fix(composer): stop three E2EE plaintext leaks (compress, schedule, GIF)
- Image compression in an encrypted room re-encoded the *plaintext* original, uploaded it unencrypted, and reused the original's encInfo, so the media sat on the server in the clear AND the attachment was undecryptable. The compressed bytes are now run through encryptFile and the synthetic upload item carries the new encInfo (buildCompressedUploadItem, unit-tested; it can never inherit the stale encInfo). - Scheduled messages (MSC4140) are PUT as raw m.room.message, bypassing the SDK encryption pipeline. The Schedule button is now hidden in encrypted rooms, handleScheduleClick no-ops there, and scheduleMessage() itself refuses with a clear error so no caller can regress this. README notes the limitation. - The GIF picker uploaded the Giphy blob unencrypted into E2EE rooms; it now mirrors the voice/attachment path (encryptFile -> upload ciphertext -> content.file). Fixes #6 Fixes #7 Fixes #11 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
@@ -22,7 +22,7 @@ The Lotus Chat logo (`public/res/Lotus.png`) is a derivative work based on the o
|
||||
- Slack-style thread notifications: by default you're only pinged for threads you're in or where you're @mentioned; set any thread to All / Mentions-only / Mute from the panel's bell menu (muted threads stop bumping badges; syncs across devices)
|
||||
- See who has read each message, and track delivery status (sending / sent / failed)
|
||||
- Bookmark any message and revisit saved messages from the sidebar
|
||||
- Schedule messages to send at a specific time
|
||||
- Schedule messages to send at a specific time (unencrypted rooms only — MSC4140 delayed events cannot be end-to-end encrypted, so the option is hidden in E2EE rooms)
|
||||
- Click "edited" on any message to see the full edit history
|
||||
- Drafts are saved automatically and survive page reloads
|
||||
- Long messages collapse automatically — click "Read more" to expand
|
||||
|
||||
Reference in New Issue
Block a user