Keep the client unminified and auditable #70

Closed
opened 2026-09-21 18:07:07 +01:00 by cruelacid · 1 comment
Owner

Part of #37. Category 4: no competitor does this. A standing obligation, not a task.

Why it is filed

docs/positioning.md names this as one of three claims to lead with: "The code
that encrypts your notes is on your disk. Read it."
Obsidian plugins ship as
JavaScript, and ours ships not minified at all (esbuild.config.mjs,
minify: false) — so verification means reading the file, not arguing about
reproducible builds the way one must with Signal, Threema or WhatsApp.

Relay's plugin is MIT and therefore readable too, but they are not end-to-end
encrypted
, so there is nothing in their client for an auditor to check. The
combination — E2EE and an unminified client — is ours alone in this category.

The obligation

This is a claim that goes false silently. It breaks if anyone ever enables
minification for bundle size, adds an obfuscating dependency, or ships a build
step that rewrites the shipped JavaScript.

The cost is already accepted and recorded: 214KB to 526KB, "which is nothing
beside the attachments this plugin moves"
(docs/plan-master.md).

What this issue is for

A CI assertion that the published main.js is not minified, so the claim cannot
regress without failing a build. CLAUDE.md already requires grepping the built
artefact for a literal when verifying a change reached it — this is the same
discipline applied to a marketing claim.

Risk

risk:none.

Part of #37. **Category 4: no competitor does this.** A standing obligation, not a task. ## Why it is filed `docs/positioning.md` names this as one of three claims to lead with: *"The code that encrypts your notes is on your disk. Read it."* Obsidian plugins ship as JavaScript, and ours ships **not minified at all** (`esbuild.config.mjs`, `minify: false`) — so verification means reading the file, not arguing about reproducible builds the way one must with Signal, Threema or WhatsApp. Relay's plugin is MIT and therefore readable too, but **they are not end-to-end encrypted**, so there is nothing in their client for an auditor to check. The combination — E2EE *and* an unminified client — is ours alone in this category. ## The obligation This is a claim that goes false silently. It breaks if anyone ever enables minification for bundle size, adds an obfuscating dependency, or ships a build step that rewrites the shipped JavaScript. The cost is already accepted and recorded: 214KB to 526KB, *"which is nothing beside the attachments this plugin moves"* (`docs/plan-master.md`). ## What this issue is for A CI assertion that the published `main.js` is not minified, so the claim cannot regress without failing a build. `CLAUDE.md` already requires grepping the built artefact for a literal when verifying a change reached it — this is the same discipline applied to a marketing claim. ## Risk `risk:none`.
Author
Owner

Moved to the Vikunja board as NEC-46: https://projectron.nerchure.com/tasks/46

Moved to the Vikunja board as **NEC-46**: https://projectron.nerchure.com/tasks/46
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#70
No description provided.