnpm mobile:dev expo start for the mobile app.
pnpm mobile:ios Native iOS run.
pnpm mobile:android Native Android run.
pnpm desktop:dev tauri dev for the desktop app.
pnpm desktop:build Platform-specific Tauri bundle.
pnpm db:types Regenerate @chat-app/db-types from the running Supabase.

Architecture Overview

  • Shared-first: Anything that can run in both React Native and the Tauri WebView lives in packages/shared and is imported via @chat-app/shared/*. Both hosts pass in adapters for platform-only concerns (secure storage, SQLite, libsodium backend).
  • Zero-knowledge server: Messages are encrypted client-side before insert. The server sees ciphertexts, a conversation id, a sender id, and a timestamp — nothing else.
  • Key custody: X25519 private keys live in platform secure stores only (Keychain/Keystore on mobile, Stronghold on desktop). Public keys live in the profiles table.
  • Realtime: Supabase Realtime delivers new ciphertext rows to subscribed clients. Push notifications are silent (data-only) — the client decrypts and composes the visible notification locally.

Security Checklist

  • RLS enabled on every user-facing table
  • Invite-only enforced in SQL (invites table + policy)
  • No plaintext in push payloads
  • Service role key never shipped to a client
  • JWT secret rotated on first boot
  • TLS via Caddy at the edge
S
Description
No description provided
Readme 64 MiB
Languages
TypeScript 76.3%
Makefile 9.5%
JavaScript 4.3%
PLpgSQL 4%
CSS 3.3%
Other 2.6%