dtoro 9e3443079f Sandbox artifact rendering via iframe + CSP
Splits /p/{slug} into a trusted wrapper (HTML with a sandboxed iframe)
and /p/{slug}/raw (the artifact itself, served with Content-Security-Policy:
sandbox). Artifact JS now runs in an opaque origin and can't read admin
cookies or make same-origin credentialed requests to /a/* or /api/*.
Password gating is enforced on both routes so /raw can't be used to bypass
the unlock flow.
2026-04-23 13:59:50 +02:00
2026-04-22 15:45:57 +02:00
2026-04-22 15:45:57 +02:00
2026-04-22 15:45:57 +02:00
2026-04-22 15:45:57 +02:00

Artifacto

Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share. Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.

Features

  • Paste or upload HTML, auto-generated slug (or custom)
  • Optional per-artifact password (bcrypt), rate-limited unlock
  • Optional expiration (time or view-count)
  • Admin dashboard with view counts, sparklines, per-artifact 30-day chart
  • Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
  • One container, one SQLite file, one data directory

Quick start

cp .env.example .env           # set ADMIN_PASSWORD + SESSION_SECRET
docker compose up -d
open http://localhost:3100

Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.

Configuration

Env var Default Purpose
ADMIN_PASSWORD — (required) Admin login password
SESSION_SECRET — (required, 32+ bytes hex) Cookie HMAC key
BASE_URL http://localhost:3000 Used when building share links
DATA_DIR /data SQLite DB + artifact files
BIND_ADDR :3000 Listen address
MAX_UPLOAD_MB 5 Per-artifact upload cap
LOG_LEVEL info info or debug
SSO_GATEWAY_SECRET Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching X-Artifacto-Gateway header

License

MIT

Description
No description provided
Readme 376 KiB
Languages
Go 66.8%
HTML 31.6%
Dockerfile 0.9%
Makefile 0.7%