1
0
Fork 0
mirror of https://github.com/alangrainger/immich-public-proxy.git synced 2024-12-29 12:21:57 +00:00
immich-public-proxy/README.md

122 lines
4.9 KiB
Markdown
Raw Normal View History

2024-10-29 14:51:49 +00:00
# Immich Public Proxy
2024-10-29 18:57:44 +00:00
Share your Immich photos and albums in a safe way without exposing your Immich instance to the public.
2024-10-29 15:31:21 +00:00
<p align="center" width="100%">
<img src="public/images/immich.png" width="180" height="180">
</p>
2024-10-31 13:32:50 +00:00
### Table of Contents
2024-10-31 13:30:26 +00:00
2024-10-31 13:44:23 +00:00
- [Demo <img src="./public/images/external-link.png" width="14" height="14">](https://immich-demo.note.sx/share/ffSw63qnIYMtpmg0RNvOui0Dpio7BbxsObjvH8YZaobIjIAzl5n7zTX5d6EDHdOYEvo)
2024-10-31 13:31:17 +00:00
- [About this project](#about-this-project)
2024-10-31 13:30:26 +00:00
- [Install with Docker](#how-to-install-with-docker)
- [How it works](#how-it-works)
- [Additional configuration](#configuration)
- [Feature requests](#feature-requests)
## About this project
2024-10-29 14:51:49 +00:00
Immich is a wonderful bit of software, but since it holds all your private photos it's best to keep it fully locked down.
This presents a problem when you want to share a photo or a gallery with someone.
2024-10-30 10:25:36 +00:00
**Immich Public Proxy** provides a barrier of security between the public and Immich, and _only_ allows through requests
2024-10-29 14:51:49 +00:00
which you have publicly shared. When it receives a valid request, it talks to Immich locally via API and returns only
those shared images.
It exposes no ports, allows no incoming data, and has no API to exploit.
2024-10-31 06:53:56 +00:00
### Why not simply put Immich behind a reverse proxy and only expose the `/share/` path to the public?
To view a shared album in Immich, you need access to the `/api/` path. If you're sharing a gallery with the public, you need
2024-10-31 11:10:47 +00:00
to make that path public. Any existing or future vulnerability has the potential to compromise your Immich instance.
2024-10-31 06:53:56 +00:00
2024-10-31 11:10:47 +00:00
For me, the ideal setup is to have Immich secured privately behind mTLS or VPN, and only allow public access to Immich Public Proxy.
2024-10-31 12:03:33 +00:00
Here is an example setup for [securing Immich behind mTLS](./docs/securing-immich-with-mtls.md) using Caddy.
2024-10-29 19:00:41 +00:00
2024-10-30 10:25:36 +00:00
## How to install with Docker
2024-10-29 14:51:49 +00:00
2024-10-31 12:51:06 +00:00
1. Download the [docker-compose.yml](https://github.com/alangrainger/immich-public-proxy/blob/main/docker-compose.yml) file.
2024-10-29 14:51:49 +00:00
2024-10-31 13:03:53 +00:00
2. Create a `.env` file to configure the app:
2024-10-29 14:51:49 +00:00
```
IMMICH_URL=http://localhost:2283
2024-10-31 12:51:06 +00:00
PROXY_PUBLIC_URL=https://your-proxy-url.com
2024-10-29 18:57:44 +00:00
PORT=3000
2024-10-29 15:15:34 +00:00
CACHE_AGE=2592000
2024-10-29 14:51:49 +00:00
```
- `IMMICH_URL` is the URL to access Immich in your local network. This is not your public URL.
2024-10-31 12:51:06 +00:00
- `PROXY_PUBLIC_URL` is the public URL for your proxy.
- `PORT` is the external port you want for the docker container.
2024-10-30 10:25:36 +00:00
- `CACHE_AGE` this is setting the `cache-control` header, to tell the browser to cache the assets. Set to 0 to disable caching.
2024-10-29 14:51:49 +00:00
3. Start the docker container:
```bash
docker-compose up -d
```
2024-10-31 12:51:06 +00:00
4. Set the "External domain" in your Immich **Server Settings** to be the same as the `PROXY_PUBLIC_URL`:
2024-10-29 14:51:49 +00:00
2024-10-30 19:47:54 +00:00
<img src="public/images/server-settings.png" width="400" height="182">
2024-10-29 14:51:49 +00:00
2024-10-30 10:25:36 +00:00
Now whenever you share an image or gallery through Immich, it will automatically create the
2024-10-29 14:51:49 +00:00
correct public path for you.
2024-10-30 10:20:51 +00:00
2024-10-30 13:15:14 +00:00
## How it works
You share your photos/videos as normal through Immich. Because you have set the **External domain** in Immich settings
to be the URL for your proxy app, the links that Immich generates will automaticaly have the correct URL.
When the proxy receives a request, it will come as a link like this:
```
https://your-proxy-url.com/share/ffSw63qnIYMtpmg0RNvOui0Dpio7BbxsObjvH8YZaobIjIAzl5n7zTX5d6EDHdOYEvo
```
The part after `/share/` is Immich's shared link public ID (called the `key` [in the docs](https://immich.app/docs/api/get-my-shared-link)).
2024-10-30 13:15:14 +00:00
2024-10-31 06:53:56 +00:00
**Immich Public Proxy** takes that key and makes an API call to your Immich instance over your local network, to ask what
2024-10-30 13:15:14 +00:00
photos or videos are shared in that share URL.
2024-10-31 06:53:56 +00:00
If it is a valid share URL, the proxy fetches just those assets via local API and returns them to the visitor as an
2024-10-30 13:15:14 +00:00
individual image or gallery.
If the shared link has expired or any of the assets have been put in the Immich trash, it will not return those.
2024-10-30 13:15:14 +00:00
2024-10-30 10:20:51 +00:00
## Configuration
2024-10-30 10:31:00 +00:00
The gallery is created using [lightGallery](https://github.com/sachinchoolur/lightGallery). You can change various settings to change how your gallery displays by
2024-10-30 10:20:51 +00:00
updating the `lightGallery` section in `/views/gallery.ejs`:
```javascript
lightGallery(document.getElementById('lightgallery'), {
plugins: [lgZoom, lgThumbnail, lgVideo, lgFullscreen],
speed: 500
})
```
For example to disable the download button for images, you would add `download: false`:
```javascript
lightGallery(document.getElementById('lightgallery'), {
plugins: [lgZoom, lgThumbnail, lgVideo, lgFullscreen],
download: false,
speed: 500
})
```
2024-10-30 10:31:00 +00:00
You can find all of lightGallery's settings here:
2024-10-30 10:20:51 +00:00
https://www.lightgalleryjs.com/docs/settings/
2024-10-30 14:31:41 +00:00
## Feature requests
You can [add feature requests here](https://github.com/alangrainger/immich-public-proxy/discussions/categories/feature-requests?discussions_q=is%3Aopen+category%3A%22Feature+Requests%22+sort%3Atop),
2024-10-31 06:53:56 +00:00
however my goal with this project is to keep it as lean as possible.
2024-10-30 15:42:34 +00:00
Due to the sensitivity of data contained within Immich, I want anyone with a bit of coding knowledge
to be able to read this codebase and fully understand everything it is doing.