9e3443079fc0b43edf45ce41d44c02bc6ce09def
Splits /p/{slug} into a trusted wrapper (HTML with a sandboxed iframe)
and /p/{slug}/raw (the artifact itself, served with Content-Security-Policy:
sandbox). Artifact JS now runs in an opaque origin and can't read admin
cookies or make same-origin credentialed requests to /a/* or /api/*.
Password gating is enforced on both routes so /raw can't be used to bypass
the unlock flow.
Artifacto
Self-hosted drop-and-share for HTML artifacts. Paste HTML → get a link → share. Single-binary Go service, SQLite metadata, HTML bodies on disk, behind a reverse proxy.
Features
- Paste or upload HTML, auto-generated slug (or custom)
- Optional per-artifact password (bcrypt), rate-limited unlock
- Optional expiration (time or view-count)
- Admin dashboard with view counts, sparklines, per-artifact 30-day chart
- Privacy-preserving visitor hash (daily-rotated salt, no cookies on viewers)
- One container, one SQLite file, one data directory
Quick start
cp .env.example .env # set ADMIN_PASSWORD + SESSION_SECRET
docker compose up -d
open http://localhost:3100
Then put a reverse proxy (Caddy, nginx, Traefik) in front for HTTPS.
Configuration
| Env var | Default | Purpose |
|---|---|---|
ADMIN_PASSWORD |
— (required) | Admin login password |
SESSION_SECRET |
— (required, 32+ bytes hex) | Cookie HMAC key |
BASE_URL |
http://localhost:3000 |
Used when building share links |
DATA_DIR |
/data |
SQLite DB + artifact files |
BIND_ADDR |
:3000 |
Listen address |
MAX_UPLOAD_MB |
5 |
Per-artifact upload cap |
LOG_LEVEL |
info |
info or debug |
SSO_GATEWAY_SECRET |
— | Optional: enables auto-login from a trusted reverse proxy forwarding Authentik headers plus a matching X-Artifacto-Gateway header |
License
MIT
Description
Languages
Go
66.8%
HTML
31.6%
Dockerfile
0.9%
Makefile
0.7%