paul 2b5b875dfe
Test Gitea Actions / test (push) Successful in 20s
continuous-integration/drone/push Build is passing
fix(security): remove hardcoded JWT secret fallback - CRITICAL
BREAKING CHANGE: Server now requires JWT_SECRET environment variable to be set

Security fixes:
- Remove hardcoded JWT secret fallback 'your-secret-key' from protectedImages.js
- Add startup validation to ensure JWT_SECRET is properly configured
- Reject insecure default values and short secrets
- Server will refuse to start without proper JWT_SECRET

This fixes a critical vulnerability where the application would use a publicly
known secret if JWT_SECRET was not set, completely compromising authentication.

Migration guide: docs/JWT_SECRET_MIGRATION.md

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-12 23:33:22 +02:00
2025-07-03 16:27:04 +02:00
2025-07-03 16:26:50 +02:00
2025-07-03 16:25:53 +02:00
2025-07-11 08:30:07 +02:00

Photo Sharing Platform

A secure, self-hosted photo sharing platform designed for weddings and events. Features automatic expiration, email notifications, and simple file-based management.

Features

  • 🔒 Password Protected Galleries
  • Automatic Expiration
  • 📧 Email Notifications
  • 📁 Simple File Management
  • 📊 Analytics Integration
  • 🎨 Customizable Themes
  • 📱 Mobile Responsive
  • Docker Ready

Quick Start

  1. Clone the repository
  2. Run ./scripts/install.sh
  3. Configure .env file
  4. Setup SSL: ./scripts/setup-ssl.sh
  5. Start: docker-compose -f docker-compose.prod.yml up -d

Default credentials: admin / admin123 (change immediately!)

Documentation

See DEPLOYMENT.md for detailed deployment instructions.

License

MIT License

S
Description
Secure photo sharing platform for weddings and events with automatic expiration and email notifications
Readme MIT 48 MiB
2025-07-24 15:24:20 +02:00
Languages
JavaScript 49.5%
TypeScript 47.6%
Shell 2.2%
CSS 0.6%
Dockerfile 0.1%