confirmVerification(userCode)validates a manually entered SAS code.- Verification succeeds only after both local and remote confirmations are present.
isVerifiedis assigned in one place (_setVerifiedStatus), which refuses any SAS-based transition without a recorded local confirmation.- Control frames listed in
POST_VERIFICATION_CONTROL_TYPES(reconnection signalling, call setup, message deletion, delivery receipts) are only acted on after verification. The set is an allowlist; unrecognised frame types are rejected by the chat channel's default-deny branch. - Protocol version
4.1is enforced during offer/answer processing.
isRatchetActive()reports whether the Double Ratchet is running on this connection. It is negotiated: both peers advertiseRATCHET_VERSIONin the offer and answer, and a peer that does not falls back to per-session keys._ratchet.canEncryptis false on the joining peer until the inviting peer's first message arrives, because the sending chain does not exist until then. Callers must check it rather than assume; the send path falls back to session keys for those first frames._ratchet.getState()returns counters and the number of retained keys for diagnostics. It exposes no key material.- Ratcheted chat arrives as
MESSAGE_TYPES.RATCHET_MESSAGEwithh(the header string, used verbatim as AES-GCM additional data) andc(base64 body). The header must be passed back todecrypt()exactly as received; re-serialising it can change a byte and fail authentication.
- relay-only configuration sets WebRTC
iceTransportPolicyto"relay". - TURN availability is checked before claiming IP protection.
setFileTransferCallbacks(onProgress, onReceived, onError, onIncomingRequest)updates manager fields and any liveEnhancedSecureFileTransferinstance.- Passing
nullvalues detaches callbacks from the active transfer system.
sendFile(file, options)accepts an optionaloptionsobject.options.voice({ dur, bars }) marks the transfer as a voice note and rides along as unsigned metadata;options.uiIdcorrelates progress events to a UI bubble before thefileIdresolves.onProgressreceives{ fileId, uiId, direction, progress, isVoice, voice }.onIncomingFileRequestandonReceivedincludeisVoiceandvoiceso the UI can auto-accept and render a voice bubble instead of a file card.- The
isVoicea callback receives is the receiver's verdict, not the sender's claim:validateIncomingMetadataclears it unless the transfer declares a recognised audio MIME type and fits the per-note and per-session size budgets. A transfer that fails those checks is not rejected; it simply loses the consent-free shortcut and is offered as a normal file.
- metadata is validated before prompting
- acceptance is explicit
- receive buffers are allocated only after consent
- file type acceptance is allowlist-based
- pending sender consent promises are rejected on cleanup
- consent timeouts are cleared immediately
- retained received buffers are bounded
- evicted download handles fail with a user-facing availability message
- metadata is encrypted before storage
- legacy plaintext records migrate lazily
- corrupted encrypted metadata is ignored safely