Full Stack & Real-Time SecurityCompletedFeatured SystemJul 2025 – Dec 2025

NexaChat — End-to-End Encrypted Real-Time Messaging Platform

High-security real-time messaging platform engineered with Next.js 16, Express, Socket.io, MongoDB, and zero-knowledge client-side End-to-End Encryption (ECDH NIST P-256 + AES-GCM 256).

Demo Accounts & Test Credentials

2 Test Roles

Use these pre-configured accounts to test live features across different user roles without registering.

Open App to Login
Select Role to Test:Active: Encrypted Alice (Originator)
User ID / Email (Encrypted Alice (Originator))
Password
••••••••••••
Role Note:Generates client-side ECDH P-256 keypair in IndexedDB; derives shared AES-GCM-256 secret to send zero-knowledge encrypted messages.
NexaChat — End-to-End Encrypted Real-Time Messaging Platform

Technologies & Architecture Stack

Next.js 16 (App Router)React 19TypeScriptNode.jsExpress.jsSocket.ioMongoDBMongooseWeb Crypto API (SubtleCrypto)IndexedDBECDH (NIST P-256)AES-GCM (256-bit)Tailwind CSS v4Lucide ReactBcryptExpress-SessionMulter

Project Overview

NexaChat is an enterprise-grade, high-security real-time messaging platform engineered with Next.js 16 (App Router), React 19, TypeScript, and an Express.js / Socket.io backend. The platform provides true zero-knowledge privacy through browser-native End-to-End Encryption (E2EE) powered by the Web Crypto API (SubtleCrypto). Asymmetric key agreement using ECDH (NIST P-256) establishes ephemeral 256-bit AES-GCM symmetric session keys directly between communicating peers, guaranteeing that private keys never leave client-side IndexedDB vaults and the server never encounters unencrypted plaintext.

The Engineering Problem

Most modern web-based chat applications suffer from critical security and privacy flaws: 1. Server-Side Plaintext Exposure: Messages are either transmitted in plaintext over WebSockets or decrypted on the server before database insertion, exposing private user communications to database breaches, rogue server admins, or MITM interception. 2. Inefficient Crypto Dependencies: Third-party JavaScript crypto bundles add significant bundle bloat, lack side-channel resistance, and introduce supply-chain vulnerabilities. 3. Broken Real-Time Synchronization: Synchronizing message states (read receipts, delivery indicators, dynamic online presence, and message retraction) across concurrent mobile and desktop clients without causing UI race conditions or data loss is notoriously difficult. 4. Responsive Mobile Keyboard Layout Shifts: Dynamic virtual keyboards on iOS and Android frequently break viewport height calculations in standard CSS chat boxes.

The Solution

Architected a zero-knowledge real-time messaging system rooted in native browser cryptography and reactive WebSockets: 1. Zero-Knowledge E2EE Protocol: Integrated the native Web Crypto API (window.crypto.subtle) without third-party dependencies. Users generate ECDH NIST P-256 keypairs during registration; private keys are stored exclusively in IndexedDB (ChatApp_E2EE_Keys). Communicating clients derive identical 256-bit AES-GCM keys on the fly using ECDH shared secrets. 2. Fresh IV Randomization: Every individual message is encrypted with a cryptographically secure 12-byte initialization vector (crypto.getRandomValues), preventing replay attacks and ciphertext pattern frequency analysis. 3. Targeted Socket.io Rooms: Structured WebSocket connections into isolated private rooms (user_<id>), eliminating broadcast eavesdropping and ensuring messages are relayed strictly to authorized recipient sockets. 4. Delete-For-Everyone Lifecycle: Engineered real-time message revocation events (chatDeleted / chatMessageDeleted) that purge ciphertext from MongoDB while simultaneously commanding recipient DOM instances to unmount the decrypted bubble. 5. Keyboard-Aware Responsive Design: Utilized Tailwind CSS v4 and dynamic viewport units (100dvh) with touch-first single-pane/dual-pane adaptive breakpoints.

