9400189a8dcb9294e02563e2e1dc6f0ce4736474
Replace the federation outbox worker's 401/403 wipe-and-rehandshake loop with bounded retry (AUTH_FAILURE_THRESHOLD=5, ~21.5 min backoff window) and a new `needs_attention` peer state. Surfaces persistent HMAC desync to admins via a first-class 'Reset peering' action instead of the prior silent loop. Closes backlog item #19. Security invariants verified on live infra (Pi+VM): - hmac_secret is NEVER wiped in response to a network-observed 401/403 (Task 5 removes the wipe; Task 7 extends the /peer/accept idempotent- 200-no-update safeguard to cover needs_attention peers). - Auth failures increment only consecutive_auth_failures, never the network counter consecutive_failures (Task 5 splits handleOutboxDeliveryFailure → applyOutboxEntryBackoff). - Transition occurs at exactly 5 consecutive 401/403 responses; below threshold, entries get backoff but state is preserved; above, peer flips to needs_attention, affected users get federation_peer_rejected WS with 'Federation trust broken — admin must reset peering'. - /peer/accept safeguard confirmed against attacker curl probe on the live Pi instance while in needs_attention — forged-secret request returned 200-no-update, local hmac_secret unchanged. - Legitimate rotation (Scenario B) does not false-positive: both sides capture pending secret, auth_failures stays at 0, DM delivers cleanly during grace period. Four follow-up backlog items discovered during the work: #20 health-check cadence tightening (15-min grace vs 1-hour tick) #21 /peer/initiate 202 handling #22 consecutive_failures nullability normalization #23 unify client-side FederationPeer with shared type Spec: internal notes Plan: internal notes
Backspace
Open-source, self-hosted Discord alternative built with TypeScript.
Features
- Real-time text messaging with WebSocket
- Servers, channels, and role-based permission management
- Voice and video chat via LiveKit
- Screen sharing with configurable quality (VP9)
- Direct messages (1-on-1 and group DMs up to 10)
- DM voice/video calls with ringing
- Friend system with requests
- File uploads and image sharing
- Markdown message formatting with syntax highlighting
- Message reactions, replies, and editing
- Typing indicators, presence status, and read states
- Invite system with shareable codes
- Instance-level admin panel (streaming limits)
- Desktop app (Electron)
- Mobile-responsive web UI
- Docker deployment
Tech Stack
| Layer | Technology |
|---|---|
| Backend | Fastify + TypeScript |
| Database | SQLite (better-sqlite3) + Drizzle ORM |
| Auth | JWT + bcrypt |
| Real-time | WebSocket (ws) |
| Frontend | React 18 + Tailwind CSS + Zustand |
| Voice/Video | LiveKit |
| Desktop | Electron |
| Build | Vite + pnpm workspaces |
Quick Start with Docker
# Clone the repository
git clone https://github.com/your-username/backspace.git
cd backspace
# Create environment file
cp .env.example .env
# Generate a JWT secret
echo "JWT_SECRET=$(openssl rand -hex 32)" >> .env
# Start Backspace
docker compose up -d
Open http://localhost:3000 in your browser. A default server "Backspace" is created automatically.
Default admin account: admin / admin123 (change this after first login).
Development Setup
Prerequisites
- Node.js 20+
- pnpm 8+
Install
pnpm install
Configure
cp .env.example .env
# Edit .env with your settings (generate a JWT_SECRET)
Run
# Start both server and web dev server
pnpm dev
# Or start individually
pnpm dev:server # API server on :3005
pnpm dev:web # Vite dev server on :5173
Build
pnpm build
This builds the shared types, server, and web frontend. The server serves the built frontend in production mode.
Project Structure
Backspace/
├── packages/
│ ├── shared/ # Shared TypeScript types & permissions
│ ├── server/ # Fastify API + WebSocket server
│ ├── web/ # React frontend (Vite + Tailwind)
│ └── desktop/ # Electron desktop app
├── data/ # SQLite DB + uploads (created at runtime)
├── Dockerfile
├── docker-compose.yml
└── .env.example
Voice & Video
Voice and video requires a LiveKit server. Set these in your .env:
LIVEKIT_URL=wss://your-livekit-server
LIVEKIT_API_KEY=your-api-key
LIVEKIT_API_SECRET=your-api-secret
Without LiveKit configured, text chat works fully but voice/video channels will not connect.
API
The server exposes a REST API and WebSocket endpoint:
- REST API:
http://localhost:3000/api/* - WebSocket:
ws://localhost:3000/ws - Health check:
GET /api/health
See CLAUDE.md for the full API reference.
Desktop App
The Electron desktop app wraps the web UI and adds system tray, notifications, and native window controls.
cd packages/desktop
pnpm build:ts # Compile TypeScript
pnpm dev # Run in development
pnpm build # Package for distribution
License
MIT
Languages
TypeScript
96.8%
HTML
1.3%
Shell
1.1%
JavaScript
0.4%
CSS
0.3%