Skip to content
inilvinilraPublic

About

WhatNull - Open source, Linux-first, secure WhatsApp desktop client built with Rust (Tauri 2) and React

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

WhatNull

WhatNull is an open-source, Linux-first WhatsApp Web desktop client built with Rust (Tauri 2) and React + TypeScript.

It is not an Electron wrapper. The goal is a lightweight, resource-efficient shell with a strict boundary between the privileged local UI and the remote WhatsApp Web surface.

Status

WhatNull is at 0.1.0 and is pre-release. The table below reflects what is actually implemented, not what is planned.

Area State
Single-window shell, system tray, window state Working
Navigation filtering and external link routing Working
Multi-account profiles with isolated WebKit storage Working
Privacy blur on window unfocus Working
Content blur inside the page, until hovered Working
Metadata stripping for images, PDFs, video and audio Working, see limitations
Attachment interception for file picker, drag-drop and paste Working
Native desktop notifications with privacy levels Working
Passcode lock (PBKDF2-HMAC-SHA256) with idle auto-lock Working
Deleted-message preservation Opt-in, disabled by default
Local log of preserved messages Opt-in, disabled by default
Voice and video calls Not possible on WebKitGTK, see below

Voice and video calls

WhatNull cannot place calls, and this is not a missing feature that can be written. Tauri renders through WebKitGTK on Linux, and the WebKitGTK builds shipped by every distribution are compiled without ENABLE_WEB_RTC: getUserMedia works, so the microphone and camera open for voice messages, but RTCPeerConnection does not exist at all, so no peer connection can be established. This was measured directly in WebKitGTK's own MiniBrowser with --enable-webrtc=TRUE, and again inside the GNOME Flatpak runtime, with the same result. Clients that do offer calls (ZapZap, Whatsie) render through QtWebEngine, which bundles its own Chromium and its own WebRTC stack.

Everything the application side of calls needs is already implemented: media stream settings are enabled and camera, microphone and display-capture permission requests are answered separately from configuration. A WebKitGTK build with WebRTC enabled would make calls work with no further change here.

What screen-capture protection can and cannot do

No Linux compositor exposes a way for an application to exclude its own window from a screen recording or a screen share; the one that comes closest, Niri's block-out-from, has no equivalent in KWin, Mutter or i3. WhatNull therefore does not claim to hide itself from a capture. What it does instead is blur chat names, message text and media until you hover them, so that a shared screen or a shoulder cannot read your conversation while you keep using it normally. Turn it on in Settings → Privacy, or from the shield rail on the right edge of the page.

Design Goals

  • Low resource usage: minimal memory and CPU footprint.
  • Fast startup: short launch latency, single native window.
  • Linux integration: GNOME, KDE, Wayland, XDG paths, native packaging.
  • Webview isolation: the privileged local shell and the remote WhatsApp surface are separate webviews with separate capability sets.
  • Privacy first: no telemetry, no analytics, no crash reporting, no intermediary servers.

Security Boundary

WhatNull runs one native window containing two child webviews. The local shell webview holds the application capability set. The remote whatsapp webview is granted exactly three narrowly scoped commands and no others:

  • sanitize_upload_files — strips metadata from attachment bytes; takes and returns bytes only.
  • request_shell_action — asks the local shell to open its own UI or toggle a privacy setting; the action set is closed and every action is a non-destructive toggle.
  • record_preserved_message — appends one message to the local log; it only writes, and returns nothing the page can read.

See docs/SECURITY_MODEL.md and docs/WEBVIEW_SECURITY.md for details.

Build Requirements

  • Rust stable (1.70+)
  • Node.js 18+
  • WebKit2GTK and GTK3 development headers
  • ffmpeg for video and audio metadata stripping (optional)
  • libayatana-appindicator3 for the system tray (optional). Without it WhatNull starts normally, says so once on stderr, and treats "close to tray" as quit, because there would be no tray to restore the window from.

Arch:

sudo pacman -S webkit2gtk-4.1 gtk3 libayatana-appindicator ffmpeg

Debian and Ubuntu:

sudo apt install libgtk-3-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev

Fedora:

sudo dnf install gtk3-devel webkit2gtk4.1-devel libappindicator-gtk3-devel

Running

Install workspace dependencies from the repository root, then launch the desktop app:

npm install
npm run tauri dev

npm run dev starts only the Vite frontend server without the Tauri backend. Use it for isolated UI work; use npm run tauri dev to run the actual application.

Checks

cargo fmt --all -- --check
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace
npm run typecheck
npm run lint

Brand Disclaimer

WhatNull is an independent open-source project. It is not affiliated with, endorsed by, sponsored by, or officially connected to WhatsApp or Meta. No official WhatsApp logo or asset is used in this project.

License

MIT. See LICENSE.

About

WhatNull - Open source, Linux-first, secure WhatsApp desktop client built with Rust (Tauri 2) and React

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages