Start here: try, review, or help build elm.chat #42
shawnbure
announced in
Announcements
Replies: 1 comment
|
v0.1.1 is now available: https://github.com/shawnbure/elm-chat/releases/tag/v0.1.1 The update centralizes the project’s security status and limitations, preserves an invited participant’s active room when they open the “make your own” path, and adds a public changelog plus a 12-entry article/technical-note feed. The review request remains open: #56 Important boundary: this release has not completed an independent security audit. Message authentication and replay/duplicate protection remain unfinished; the relay sees ordinary connection metadata; and participant devices can retain copies. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
elm.chat is an open-source experiment in a simple idea: some conversations should be temporary by design, not permanent records waiting for a cleanup policy.
The current
v0.1.0release creates an account-free room, shares a single-use invite, encrypts messages and files in the browser, and lets the room be destroyed manually or on a timer. The relay does not persist a server-side transcript or file history.Try it: https://elm.chat
Inspect it:
This is early-stage software. It has not had an independent security audit, the relay can observe ordinary connection metadata, device compromise remains outside the app’s protection, and the threat model documents authentication work that still needs to be completed. Please evaluate those limits before relying on it for sensitive use.
There are three useful ways to help:
good first issueandhelp wanted: https://github.com/shawnbure/elm-chat/issues?q=is%3Aissue%20state%3Aopen%20label%3A%22good%20first%20issue%22If the project is useful or worth watching, starring the repository helps other open-source contributors discover it: https://github.com/shawnbure/elm-chat
Questions, criticism, self-hosting reports, and small pull requests are welcome. Please keep security reports responsible: use the private reporting path described in
SECURITY.mdfor vulnerabilities that should not be public before a fix exists.All reactions