f9e1d2f0738d5903987b6f0cf2283c4814e92912
Critical hotfix for the 0.17.0 regression: users upgrading from 0.16.x
were logged out, and their next login wrote a fresh empty secure-store
on top of the original ciphertext — destroying device keys irrecoverably.
Why it happened: loadState used a blanket `catch {}` that conflated
"file doesn't exist (genuine new user)" with "file exists but can't be
decrypted (DPAPI / OSCrypt quirk after the install rename)". Both paths
returned an empty Map; the next scheduledSave then overwrote the
original .bin file with a fresh blob.
Fix:
* Separate ENOENT from decrypt/parse failures. ENOENT → empty Map. Any
other read error → log, empty Map (no quarantine, matches old
behaviour for transient lock issues).
* When decrypt/parse fails the original file is renamed to
<file>.broken-<iso-ts> BEFORE returning empty Map. The next save
writes to a fresh file; the original ciphertext is preserved on disk
so a future build (or manual recovery) can still get at the bytes.
* Loud console.error around the failure so future regressions surface
in main-process logs.
main.ts: move setPath('userData', appData/ChatApp) BEFORE setName so
any productName-derived path caching inside setName can't beat us to
it. Add a startup log of the resolved paths so future debugging has
hard evidence instead of guessing.
Affected users on 0.17.0 should still recover via Settings → Backup
Wiederherstellen (account-level keys are unchanged); this fix prevents
the data destruction for anyone who hasn't upgraded yet.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
chat-app
Private, end-to-end encrypted chat app for a small circle. Self-hosted Supabase backend, clients on iOS, Android, macOS, Windows, and Linux.
Server is zero-knowledge: it only stores ciphertexts and metadata needed to route them.
Milestone Roadmap
- Milestone 1 — Text Chat (current): auth, identity keys, 1:1 encrypted messaging, local history, push.
- Milestone 2 — Voice Calls: libsodium-secured WebRTC signaling via Supabase Realtime.
- Milestone 3 — Video Calls: same stack, add video tracks + bandwidth handling.
- Milestone 4 — Desktop Polish: feature parity with mobile, tray, notifications.
- Milestone 5 — Groups & Channels: Discord-like group channels with shared ratchet keys.
Repository Layout
apps/
mobile/ Expo + React Native (iOS / Android)
desktop/ Tauri v2 + React + Vite + Tailwind (macOS / Windows / Linux)
packages/
shared/ Business logic: Supabase client, libsodium crypto, auth, chat
db-types/ Generated Supabase database types
ui-web/ React web components shared by desktop (not by React Native)
infra/
supabase/ Self-hosting docs, client env, SQL migrations
.github/workflows/ CI + build placeholders
Tech Stack
- Mobile: Expo SDK 52, Expo Router, expo-secure-store, expo-sqlite, expo-notifications, react-native-libsodium.
- Desktop: Tauri v2, React 18, Vite, Tailwind, tauri-plugin-stronghold, tauri-plugin-sql, tauri-plugin-notification, Zustand.
- Backend: Supabase self-hosted (Postgres + GoTrue + PostgREST + Realtime + Storage + Edge Functions) on Hetzner, Caddy reverse proxy.
- Crypto: X25519 identity keys, XChaCha20-Poly1305 envelopes (libsodium / NaCl).
- Auth: email magic-link, invite-only.
Prerequisites
- Node 22+ (see
.nvmrc) - pnpm 9+
- Rust + Cargo (Tauri): https://rustup.rs
- Docker + Docker Compose (for running Supabase locally or on the VPS)
- Platform toolchain per target:
- iOS: Xcode
- Android: Android Studio + SDK
- macOS/Linux/Windows Tauri: see
apps/desktop/README.md
Setup
# 1. Node + pnpm (macOS)
brew install pnpm
corepack enable
# 2. Clone + install
git clone <this repo>
cd chat-app
pnpm install
# 3. Env
cp infra/supabase/.env.example apps/mobile/.env
cp infra/supabase/.env.example apps/desktop/.env
# Fill in SUPABASE_URL and SUPABASE_ANON_KEY from your self-hosted stack.
See infra/supabase/README.md for spinning up the backend.
Common Scripts (run from repo root)
| Script | Purpose |
|---|---|
pnpm dev |
Start every workspace's dev task (Turborepo). |
pnpm build |
Build every workspace. |
pnpm lint |
ESLint across workspaces. |
pnpm typecheck |
TypeScript project-wide type check. |
pnpm test |
Vitest across workspaces. |
pnpm format |
Prettier write. |
pnpm format:check |
Prettier check. |
pnpm mobile:dev |
expo start for the mobile app. |
pnpm mobile:ios |
Native iOS run. |
pnpm mobile:android |
Native Android run. |
pnpm desktop:dev |
tauri dev for the desktop app. |
pnpm desktop:build |
Platform-specific Tauri bundle. |
pnpm db:types |
Regenerate @chat-app/db-types from the running Supabase. |
Architecture Overview
- Shared-first: Anything that can run in both React Native and the Tauri WebView lives in
packages/sharedand is imported via@chat-app/shared/*. Both hosts pass in adapters for platform-only concerns (secure storage, SQLite, libsodium backend). - Zero-knowledge server: Messages are encrypted client-side before insert. The server sees ciphertexts, a conversation id, a sender id, and a timestamp — nothing else.
- Key custody: X25519 private keys live in platform secure stores only (Keychain/Keystore on mobile, Stronghold on desktop). Public keys live in the
profilestable. - Realtime: Supabase Realtime delivers new ciphertext rows to subscribed clients. Push notifications are silent (data-only) — the client decrypts and composes the visible notification locally.
Security Checklist
- RLS enabled on every user-facing table
- Invite-only enforced in SQL (invites table + policy)
- No plaintext in push payloads
- Service role key never shipped to a client
- JWT secret rotated on first boot
- TLS via Caddy at the edge
Description
Languages
TypeScript
76.3%
Makefile
9.5%
JavaScript
4.3%
PLpgSQL
4%
CSS
3.3%
Other
2.6%