Sign inSign up

samuelstreets/encrypted-share

By samuelstreets

•Updated about 1 month ago

Image
0

1.0K

samuelstreets/encrypted-share repository overview

⁠Emerald Password Share

Secure, self-destructing encrypted note and file sharing for The Emerald Group. Inspired by cryptgeon⁠ by @cupcakearmy⁠.

⁠Stack

LayerTech
BackendPython 3.13 + FastAPI + Uvicorn
StorageRedis 7 (in-memory, no disk)
FrontendSingle static index.html
CryptoAES-GCM-256 via browser WebCrypto

⁠How it works

  1. A note is encrypted in the browser with AES-GCM-256 before being sent anywhere.
  2. The server receives only ciphertext — it is cryptographically incapable of reading note contents.
  3. The encryption key lives only in the URL fragment (#key), which is never sent to the server.
  4. Notes self-destruct after N views or a time limit. Redis TTL enforces time expiry automatically.
  5. View-based expiry uses an atomic Lua script in Redis (read + decrement/delete in one step).

⁠Docker Image

The application is published as a Docker image on Docker Hub:

samuelstreets/encrypted-share:latest
⁠Quick start with Docker Compose

Copy the docker-compose.yaml below and run:

docker compose up -d

App runs at http://localhost:8001⁠

Note: An SSL/TLS certificate is required to generate notes (WebCrypto requires a secure context).

⁠docker-compose.yaml
services:
  redis:
    image: redis:7-alpine
    command: redis-server --save "" --appendonly no
    tmpfs:
      - /data
    restart: unless-stopped

  app:
    image: samuelstreets/encrypted-share:latest
    depends_on:
      - redis
    environment:
      REDIS: redis://redis/
      SIZE_LIMIT_BYTES: "83886080"   # 80 MiB
      MAX_VIEWS: "100"
      MAX_EXPIRATION: "360"          # minutes (6 hours)
      ALLOW_ADVANCED: "true"
      ALLOW_FILES: "true"
      VERBOSITY: "INFO"
      RATE_LIMIT_CREATE: "20"
      RATE_LIMIT_READ: "60"
    ports:
      - "8001:8000"
    restart: unless-stopped
⁠Building the image yourself
# Build locally
docker build -t encrypted-share:latest .

# Rebuild and restart via Compose
docker compose up --build -d

The GitHub Actions workflow in .github/workflows/docker-image.yml automatically builds and pushes multi-arch images (linux/amd64, linux/arm64) to Docker Hub on every push to main.

⁠Environment variables

VariableDefaultDescription
REDISredis://redis/Redis connection URL
SIZE_LIMIT_BYTES83886080 (80 MiB)Max note payload size
MAX_VIEWS100Max allowed views per note
MAX_EXPIRATION360Max expiration in minutes
ALLOW_ADVANCEDtrueAllow advanced options
ALLOW_FILEStrueAllow file uploads
VERBOSITYINFOLog level
RATE_LIMIT_CREATE20Max note creations per minute/IP
RATE_LIMIT_READ60Max note reads per minute/IP
THEME_IMAGEEmerald logo URLLogo image URL
THEME_PAGE_TITLEEmerald Password ShareBrowser tab title
THEME_FAVICONEmerald favicon URLFavicon URL
THEME_TEXT(empty)Custom intro text (HTML)
IMPRINT_URL(empty)Imprint/legal page URL
IMPRINT_HTML(empty)Imprint/legal HTML content

Tag summary

Content type

Image

Digest

sha256:b5afd0a28…

Size

28.4 MB

Last updated

about 1 month ago

docker pull samuelstreets/encrypted-share