{"id":13674289,"url":"https://github.com/smallwat3r/shhh","last_synced_at":"2026-01-22T23:53:45.619Z","repository":{"id":38814321,"uuid":"209153501","full_name":"smallwat3r/shhh","owner":"smallwat3r","description":"Share sensitive info without leaving a trace in your chat logs or email accounts.","archived":false,"fork":false,"pushed_at":"2024-04-12T21:40:39.000Z","size":26158,"stargazers_count":361,"open_issues_count":1,"forks_count":31,"subscribers_count":11,"default_branch":"master","last_synced_at":"2024-04-13T05:26:26.400Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/smallwat3r.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2019-09-17T20:46:53.000Z","updated_at":"2024-04-15T13:06:18.646Z","dependencies_parsed_at":"2023-09-23T06:55:46.108Z","dependency_job_id":"57e44259-1418-4a33-ab80-8162ee7a9c33","html_url":"https://github.com/smallwat3r/shhh","commit_stats":null,"previous_names":[],"tags_count":31,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallwat3r%2Fshhh","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallwat3r%2Fshhh/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallwat3r%2Fshhh/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallwat3r%2Fshhh/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/smallwat3r","download_url":"https://codeload.github.com/smallwat3r/shhh/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247369952,"owners_count":20927928,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T11:00:44.965Z","updated_at":"2026-01-22T23:53:45.613Z","avatar_url":"https://github.com/smallwat3r.png","language":"Python","funding_links":["https://www.buymeacoffee.com/smallwat3r"],"categories":["Software","Python","others"],"sub_categories":["Communication - Custom Communication Systems"],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg width=\"100px\" src=\"https://github.com/smallwat3r/shhh/blob/master/shhh/static/img/logo.png\" /\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003eKeep secrets out of emails and chat logs.\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://codecov.io/gh/smallwat3r/shhh\" rel=\"nofollow\"\u003e\u003cimg src=\"https://codecov.io/gh/smallwat3r/shhh/branch/master/graph/badge.svg\" style=\"max-width:100%;\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://codeclimate.com/github/smallwat3r/shhh/maintainability\" rel=\"nofollow\"\u003e\u003cimg src=\"https://api.codeclimate.com/v1/badges/f7c33b1403dd719407c8/maintainability\" style=\"max-width:100%;\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/smallwat3r/shhh/blob/master/LICENSE\" rel=\"nofollow\"\u003e\u003cimg src=\"https://img.shields.io/badge/License-MIT-green.svg\" style=\"max-width:100%;\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n## Sunsetting...\n\nThis project is being sunset in favor of [secretapi](https://github.com/smallwat3r/secretapi), \nwhich offers a more streamline approach to achieving the same functionality as shhh.\n\n## What is it?\n\n**Shhh** is a tiny Flask app to create encrypted secrets and share \nthem securely with people. The goal of this application is to get rid\nof plain text sensitive information into emails or chat logs.\n\nShhh is deployed [here](https://www.shhh-encrypt.com) (_temporary unavailable\nuntil new deployment solution_), but **it's better for organisations and people \nto deploy it on their own personal / private server** for even better security. \nYou can find in this repo everything you need to host the app yourself.\n\nOr you can **one-click deploy to Heroku** using the below button.\nIt will generate a fully configured private instance of Shhh \nimmediately (using your own server running Flask behind Gunicorn and Nginx, \nand your own PostgreSQL database). You can see the Heroku configuration files [here](https://github.com/smallwat3r/shhh-heroku-deploy/tree/main).\n\n[![Deploy][heroku-shield]][heroku] (see [here](#initiate-the-database-tables) to \ninitiate the db tables after deploying on Heroku)\n\nAlso, checkout [shhh-cli](https://github.com/smallwat3r/shhh-cli), \na Go client to interact with the Shhh API from the command line.\n\n## How does it work?\n\nThe sender has to set an expiration date along with a passphrase to\nprotect the information he wants to share.\n\nA unique link is generated by Shhh that the sender can share with the\nreceiver in an email, alongside the temporary passphrase he created\nin order to reveal the secret.\n\nThe secret will be **permanently removed** from the database as soon \nas one of these events happens:\n\n* the expiration date has passed. \n* the receiver has decrypted the message. \n* the amount of tries to open the secret has exceeded. \n\nThe secrets are encrypted in order to make the data anonymous, \nespecially in the database, and the passphrases are not stored \nanywhere.\n\n_Encryption method used: Fernet with password, random salt value and\nstrong iteration count (100 000)._ \n\n_Tip: for better security, avoid writing any info on how/where to use the secret you're sharing (like urls, websites or emails). Instead, explain this in your email or chat, with the link and passphrase generated from Shhh. So even if someone got access to your secret, there is no way for the attacker to know how and where to use it._\n\n## Is there an API?