44 lines
2.7 KiB
Markdown
44 lines
2.7 KiB
Markdown
# kirakira
|
|
|
|
[](https://ai-declaration.md)
|
|
[](https://opensource.org/licenses/MIT)   [](https://github.com/sarthakkimtani/flash-mail)
|
|
|
|
A mobile client for [Smol Mail](https://smol.place), a minimalist end-to-end encrypted mail protocol: one Ed25519 identity, five operations, sealed and signed messages over a Noise_NX transport. Sibling of the reference CLI client (`https://smol.place`) and the browser client (`https://code.randogoth.com/randogoth/gsmol`).
|
|
|
|
kirakira began as [FlashMail](https://github.com/sarthakkimtani/flash-mail), a Flutter UI template for a disposable-email app built on mail.tm. Its networking layer was replaced end to end with a from-scratch Smol Mail implementation (`lib/smol/`: crypto, Noise handshake, framing, client flows), and the UI was redesigned around a Material 3 theme — dark navy and mint green by default, with a matching light theme — built from a single `ColorScheme` and `AppColors` extension rather than hardcoded colors per screen.
|
|
|
|
## What it does
|
|
|
|
- Create or restore an identity from a 32-byte seed — that's the only secret.
|
|
- Pin a server's key, register or recall an address, then fetch and send sealed mail.
|
|
- Trust-on-first-use for server and contact keys, with rotation support and on-screen warnings for anything unverified.
|
|
- Export/import inbox, sent mail, contacts and server pins as one shareable backup file — never the seed.
|
|
|
|
## Layout
|
|
|
|
```
|
|
lib/smol/ the protocol: crypto, Noise handshake, framing, client flows
|
|
lib/presentation/ screens, widgets and theme (Riverpod + auto_route)
|
|
lib/data/ Riverpod providers
|
|
test/ protocol vectors, store tests, a live e2e round-trip
|
|
```
|
|
|
|
## Run and verify
|
|
|
|
```
|
|
devbox run analyze
|
|
devbox run test
|
|
flutter run
|
|
```
|
|
|
|
`test/e2e_test.dart` runs a live round-trip against `https://smol.place/smolmaild.py` on `127.0.0.1:1961` and skips itself when nothing's listening there.
|
|
|
|
## Notes and limits
|
|
|
|
- No server push in v1 — fetch is manual.
|
|
- The seed lives in app storage; a compromised device is a compromised identity.
|
|
- Rotation isn't revocation — a stolen key can still rotate onward. Settings surfaces rotations for out-of-band verification rather than applying them silently.
|
|
|
|
## License
|
|
|
|
MIT — see LICENSE.md.
|