Skip to content

About

💻 Wire for desktop

Topics

Resources

Security policy

Stars

1.1k stars

Watchers

54 watching

Forks

Latest commit

 

History

6,154 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Wire™

Wire logo

This repository is part of the source code of Wire. You can find more information at wire.com or by contacting opensource@wire.com.

You can find the published source code at github.com/wireapp/wire.

For licensing information, see the attached LICENSE file and the list of third-party licenses at wire.com/legal/licenses/.

If you compile the open source software that we make available from time to time to develop your own mobile, desktop or web application, and cause that application to connect to our servers for any purposes, we refer to that resulting application as an “Open Source App”. All Open Source Apps are subject to, and may only be used and/or commercialized in accordance with, the Terms of Use applicable to the Wire Application, which can be found at https://wire.com/legal/#terms. Additionally, if you choose to build an Open Source App, certain restrictions apply, as follows:

a. You agree not to change the way the Open Source App connects and interacts with our servers; b. You agree not to weaken any of the security features of the Open Source App; c. You agree not to use our servers to store data for purposes other than the intended and original functionality of the Open Source App; d. You acknowledge that you are solely responsible for any and all updates to your Open Source App.

For clarity, if you compile the open source software that we make available from time to time to develop your own mobile, desktop or web application, and do not cause that application to connect to our servers for any purposes, then that application will not be deemed an Open Source App and the foregoing will not apply to that application.

No license is granted to the Wire trademark and its associated logos, all of which will continue to be owned exclusively by Wire Swiss GmbH. Any use of the Wire trademark and/or its associated logos is expressly prohibited without the express prior written consent of Wire Swiss GmbH.

Wire Desktop

Cross platform desktop app, wrapping the wire-webapp. Based on Electron.

Prerequisites

Install Dependencies

sudo apt install git npm nodejs
npm install --global yarn

Clone

git clone https://github.com/wireapp/wire-desktop.git
cd wire-desktop
yarn

Start

yarn start

Test

yarn test

Managed device configuration (MDM)

On company-managed devices, an MDM administrator can force App-lock on, overriding the team-level App-lock setting. The desktop app reads a single applockOverride flag at startup — without spawning any shell command — and forwards it to the webapp as window.desktopAppConfig.managedConfig.

The flag is read from organization-agnostic, Wire-vendor locations (no customer/company name is hardcoded):

OS Source Signal
Windows Registry …\SOFTWARE\Policies\Wire (HKLM, HKCU fallback) applockOverride value = 1, or the device is MDM-enrolled / Azure-AD joined
macOS App's managed preferences domain (MDM AppConfig profile) applockOverride boolean = true
Linux /etc/wire/managed.json {"applockOverride": true} (presence means managed unless explicitly false)

Testing locally

For each OS: plant the flag, relaunch the app, then open DevTools on the webapp's <webview> and evaluate window.desktopAppConfig.managedConfig — expect {applockOverride: true}. With nothing planted it must be {applockOverride: false} and the app behaves as before.

Windows (elevated prompt):

reg add "HKLM\SOFTWARE\Policies\Wire" /v applockOverride /t REG_DWORD /d 1 /f
:: relaunch app -> applockOverride === true
reg delete "HKLM\SOFTWARE\Policies\Wire" /f

Enrollment is detected automatically on an Intune/MDM-enrolled or Azure-AD-joined machine (no Policies\Wire value needed).

macOS (use the running build's bundle id — production is com.wearezeta.zclient.mac; dev/internal differ):

defaults write com.wearezeta.zclient.mac applockOverride -bool true
# relaunch app -> applockOverride === true
defaults delete com.wearezeta.zclient.mac applockOverride

To validate the real MDM path (managed-preferences domain):

sudo defaults write "/Library/Managed Preferences/com.wearezeta.zclient.mac.plist" applockOverride -bool true

Linux:

echo '{"applockOverride": true}' | sudo tee /etc/wire/managed.json
# relaunch app -> applockOverride === true
sudo rm /etc/wire/managed.json

