Notifications and mentions #66

Closed
opened 2026-09-21 18:06:06 +01:00 by cruelacid · 1 comment
Owner

Part of #37.

What Relay does

Not shipped. "Notifications — mentions and tracked note modifications" sits
under Considering. Their issue #35 asks for an indicator when a file has been
changed by someone else.

What we do today

Nothing beyond the status bar and presence. There is no signal that a note you
are not looking at has changed.

The E2EE shape

A mention is text inside an encrypted document, so the server cannot route
notifications
— it cannot see who was mentioned. Two honest options:

  1. Client-side: a connected client notices mentions in folders it syncs and
    notifies locally. Works, needs the client running, no server involvement.
  2. Server-assisted: clients push an opaque per-recipient token when they
    write a mention, and the server fans it out without knowing what it means.
    Adds metadata — who mentions whom, and when — which
    docs/security-model.md would have to disclose.

(1) is the one consistent with the position. Note that (2) would weaken a claim
the product leads with, for a convenience feature.

Risk

risk:none for option 1.

Part of #37. ## What Relay does **Not shipped.** "Notifications — mentions and tracked note modifications" sits under **Considering**. Their issue #35 asks for an indicator when a file has been changed by someone else. ## What we do today Nothing beyond the status bar and presence. There is no signal that a note you are not looking at has changed. ## The E2EE shape A mention is text inside an encrypted document, so **the server cannot route notifications** — it cannot see who was mentioned. Two honest options: 1. **Client-side**: a connected client notices mentions in folders it syncs and notifies locally. Works, needs the client running, no server involvement. 2. **Server-assisted**: clients push an opaque per-recipient token when they write a mention, and the server fans it out without knowing what it means. Adds metadata — who mentions whom, and when — which `docs/security-model.md` would have to disclose. (1) is the one consistent with the position. Note that (2) would weaken a claim the product leads with, for a convenience feature. ## Risk `risk:none` for option 1.
Author
Owner

Moved to the Vikunja board as NEC-43: https://projectron.nerchure.com/tasks/43

Moved to the Vikunja board as **NEC-43**: https://projectron.nerchure.com/tasks/43
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#66
No description provided.