quarto-lock extension: password-protect static Quarto sites with client-side encryption
#14950
lsbjordao
started this conversation in
Show and Tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Description
Hi, everyone!
quarto-lockis a Quarto extension for protecting rendered websites and books on static hosting such as GitHub Pages.Instead of relying on server-side authentication, it encrypts the rendered output at build time and decrypts it in the browser only after the visitor enters a shared password.
It currently uses PBKDF2-HMAC-SHA-256 for key derivation and AES-256-GCM for authenticated encryption, and can protect not only HTML pages but also local CSS, JavaScript, images, fonts, search indexes, PDFs, ZIP files, and other rendered assets.
The intended use case is publishing private or semi-private static Quarto content where a full authentication backend would be unnecessary or impractical.
A particularly useful deployment pattern is:
The extension is intentionally a cryptographic lock, not an authentication system: there are no users, roles, MFA, password recovery, or server-side authorization, and password strength remains important because encrypted files can be downloaded and attacked offline.
Installation:
Project links:
quarto-lock-demoI’d be very interested in feedback from the Quarto community, especially about deployment patterns, static-site security trade-offs, and possible integration improvements.
All reactions