Deployment

Stage Branch Action Version
1 (Feature development) (varies) commit x.y+3 (e.g. 3.20)
2 (Nightly test automation) dev commit or squash merge from feature branch x.y+2 (e.g. 3.19)
3 (Internal release) staging merge (don't squash) from dev x.y+1 (e.g. 3.18)
4 (Production release) main merge (don't squash) from staging x.y (e.g. 3.17)

Compare Views

  1. Updates from "dev" to "staging" (changelog): https://github.com/wireapp/wire-desktop/compare/staging...dev
  2. Updates from "staging" to "main" (changelog): https://github.com/wireapp/wire-desktop/compare/main...staging

Tasks

# Build for macOS
yarn build:macos

# Build for Windows
yarn build:win

# Build for Linux
yarn build:linux

On macOS, desktop SSO uses ASWebAuthenticationSession through the optional objc-js bridge. Authentication runs in a supporting default browser, with Safari as fallback. Windows and Linux retain embedded SSO; the standalone webapp is unchanged.

The macOS flow follows Wire iOS's existing backend contract: a validated callback returns a session cookie to the initiating account. Callback URLs and cookies must not be logged. This is not a single-use-code/PKCE exchange.

macOS packaging unpacks and signs the native bridge using the existing app-signing identity. Browser SSO does not require the former WebAuthn keychain-group entitlement or additional provisioning-profile credentials. Both Jenkins jobs use the configured node-v23.0.0 tool for the upgraded Electron runtime.

Embedded SSO windows support website window.prompt() requests through a local text dialog. This covers passkey labels requested by Keycloak and other providers using the same browser API, without changing the identity provider's theme. The dialog shows the requesting origin, returns entered text on OK and null on cancellation, and closes when the requesting page navigates or closes. Prompt messages and entered values are not logged. This addresses prompt compatibility; each provider's complete login flow still needs testing.

On Windows and Linux, SSO opens in an independent window using the shared persistent persist:wire-sso session. The backend completion callback is checked against the expected origin before copying its Wire login cookie into the requesting account. SSO website storage is cleared on close and before a new login, while passkey session preferences remain. Removing one sub-app/account does not remove this shared session. Reuse requires the same identity-provider account and relying-party ID; unrelated providers still need separate credentials. Deleting the entire desktop user-data directory or the credential in Keycloak is different. In a signed build, test registration, restart, account removal/re-addition, and login from another sub-app.

To test authentication, launch the signed app with --enable-logging and search its logs/YYYY-MM-DD/electron.log (inside Electron's user-data directory) for [Passkeys]. For macOS browser SSO, search for [SSO] to follow session startup, callback validation failures, and cookie installation. Browser authentication does not use the embedded account picker. For embedded WebAuthn, account-picker logs show requests, selection, cancellation, or failure without account names or credential IDs. An account-selection event only occurs when the authenticator needs a choice: its absence does not prove WebAuthn failed. Complete login against the intended identity provider to verify the result. Build checks do not establish authenticator compatibility; test the signed app against the intended IdP.

Other Linux targets

If you would like to build for another Linux target, run the following command:

export LINUX_TARGET=<target>
yarn build:linux

Replace <target> with your desired target (e.g. rpm). Have a look at the documentation for electron-builder for the available targets. Multiple targets can be combined by comma separation (e.g. rpm,deb). Note that we cannot offer support for uncommon targets.

Furthermore, you can disable asar packaging (not recommended, but e.g. needed for target dir) by setting ENABLE_ASAR="false" before building. Example:

export ENABLE_ASAR="false"
yarn build:linux

Troubleshooting

If you are having troubles building Wire for Desktop, then our troubleshooting page might be of help.

Translations

All Wire translations are crowdsourced via Crowdin.

Install wire-desktop under Linux

You can of course use the webapp in your browser, but if you prefer to install wire-desktop, continue reading here:

https://github.com/wireapp/wire-desktop/wiki/How-to-install-Wire-for-Desktop-on-Linux

About

💻 Wire for desktop

Topics

Resources

Security policy

Stars

1.1k stars

Watchers

54 watching

Forks

Releases

Used by

Contributors

Languages