\n\nYes, you can find some doc [here](https://app.swaggerhub.com/apis-docs/smallwat3r/shhh-api/1.0.0).\n\n## How to launch Shhh?\n\nThese instructions are for development purpose only. For production \nuse you might want to use a more secure configuration.\n\n#### Deps\n\nThe application will use the development env variables from [/environments/dev-docker-postgres.env](https://github.com/smallwat3r/shhh/blob/master/environments/dev-docker-postgres.env).\n\n#### Docker\n\nFrom the root of the repository, run\n\n```sh\nmake dc-start          # to start the app \nmake dc-start-adminer  # to start the app with adminer (SQL editor)\nmake dc-stop           # to stop the app\n```\n\nOnce the container image has finished building and has started, you \ncan access: \n\n* Shhh at \u003chttp://localhost:8081\u003e\n* Adminer at \u003chttp://localhost:8082\u003e (if launched with `dc-start-adminer`)\n\n_You can find the development database credentials from the env file at [/environments/dev-docker-postgres.env](https://github.com/smallwat3r/shhh/blob/master/environments/dev-docker-postgres.env)._\n\nYou have also the option to use `MySQL` instead of `PostgreSQL`, using these commands:\n```sh\nmake dc-start-mysql          # to start the app\nmake dc-start-adminer-mysql  # to start the app with adminer (SQL editor)\nmake dc-stop-mysql           # to stop the app\n```\n\n#### Migrations\n\nRun the migrations using:\n``` sh\nmake db c='upgrade'\n```\n\nIf deployed on Heroku, you can run the migrations using:\n``` sh\nheroku run --app=\u003cheroku-app-name\u003e python3 -m flask db upgrade\n```\n\nThis will ensure the necessary tables are created and up-to-date in the database, \nand make sure your deployed Shhh application works as expected.\n\nYou can write a revision using:\n``` sh\nmake db c='revision \"my revision\"'\n```\n\n#### Development tools\n\nYou can run tests and linting / security reports using the Makefile.\n\nMake sure you have `make`, `docker`, `yarn`, and a version of Python 3.12 installed on your machine.\n\nTests, linting, security tools do not run from the Docker container, so you need to have a Python\nvirtual environment configured locally.\n\nYou can do so with the following command:\n``` sh\nmake venv deps\n```\n\nThe following command will display all the commands available from the Makefile:\n``` sh\nmake help\n```\n\n* Enter a Flask shell (from the running shhh container)\n  ``` sh\n  make shell \n  ```\n\n* Run sanity checks\n  ```sh\n  make tests   # run tests\n  make ruff    # run Ruff report\n  make bandit  # run Bandit report\n  make mypy    # run Mypy report\n  ```\n\n* Run code formatter\n  ```sh\n  make yapf    # format code using Yapf\n  ```\n\n* Generate frontend lockfile\n  ```sh\n  make yarn    # install the frontend deps using Yarn\n  ```\n\n## Environment variables\n\nBellow is the list of environment variables used by Shhh.\n\n#### Mandatory\n* `FLASK_ENV`: the environment config to load (`testing`, `dev-local`, `dev-docker`, `heroku`, `production`).\n* `DB_HOST`: Database hostname\n* `DB_USER`: Database username\n* `DB_PASSWORD`: Database password\n* `DB_NAME`: Database name\n* `DB_ENGINE`: Database engine to use (ex: `postgresql+psycopg2`, `mysql+pymysql`)\n\nDepending if you can use PostgreSQL or MySQL you might also need to set (these need to match the values\nyou've specified as `DB_NAME`, `DB_PASSWORD` and `DB_NAME` above):\n\n* `POSTGRES_USER`: Postgresql username\n* `POSTGRES_PASSWORD`: Postgresql password\n* `POSTGRES_DB`: Postgresql database name\n\nor\n\n* `MYSQL_USER`: MySQL username\n* `MYSQL_PASSWORD`: MySQL password\n* `MYSQL_DATABASE`: MySQL database name\n\n#### Optional\n* `SHHH_HOST`: This variable can be used to specify a custom hostname to use as the\ndomain URL when Shhh creates a secret (ex: `https://\u003cdomain-name.com\u003e`). If not set, the hostname \ndefaults to request.url_root, which should be fine in most cases.\n* `SHHH_SECRET_MAX_LENGTH`: This variable manages how long the secrets your share with Shhh can \nbe. It defaults to 250 characters.\n* `SHHH_DB_LIVENESS_RETRY_COUNT`: This variable manages the number of tries to reach the database \nbefore performing a read or write operation. It could happens that the database is not reachable or is \nasleep (for instance this happens often on Heroku free plans). The default retry number is 5.\n* `SHHH_DB_LIVENESS_SLEEP_INTERVAL`: This variable manages the interval in seconds between the database\nliveness retries. The default value is 1 second.\n\n## License\n\nSee [LICENSE](https://github.com/smallwat3r/shhh/blob/master/LICENSE) file.\n\n## Contact\n\nPlease report issues or questions \n[here](https://github.com/smallwat3r/shhh/issues).\n\n\n[![Buy me a coffee][buymeacoffee-shield]][buymeacoffee]\n\n\n[buymeacoffee-shield]: https://www.buymeacoffee.com/assets/img/guidelines/download-assets-sm-2.svg\n[buymeacoffee]: https://www.buymeacoffee.com/smallwat3r\n\n[heroku-shield]: https://www.herokucdn.com/deploy/button.svg\n[heroku]: https://heroku.com/deploy?template=https://github.com/smallwat3r/shhh-heroku-deploy\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallwat3r%2Fshhh","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsmallwat3r%2Fshhh","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallwat3r%2Fshhh/lists"}