// Service worker: offline app shell + Web Push wake-up. // It never touches message plaintext — decryption happens only in the page. const CACHE = "cipher-v11"; const SHELL = [ "/", "/index.html", "/manifest.webmanifest", "/js/app.js", "/js/api.js", "/js/crypto.js", "/js/store.js", "/js/accounts.js", "/js/call.js", "/js/vendor/libsignal.js", "/js/vendor/qrcode.js", "/icons/icon.svg", ]; self.addEventListener("install", (e) => { e.waitUntil(caches.open(CACHE).then((c) => c.addAll(SHELL)).then(() => self.skipWaiting())); }); self.addEventListener("activate", (e) => { e.waitUntil( caches.keys().then((keys) => Promise.all(keys.filter((k) => k !== CACHE).map((k) => caches.delete(k))) ).then(() => self.clients.claim()) ); }); self.addEventListener("fetch", (e) => { const url = new URL(e.request.url); // Never cache API or WebSocket traffic. if (url.pathname.startsWith("/api/")) return; // Cache-first for the shell, network fallback. e.respondWith( caches.match(e.request).then((hit) => hit || fetch(e.request)) ); }); // Payloadless push: just wake the client, which pulls ciphertext over the socket. self.addEventListener("push", (e) => { e.waitUntil( self.registration.showNotification("Cipher", { body: "New encrypted message", icon: "/icons/icon.svg", badge: "/icons/icon.svg", tag: "cipher-msg", }) ); }); self.addEventListener("notificationclick", (e) => { e.notification.close(); e.waitUntil( self.clients.matchAll({ type: "window" }).then((cl) => { for (const c of cl) if ("focus" in c) return c.focus(); return self.clients.openWindow("/"); }) ); });