Skip to content

Remove the browser client, keep the relay (removal phases 1–4) - #69

Open
op-q wants to merge 4 commits into
fix/sanitize-peer-textfrom
chore/remove-browser-client
Open

op-q wants to merge 4 commits into
fix/sanitize-peer-textfrom
chore/remove-browser-client

Conversation

@op-q

@op-q op-q commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Browser client removal, phases 1–4, recorded as decisions.md entry 17. Stacked on #68. This needs your review, and two repository settings changes when it merges (below).

Removed

  • web/ and crypto-wasm/ (about 4,500 lines), plus the workspace member and .cargo/config.toml's wasm rustflag.
  • The relay's / and /assets routes. GET / now answers 404 with one plain-text line naming the project and the repository.
  • CORS and DROP_ALLOWED_ORIGINS (open question 1, answered "remove").
  • Dockerfile.fullstack. docker-compose.yml now builds Dockerfile.
  • The web CI job, and npm in dependabot.
  • CodeQL now analyses Rust. There is no TypeScript left to scan.

Kept

  • The relay. --transport relay is what works where no UDP gets out, and netlab covers that case.
  • The rules about what a browser transfer may be called, in AGENTS.md and security.md, reworded as dormant (open question 3). They bind any future browser client.
  • The crypto/ crate boundary. Entry 11 is marked superseded, not deleted.

Found along the way

  • Dockerfile has not built since the envelope got its own crate. It never copied crypto/, so cargo could not load the workspace. Reproduced by copying exactly the Dockerfile's files into a scratch directory (cargo metadata fails on drop-crypto). With COPY crypto ./crypto added, cargo build --release --locked --package api succeeds there. I could not build the image itself: Docker isn't installed on this machine.
  • k8s/README.md claimed the message cap is 256 KiB, justified by a browser chunk size. It is 1 MiB + 64 KiB, and RELAY_BUDGET_BYTES is what actually bounds memory.
  • AGENTS.md said "every transfer today crosses the relay", which has been false since v0.2.0.

⚠️ Settings changes needed at merge

Branch protection on main requires these checks:

  • Web: the job is deleted, so the check never reports. Remove it from required checks.
  • Analyze JavaScript and TypeScript: renamed to Analyze Rust. Swap it in required checks.

While you're there, Rust (macos-14) and Rust (windows-2025) from #67 can be added as required once they're green on this stack.

Verified

  • cargo fmt --check, clippy -D warnings, and cargo test --workspace --all-targets pass: 193 tests. The removed index test is replaced by the_root_explains_what_this_host_is.
  • scripts/check-secrets.sh passes and git diff --check is clean.
  • git grep finds no web/, svelte, wasm-pack, vite or npm outside plans, decisions and checklist history.
  • Not run: docker compose up --build (no Docker here) and netlab (the relay code it drives only lost the removed routes and CORS). The Kubernetes render is covered by CI.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S

op-q and others added 2 commits September 14, 2026 12:18
Entry 16 removed the browser client's audience: with no hosted relay, only
someone self-hosting the full-stack image could reach it. It had also never
been exercised by a browser, and every wire change planned for 0.4.0 would have
had to be carried through it untested.

Gone: `web/`, `crypto-wasm/`, the relay's `/` and `/assets` routes, CORS and
`DROP_ALLOWED_ORIGINS`, `Dockerfile.fullstack`, the `web` CI job, npm in
dependabot, and `.cargo/config.toml`'s wasm rustflag. `GET /` now answers 404
with one line saying what the host is. CodeQL analyses Rust instead of the
TypeScript that no longer exists.

The relay stays. `--transport relay` is what works on a network that lets no
UDP out, and netlab covers that. The rules about what a browser transfer may be
called stay too, marked dormant, since they bind any future browser client.

Found on the way: `Dockerfile` has not built since the envelope moved into its
own crate. It copied the CLI's manifest but not `crypto/`, so cargo could not
load the workspace. Reproduced by copying exactly the Dockerfile's files into a
scratch directory, and fixed there with `--release --locked`.

Recorded as decisions entry 17; entry 11 is marked superseded.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

op-q and others added 2 commits September 14, 2026 12:29
It does not. The relay repeats the few envelope constants it enforces, and
cli/tests/protocol.rs fails if a copy drifts. architecture.md said otherwise,
and the removal carried that claim into the Dockerfile, two manifest comments,
lib.rs and decisions entry 17. The Dockerfile change itself stands: cargo needs
crypto/ because it is a workspace member and the CLI's path dependency.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant