3e136d3729f53d361278c633efca696207e7ff40
Linux (WebKitGTK) allowed every permission request of every kind; Windows (WebView2) auto-allowed mic/camera/notifications without checking who asked. Now (src-tauri/src/webview_permissions.rs, unit-tested): - Linux: microphone/camera/screen, device labels, notifications and location are granted when the page in the window is the app (http://localhost:44548; debug builds also the bundled/dev page). Everything else is denied (WebKitGTK has no prompt of its own). WebKitGTK doesn't say which frame asked; frames are gated earlier by the Permissions Policy (cinny gives microphone/camera only to the same-origin call frame). - Windows: the same grants (minus location, which keeps WebView2's prompt), checked against the origin of the frame that asked (args.Uri()). Other origins are denied mic/camera/notifications/location; other kinds keep WebView2's default handling. - Denials are logged ("webview: denied …"). Tested on Linux with a release build under Xvfb + PulseAudio (no WebDriver: WebKit's automation mode bypasses the handler), before/after: - app page: mic, device labels, location allowed (unchanged) - same-origin call frame: mic allowed (unchanged) - cross-origin frame without allow=: blocked before the handler (unchanged) - foreign top-level page: mic, device labels, location now denied (were allowed) Real cinny build: boots, logs in, no denials. Windows code type-checked (x86_64-pc-windows-gnu). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
Cinny desktop
Cinny is a matrix client focusing primarily on simple, elegant and secure interface. The desktop app is made with Tauri.
Download
Installers for macOS, Windows and Linux can be downloaded from Github releases. Releases are signed with a Ed25519 public-key.
| Operating System | Download |
|---|---|
| Windows | Get it on Windows |
| macOS | Get it on macOS |
| Linux | Get it on Linux · Flatpak |
Decoded public key:
RWRflTUQD3RHFtn25QNANCmePR9+4LSK89kAKTMEEB4OKpOFpLMgc64z
To verify release files, you need to download minisign tool and decode the .sig file before running:
minisign -Vm RELEASE_FILE.msi.zip -P RWRflTUQD3RHFtn25QNANCmePR9+4LSK89kAKTMEEB4OKpOFpLMgc64z -x SINGATURE.msi.zip.sig
Local development
Firstly, to setup Rust, NodeJS and build tools follow Tauri documentation.
Now, to setup development locally run the following commands:
git clone --recursive https://github.com/cinnyapp/cinny-desktop.gitcd cinny-desktop/cinnynpm cicd ..npm ci
To build the app locally, run:
npm run tauri build
To start local dev server, run:
npm run tauri dev
Languages
Rust
92.5%
JavaScript
4.4%
C
1.3%
Shell
1%
NSIS
0.8%