So, given that this is a proof-of-concept, my advice is to back off on the web app part of this, and develop an installable client.
So, given that this is a proof-of-concept, my advice is to back off on the web app part of this, and develop an installable client.
[1] That's specifically for Node, but it could be tweaked to work in browsers.
This idea comes up a lot, and nobody's ever explained to me a workable method for doing an integrity check of the entire Javascript runtime associated with a specific site. It's not as easy to do as it sounds.
The cheapest browser-app integrity check that I know of is shipping the dev code, complete with source maps. Allow anyone to read and debug what is going on inside your app.
See? "Fun" problem.
It will speed up the whole encryption/decryption progress too.
I install git server, I add a person's public key to authorized_keys to allow him to git checkout/clone, and I keep committing with my own username and push whenever I want to update.
Is this similar to what you are trying to do?
You could do a Chrome extension with all the frontend code baked into the extension's static JavaScript. Firefox still has no sandboxing for add-ons, so you wouldn't have luck there.
Desktop / installed apps would be the way to go. See https://turtl.it for an example of this (shameless plug)
http://substack.net/offline_decentralized_single_sign_on_in_...
Edit: This article describes a solution that uses an appcache manifest with a far-future max-age that stops the browser from refetching the application code. It then uses an alternative mechanism to load updates presumably with a future option capable of verifying the legitimacy of the code with some sort of public key infrastructure ala Microsoft's Authenticode.