<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: darkdejavu</title>
    <description>The latest articles on DEV Community by darkdejavu (@darkdejavu_c9e45a9a42b579).</description>
    <link>https://dev.to/darkdejavu_c9e45a9a42b579</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4153924%2F78a19180-509a-4513-8937-5aab4e379939.png</url>
      <title>DEV Community: darkdejavu</title>
      <link>https://dev.to/darkdejavu_c9e45a9a42b579</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/darkdejavu_c9e45a9a42b579"/>
    <language>en</language>
    <item>
      <title>I built a chat app solo — rooms, voice/video calls, E2EE, and in-room games</title>
      <dc:creator>darkdejavu</dc:creator>
      <pubDate>Thu, 01 Oct 2026 07:20:53 +0000</pubDate>
      <link>https://dev.to/darkdejavu_c9e45a9a42b579/i-built-a-chat-app-solo-rooms-voicevideo-calls-e2ee-and-in-room-games-41fd</link>
      <guid>https://dev.to/darkdejavu_c9e45a9a42b579/i-built-a-chat-app-solo-rooms-voicevideo-calls-e2ee-and-in-room-games-41fd</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Foo9loau18deafth379n2.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Foo9loau18deafth379n2.jpg" alt=" " width="665" height="1280"&gt;&lt;/a&gt;&lt;br&gt;
I didn't want to build another messenger. There are plenty. What I wanted was a place where you walk into a room built around a shared interest — movies, music, gaming — and people are just... there, and you can start talking. No "add friend" ceremony, no app store install.&lt;/p&gt;

&lt;p&gt;That became PTT Chat (&lt;a href="https://pttchat.ru" rel="noopener noreferrer"&gt;pttchat.ru&lt;/a&gt;). I build and maintain it solo.&lt;/p&gt;

&lt;p&gt;A note up front: the UI is currently Russian-only. English localization is on the roadmap but not done. This post is for the architecture and the war stories — not an invitation to use the app in English today, though you're welcome to poke around.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's in it&lt;/strong&gt;&lt;br&gt;
Topic rooms: General, Newcomers, Movies &amp;amp; TV, Music, Gamers — plus user-created rooms, some password-protected&lt;br&gt;
Geo-channels: the app detects your city and spins up a room for it automatically if one doesn't exist yet&lt;br&gt;
1:1 and group voice/video calls&lt;br&gt;
E2E-encrypted DMs&lt;br&gt;
Two in-room games: Mafia, and an AI-generated guessing game&lt;br&gt;
An AI bot you can talk to in rooms&lt;br&gt;
Installable as a PWA — no App Store, no Google Play&lt;br&gt;
Login via Telegram, VK ID, email, or guest.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Architecture, briefly&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Everything runs through one Node.js process: Express for REST, Socket.io for realtime, SQLite (better-sqlite3, WAL mode) as the only datastore. No microservices. For this scale, one process is easier to reason about and debug than ten, and the honest ceiling is "when I need more than one instance" — which hasn't happened yet.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Mesh vs SFU&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For calls, I run two modes:&lt;br&gt;
Mesh: every participant connects directly to every other participant via WebRTC. Fine for 2–3 people — minimal latency, zero server load. Uplink cost grows quadratically with group size, though.&lt;br&gt;
SFU (mediasoup): each participant sends one stream to the server, which fans it out to everyone else. Flat uplink cost regardless of group size, at the cost of running media server infrastructure.&lt;/p&gt;

&lt;p&gt;The mode is set server-side at startup, not switched dynamically per call size — a deliberate simplicity trade-off I might revisit.&lt;/p&gt;

&lt;p&gt;The hard part wasn't group calls — it was calling one friend&lt;/p&gt;

&lt;p&gt;Group rooms are "easy": everyone's already in the same place. A 1:1 "call this specific friend" button turned out to be the most fiddly part of the whole project.&lt;/p&gt;

&lt;p&gt;You need to know: is the person mid-call with someone else, online but not answering, or just offline? Three different outcomes, three different notification paths. If they're offline, a push notification goes out. If they're online but silent for a few seconds, a push goes out too, in case the tab is backgrounded.&lt;/p&gt;

&lt;p&gt;Then there's handshake ordering: you can't fire a WebRTC offer the instant someone taps "accept" — their media stream isn't ready yet. The flow had to become "accepted → peer ready → now start the connection." Skip a step and the call either doesn't connect or connects silently with no audio.&lt;/p&gt;

&lt;p&gt;And occasionally a 1:1 call needs to become a group call mid-conversation, without dropping the existing connection.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Games in rooms&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Rooms can be flagged as "game rooms," which unlocks two features:&lt;br&gt;
Mafia: host-run lobby, minimum 4 players, private role assignment, alternating night/day phases with voting&lt;br&gt;
"Who am I?": an LLM generates a character, one player asks yes/no questions to guess who it is. Play solo and the AI answers your questions instead of a human.&lt;/p&gt;

&lt;p&gt;The tricky part wasn't the rules — it was disconnects. What happens when the host leaves mid-game? When the guesser closes the tab while waiting on an AI response? Each of those needed explicit handling or the round just hangs forever.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;E2EE — and what it doesn't give you&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;DMs are encrypted client-side: ECDH on P-256 for the shared secret, AES-GCM for messages. The private key is generated as non-extractable and lives in IndexedDB, so it can't be read out via JavaScript.&lt;/p&gt;

&lt;p&gt;I want to be upfront about the limits, because overselling crypto is worse than not having it:&lt;/p&gt;

&lt;p&gt;Keys are static. No ratchet, so no forward secrecy — if a key is ever compromised, past messages are compromised too.&lt;br&gt;
No key fingerprint verification. Public keys live server-side with no client-side defense against substitution.&lt;br&gt;
Public rooms aren't encrypted at all — the server sees everything there, and metadata (who talks to whom, when) is visible regardless.&lt;/p&gt;

&lt;p&gt;So it's protection against reading stored messages, not against a compromised server. A proper ratchet (Signal-style) is on the list, not something I'd implement from scratch myself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bugs that taught me something&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The homepage occasionally turned into a browser error page. One fallback branch in the service worker could resolve to undefined instead of a Response, which Chrome doesn't forgive — you get a hard network error instead of your app. It only reproduced with an empty cache and no network, which meant it almost never showed up on my dev machine with a warm cache. Lesson: every fallback path in a service worker has to guarantee a Response, full stop.&lt;/p&gt;

&lt;p&gt;A verification function existed and was never called. Found during review — the code looked complete, read like a complete auth check, and just... wasn't wired into the route that mattered. Nothing broke under normal use. It would only have mattered against a deliberately crafted request. That's the scary category of bug: invisible until someone looks for it on purpose.&lt;/p&gt;

&lt;p&gt;General takeaway: the bugs that bite are in the paths nobody manually tests, not in the happy path you click through every day.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's next:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Dynamic mesh/SFU switching based on participant count, instead of one mode for the whole server&lt;/li&gt;
&lt;li&gt;E2EE improvements: key fingerprint verification, key rotation, multi-device support&lt;/li&gt;
&lt;li&gt;Scaling beyond a single instance: moving off SQLite for storage, Redis adapter for sockets&lt;/li&gt;
&lt;li&gt;English UI, if there's enough interest&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you poke around and hit something confusing (especially the Russian-only UI), I'd genuinely like to hear about it. &lt;a href="https://pttchat.ru" rel="noopener noreferrer"&gt;pttchat.ru&lt;/a&gt;&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>webrtc</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
