Files
Artifacto/README.md
claudio e74439b509 Auto-login from trusted reverse-proxy Authentik headers
When SSO_GATEWAY_SECRET is set and an incoming request carries both
X-Artifacto-Gateway (matching the secret) and X-Authentik-Username, the
admin middleware mints a session automatically so Authentik-authenticated
users skip the password form. Missing or wrong gateway header falls back
to the password-login flow, so peers that can reach the container
directly (bypassing the reverse proxy) cannot spoof Authentik identities.
2026-04-22 22:21:20 +02:00

1.9 KiB

Artifacto

Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share. Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.

Features

  • Paste or upload HTML, auto-generated slug (or custom)
  • Optional per-artifact password (bcrypt), rate-limited unlock
  • Optional expiration (time or view-count)
  • Admin dashboard with view counts, sparklines, per-artifact 30-day chart
  • Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
  • One container, one SQLite file, one data directory

Quick start

cp .env.example .env           # set ADMIN_PASSWORD + SESSION_SECRET
docker compose up -d
open http://localhost:3100

Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.

Configuration

Env var Default Purpose
ADMIN_PASSWORD — (required) Admin login password
SESSION_SECRET — (required, 32+ bytes hex) Cookie HMAC key
BASE_URL http://localhost:3000 Used when building share links
DATA_DIR /data SQLite DB + artifact files
BIND_ADDR :3000 Listen address
MAX_UPLOAD_MB 5 Per-artifact upload cap
LOG_LEVEL info info or debug
SSO_GATEWAY_SECRET Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching X-Artifacto-Gateway header

License

MIT