- Record voice notes in-browser, sent over the chunked AES-GCM file-transfer channel (per-file session key + signed SHA-256 integrity). - Captured as PCM and encoded to WAV for universal playback (incl. iOS/Safari); auto-accepted and played inline from an in-memory blob, never written to disk. - Composer mic button with live waveform + timer; desktop shows mic + send side by side, mobile swaps mic to send when typing. - CSP media-src now allows blob: so recorded/received audio can play. - Roadmap: Desktop Edition -> 5.0, new 5.5 'Secure Voice & Calls', later milestones shifted; version bumped to 5.4.5. - Update README, docs (security/API/cryptography), and CHANGELOG.
1.8 KiB
1.8 KiB
API Notes
EnhancedSecureWebRTCManager
Verification
confirmVerification(userCode)validates a manually entered SAS code.- Verification succeeds only after both local and remote confirmations are present.
- Protocol version
4.1is enforced during offer/answer processing.
Privacy mode
- relay-only configuration sets WebRTC
iceTransportPolicyto"relay". - TURN availability is checked before claiming IP protection.
File transfer callbacks
setFileTransferCallbacks(onProgress, onReceived, onError, onIncomingRequest)updates manager fields and any liveEnhancedSecureFileTransferinstance.- Passing
nullvalues detaches callbacks from the active transfer system.
Voice messages
sendFile(file, options)accepts an optionaloptionsobject.options.voice({ dur, bars }) marks the transfer as a voice note and rides along as unsigned metadata;options.uiIdcorrelates progress events to a UI bubble before thefileIdresolves.onProgressreceives{ fileId, uiId, direction, progress, isVoice, voice }.onIncomingFileRequestandonReceivedincludeisVoiceandvoiceso the UI can auto-accept and render a voice bubble instead of a file card.
EnhancedSecureFileTransfer
Incoming transfers
- metadata is validated before prompting
- acceptance is explicit
- receive buffers are allocated only after consent
- file type acceptance is allowlist-based
Cleanup
- pending sender consent promises are rejected on cleanup
- consent timeouts are cleared immediately
- retained received buffers are bounded
- evicted download handles fail with a user-facing availability message
SecurePersistentKeyStorage
- metadata is encrypted before storage
- legacy plaintext records migrate lazily
- corrupted encrypted metadata is ignored safely