mirror of
https://github.com/hugo-fixit/FixIt.git
synced 2026-08-24 15:28:57 +00:00
@hugo-fixit/post-encrypt
Post-build AES-256-GCM encryption tool for the FixIt Hugo theme.
Usage
After building your Hugo site, run the encryption tool from your site root:
npx @hugo-fixit/post-encrypt --input public
Options
| Option | Description | Default |
|---|---|---|
--input <dir> |
Input directory containing HTML files | public |
| `--dry-run | Show which files would be modified without writing | false |
| `--verify | Verify all encryption templates are encrypted | false |
Examples
# Encrypt content in the default public/ directory
npx @hugo-fixit/post-encrypt
# Encrypt content in a custom directory
npx @hugo-fixit/post-encrypt --input dist
# Verify encryption without modifying files
npx @hugo-fixit/post-encrypt --verify
# Dry run to see which files would be changed
npx @hugo-fixit/post-encrypt --dry-run
How It Works
- Scans all
.htmlfiles in the input directory - Finds
<template data-password="...">elements (encryption placeholders) - Encrypts the plaintext content using AES-256-GCM with PBKDF2 key derivation
- Replaces the
data-passwordhash with a PBKDF2-protected version - Writes the encrypted payload back to the template element
Security
- Algorithm: AES-256-GCM (authenticated encryption)
- Key derivation: PBKDF2 with 100,000 iterations and random 16-byte salt
- Password verification: PBKDF2-protected hash (not raw SHA-256)
- Payload format:
base64(salt).base64(iv).base64(ciphertext+tag)
License
MIT