System Architecture & Data Flow

Client-Side Cryptographic Pipeline & Socket Routing: [Alice Browser (Next.js 16)] [Bob Browser (Next.js 16)] │ │ 1. Web Crypto API 1. Web Crypto API - ECDH P-256 Keypair - ECDH P-256 Keypair - PrivKey -> IndexedDB - PrivKey -> IndexedDB - PubKey -> Server - PubKey -> Server │ │ 2. Derives AES-GCM-256 2. Derives AES-GCM-256 (AlicePriv + BobPub) (BobPriv + AlicePub) │ │ 3. Encrypts with 12B IV 4. Decrypts with 12B IV │ ▲ ▼ │ [Socket.io Client] [Socket.io Client] │ │ ▼ (Ciphertext + IV) │ (Ciphertext + IV) ┌────────────────────────────────────────────────────────┴─────────┐ │ Express.js & Socket.io Server │ │ - Zero-Knowledge Routing (user_<id> Private Rooms) │ │ - Live Presence Detection (getOnlineUser / getOfflineUser) │ │ - MongoDB Atlas (Persists ONLY Base64 Ciphertext + IV) │ └──────────────────────────────────────────────────────────────────┘

Core Engineering Features

True End-to-End Encryption (E2EE) using Web Crypto API (SubtleCrypto) with zero external crypto dependencies.
Asymmetric Key Agreement with ECDH (NIST P-256) and authenticated symmetric encryption with AES-GCM (256-bit).
Non-exportable client-side private key storage in browser IndexedDB (ChatApp_E2EE_Keys).
Unique cryptographically random 12-byte initialization vectors (IVs) generated per message via crypto.getRandomValues.
Zero-Knowledge Server Architecture: Express server and MongoDB store strictly Base64 ciphertext and IVs.
Targeted private Socket.io rooms (user_<id>) ensuring point-to-point delivery without broadcast eavesdropping.
Real-Time presence indicators tracking dynamic online/offline connectivity status.
Instant Delete-for-Everyone functionality synchronizing message unmounting across active client viewports.
Mobile-First Responsive Interface: Adaptive single-pane view on smartphones (<768px) and dual-pane layout on desktop.
Keyboard-aware 100dvh viewport layout eliminating mobile layout shifting and virtual keyboard overlap.

Technical Challenges & Overcoming Them

Eliminating Server-Side Plaintext Exposure: Designed an asymmetric key exchange protocol using ECDH P-256 where the server only brokers public JWKs, never touching private keys or shared symmetric keys.
Preventing Replay and Pattern Analysis Attacks: Enforced per-message 12-byte IV generation with crypto.getRandomValues, ensuring identical plaintexts yield completely unique ciphertexts.
Managing Browser Key Persistence Without LocalStorage Vulnerabilities: Chose IndexedDB over localStorage to prevent XSS-based script access and support structured cloning of CryptoKey objects.
Eliminating Socket Eavesdropping in Shared Environments: Implemented isolated user rooms (user_<id>) authenticated on socket handshake, preventing unauthorized socket listeners from intercepting ciphertext.
Mobile Viewport Collapsing on Keyboard Open: Replaced standard 100vh with 100dvh dynamic viewport units and CSS touch-action controls to prevent virtual keyboard clipping on iOS Safari and Android Chrome.

Results & Impact

- Zero-Knowledge Message Architecture: 0 bytes of plaintext stored in MongoDB or handled by Node.js server memory. - Native Web Crypto Performance: Sub-2ms client-side encryption and decryption latency using browser-accelerated SubtleCrypto. - Sub-50ms Real-Time Delivery: Socket.io targeted room dispatch delivers encrypted packets to active recipients in <50ms. - 100% Mobile Responsiveness: Seamless transition between single-pane mobile contact view and desktop dual-pane messaging with 100dvh keyboard adaptation. - Ephemeral Key Security: Private keys stored in non-exportable IndexedDB domains with zero server exposure.

Key Takeaways

- Native Browser Cryptography: Deepened mastery of Web Crypto API, Diffie-Hellman key exchange protocols (ECDH P-256), and authenticated symmetric ciphers (AES-GCM 256). - WebSockets & Room Architecture: Learned best practices for stateful real-time bidirectional communication, connection recovery, and targeted user room isolation. - IndexedDB Persistence: Managed asynchronous browser-level key storage and retrieval pipelines without compromising UI responsiveness. - Modern Full-Stack Integration: Combined Next.js 16 App Router client components with a decoupled Express Socket.io backend using proxy rewrites and CORS session synchronization.

Future Roadmap

- Double Ratchet Algorithm: Upgrade E2EE to Signal's Double Ratchet protocol for post-compromise security and continuous session key rotation. - Encrypted Media & Voice Notes: Client-side chunked AES-GCM file encryption for photos, videos, and audio voice messages. - Multi-Device Synchronization: Secure cross-device private key import via QR code exchange. - WebRTC Peer-to-Peer Voice & Video Calling: End-to-end encrypted peer audio and video calls.