When SSO_GATEWAY_SECRET is set and an incoming request carries both X-Artifacto-Gateway (matching the secret) and X-Authentik-Username, the admin middleware mints a session automatically so Authentik-authenticated users skip the password form. Missing or wrong gateway header falls back to the password-login flow, so peers that can reach the container directly (bypassing the reverse proxy) cannot spoof Authentik identities.
41 lines
1.9 KiB
Markdown
41 lines
1.9 KiB
Markdown
# Artifacto
|
|
|
|
Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share.
|
|
Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.
|
|
|
|
## Features
|
|
|
|
- Paste or upload HTML, auto-generated slug (or custom)
|
|
- Optional per-artifact password (bcrypt), rate-limited unlock
|
|
- Optional expiration (time or view-count)
|
|
- Admin dashboard with view counts, sparklines, per-artifact 30-day chart
|
|
- Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
|
|
- One container, one SQLite file, one data directory
|
|
|
|
## Quick start
|
|
|
|
```bash
|
|
cp .env.example .env # set ADMIN_PASSWORD + SESSION_SECRET
|
|
docker compose up -d
|
|
open http://localhost:3100
|
|
```
|
|
|
|
Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.
|
|
|
|
## Configuration
|
|
|
|
| Env var | Default | Purpose |
|
|
|------------------|--------------------------------------|-------------------------------------|
|
|
| `ADMIN_PASSWORD` | — (required) | Admin login password |
|
|
| `SESSION_SECRET` | — (required, 32+ bytes hex) | Cookie HMAC key |
|
|
| `BASE_URL` | `http://localhost:3000` | Used when building share links |
|
|
| `DATA_DIR` | `/data` | SQLite DB + artifact files |
|
|
| `BIND_ADDR` | `:3000` | Listen address |
|
|
| `MAX_UPLOAD_MB` | `5` | Per-artifact upload cap |
|
|
| `LOG_LEVEL` | `info` | `info` or `debug` |
|
|
| `SSO_GATEWAY_SECRET` | — | Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching `X-Artifacto-Gateway` header |
|
|
|
|
## License
|
|
|
|
MIT
|