gsmol/README.md
2026-10-09 13:47:50 +03:00

1.7 KiB

gsmol

License: Apache-2.0 Built with Devbox AI-DECLARATION: copilot Nix Flake

Smol Mail in a browser tab. All the crypto, keys and mail handling run client-side in JavaScript; a small local bridge just relays bytes to a smolmaild server over WebSocket.

browser (all crypto, all keys)  ⇄  bridge.py (dumb byte pipe)  ⇄  smolmaild (TCP :1961)

The bridge holds no keys and never parses a byte of traffic. The trust boundary is the machine running the browser.

Run

devbox run serve

Open http://127.0.0.1:8096. Onboarding walks you through creating or restoring an identity (the seed is shown once — write it down), pinning your server's public key, and claiming an address. Then fetch.

Non-default server port: uv run bridge.py --allow-port <port>.

Test

devbox run test

Byte-for-byte checks against the reference vectors, protocol cases, and a live end-to-end exchange with the reference client through the bridge — the exact byte path the browser takes. Only clicking through the UI is left to a manual pass.

Deploy

nix build .#default   # -> ./result/bin/gsmol-bridge

The bridge binds to 127.0.0.1 and has no TLS of its own — for anything beyond localhost, put nginx or caddy in front. A NixOS module is included (nixosModules.default → services.gsmol-bridge) with the same options.