Repository navigation
v0.2.2 — DMs decrypt properly
Fixes direct messages showing as encrypted.
Two separate mistakes, either of which alone would have hidden every message:
The sealed key was read from the wrong field. The client looked for sealedKey; the API sends encryptedKey. No key was ever unwrapped, so every message stayed ciphertext.
Key rotation was ignored. Twetch rotates a conversation key when membership changes. Each message records the keyEpoch it was sealed under, and the API returns the current key plus a historicalKeys map of the earlier ones. That map was dropped, so even with the field name fixed, anything sent before the last rotation would still have been unreadable. Keys are now tracked per epoch and each message is decrypted with the key from its own epoch.
Also fixed along the way:
- The messages endpoint returns the keys next to the messages, and the client was discarding them. Sending now recovers a key from that endpoint if the conversation list did not carry one, instead of failing.
- Conversation members were read from
members; the field ismemberIds, so one-to-one threads could not tell who the other party was. - Conversation-list previews decrypt as well, so the inbox shows real text.
- A message whose key genuinely is not available now says so plainly rather than showing a bare padlock.