Note
Proof of Concept / Work in Progress
Outpost is a conceptual prototype demonstrating what is possible with a completely decentralized, serverless workspace client. It is currently a work in progress and is not actively under development at this time.
Outpost is a desktop-first, peer-to-peer (P2P) collaboration platform modeled after modern chat clients like Discord. Built with Electron, it features zero central servers, relying instead on cryptographic swarming, direct WebRTC data channels, and Hypercore append-only ledgers to construct secure, private, and localized group spaces.
- Zero-Backend Invariant: No central authentication, discovery directory, or message relay exists. A workspace (a "Swarm Space") is identified entirely by a server's public key. Introduction is bootstrapped over public STUN servers, WebTorrent trackers, and the Mainline DHT.
- Process Isolation & Sandboxing: Renderers run with strict Chromium sandboxing (
sandbox: true,contextIsolation: true). The preload bridge exposes only validated methods and schema-checked JSON inputs. Heavy cryptographic and erasure-coding operations are offloaded to an independent Go Sidecar via stdio pipes. - P2P Swarm Isolation: Outpost enforces strict swarming boundaries. WebTorrent/WebRTC peer connections never mix swarms, and tracking IDs are domain-separated using derived hashes of the server's public key.
- Click-to-Load Assets: To protect users against drive-by exploits, files/media are never auto-downloaded. Instead, users are presented with interactive placeholders showing risk class, mime details, and metadata. Downloading only starts when a user clicks "Load".
- Discord-Parity UI & Themes: Clean, native Web Component implementation featuring an AMOLED Midnight theme, blurple accents, customizable themes (Midnight Tokyo, Catppuccin, Nord, Rose Pine, Dracula, Solarized), collapsible channels, user docks, and virtualized message timelines.
- Friends Ledger & Fingerprints: Manage contacts locally using a cryptographically validated, JSON-backed friends ledger. Add contacts securely using their raw fingerprint hex keys.
- Hypercore Ledger & Tombstones: Message histories are synchronized via append-only feeds. Deleted messages are verified using logical tombstone markers that return cleanly without interrupting client runtime.
- Dynamic Bandwidth Throttling: Live application of bandwidth throttling rules (from Data-Saver to Max tiers) directly mapping down to active WebTorrent engine parameters.
- Universal Search (Finder): Keyboard-driven search (
Ctrl+KorCmd+K) supporting fuzzy search indexing over servers, channels, direct messages, and contacts. - Group DMs & Calling: Set up ad-hoc DMs for up to 12 members. Initiate voice/video AV calling overlay panels, complete with adaptive quality controls, screensharing, device configurations, and SVGs calling state indicators.
- Progressive / Sequential Media: Watch streaming videos or listen to audio files progressively with out-of-order piece selection and dynamic range-request media playback.
- Go Sidecar Cryptography: Scans files for malware risk profiles, executes Reed-Solomon erasure sharding, and manages AES-256-GCM file-limbo encryption with M-of-N threshold Ed25519 moderator key releases.
- Sybil-Resistant Reputation: Direct-link warning mechanisms, shadowban scoring gates, and peer-to-peer reputation evidence accumulation.
- Mobile Companion Bridge: Desktop pairing token generation to sync activity and logs to companion devices via local network bridges and QR codes.
- Core: Electron, Node.js, Go (Sidecar utility)
- UI/UX: HTML5, Vanilla JavaScript Web Components, CSS Variables
- P2P Feeds: Hypercore v11
- Asset Transport: WebTorrent (BT DHT & Trackers)
- Real-time Sync: WebRTC (Data Channels)
- Testing: Vitest, Playwright E2E
-
Clone the repository:
git clone https://github.com/your-username/Outpost.git cd Outpost -
Install dependencies:
npm install
-
Build the Go Sidecar binary (auto-build runs during development, but can also be manually compiled):
cd sidecar go build -o cmd/outpost-sidecar/outpost-sidecar cd ..
To launch the desktop client in development mode:
npm run devTip
If you wish to query active GIF media grids via the Klipy search bar integration, configure your API key in your environment variables:
# Windows (PowerShell)
$env:KLIPY_API_KEY="your-klipy-api-key"
npm run devOutpost includes a complete verification suite covering both unit logic and browser E2E workflows:
- Run Unit Tests (Vitest):
npm run test - Run Integration & E2E Tests (Playwright):
npm run e2e
- Run ESLint Code Quality Checks:
npm run lint
This project is licensed under the ISC License. See the package.json file for details.