5c3ac6832882b9374845c855a56de45c4ff515ec
The bundled Element Call page ran on the app's own origin (http://localhost:44548), so the call frame could read the app's storage (login token) and DOM. Serve it from http://127.0.0.1:44548 instead: the same local server and bundle, a different origin. - The local server binds 127.0.0.1 explicitly. The app is still loaded as http://localhost:44548 (its storage stays where it is; the engines try 127.0.0.1 for `localhost`). Binding the name `localhost` could pick ::1 only (Windows lists it first), and then 127.0.0.1 wouldn't answer. - config.json: desktopCallOrigin = http://127.0.0.1:44548. cinny loads the call page from there only when this is set (cinny #43 PR). - CSP frame-src allows http://127.0.0.1:44548. - Permissions (on top of #22): the call page's origin gets microphone/ camera/screen only; nothing else. - The call page gets no IPC: the capability only matches http://localhost:44548. Tested (Linux release build): the server listens on 127.0.0.1:44548 and the app loads as http://localhost:44548; the call page loads from 127.0.0.1 inside the app under its CSP; from that frame parent.localStorage and parent.document are SecurityError, while a same-origin frame (the old setup) reads the app's storage. The call itself was tested in a simulated desktop (Chromium, the WebView2 engine) against a local Synapse + LiveKit; see the cinny PR. Rust tests 17 passed; Windows code type-checked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
Cinny desktop
Cinny is a matrix client focusing primarily on simple, elegant and secure interface. The desktop app is made with Tauri.
Download
Installers for macOS, Windows and Linux can be downloaded from Github releases. Releases are signed with a Ed25519 public-key.
| Operating System | Download |
|---|---|
| Windows | Get it on Windows |
| macOS | Get it on macOS |
| Linux | Get it on Linux · Flatpak |
Decoded public key:
RWRflTUQD3RHFtn25QNANCmePR9+4LSK89kAKTMEEB4OKpOFpLMgc64z
To verify release files, you need to download minisign tool and decode the .sig file before running:
minisign -Vm RELEASE_FILE.msi.zip -P RWRflTUQD3RHFtn25QNANCmePR9+4LSK89kAKTMEEB4OKpOFpLMgc64z -x SINGATURE.msi.zip.sig
Local development
Firstly, to setup Rust, NodeJS and build tools follow Tauri documentation.
Now, to setup development locally run the following commands:
git clone --recursive https://github.com/cinnyapp/cinny-desktop.gitcd cinny-desktop/cinnynpm cicd ..npm ci
To build the app locally, run:
npm run tauri build
To start local dev server, run:
npm run tauri dev
Languages
Rust
92.5%
JavaScript
4.4%
C
1.3%
Shell
1%
NSIS
0.8%