Password-protect a staging site
Keep work in progress away from strangers and search engines: a password on the link, or a list of the only people who may open it.
Updated
A staging site is usually public. Anyone who has the address can open it, addresses get forwarded, and a search engine that finds it may list pages that aren't ready. For client work, you want a lock on it.
The usual ways
- Basic auth on your server, set up in its configuration with a file of usernames and passwords. Visitors get the browser's plain sign-in box, which asks for a username too and has no way to sign out.
- A login in the site itself. It works, but it's code you write and keep up only for staging, and it changes the site you're testing.
- A secret address. Anyone who has it can open it, and addresses travel in forwarded emails, chat previews and browser histories.
With ouicu, the lock is on the link. Your site doesn't change, and there is no server to configure. It works the same for a dev server shared from your laptop and for a build you uploaded.
Before you start
On macOS and Linux, install the command line tool with:
curl -fsSL https://ouicu.com/install.sh | shOn Windows, run this in PowerShell:
irm https://ouicu.com/install.ps1 | iexThen log in. It opens ouicu.com in your browser, where you approve this computer:
ouicu loginYou need a ouicu account to log in. ouicu is in a closed beta, so accounts are for people we have invited: write to [email protected] to join.
Passwords come with Hobby and Pro, and invite lists with Pro. ouicu whoami shows your plan.
A password on a share or an upload (Hobby and Pro)
ouicu share 3000 --passwordouicu deploy ./dist --passwordYou type the password twice, and it isn't shown. In scripts and CI, set OUICU_PASSWORD instead, and ouicu reads it from there:
OUICU_PASSWORD="$PREVIEW_PASSWORD" ouicu deploy ./dist --passwordVisitors see a page from ouicu asking for the password, not the browser's sign-in box. Once they type it, that browser stays in for 7 days. Passwords are 8 to 200 characters, ouicu keeps only a hash of them, and wrong tries are slowed down so a password can't be guessed by trying many.
A share's password lasts as long as the share. An upload's lasts until its next upload, so give each upload --password, or put the password on the name.
One password for everything under a name (Hobby and Pro)
A reserved name can carry the password. On the Shares page, open “Change who can open it” by the name and set it there. Every share and upload under the name then asks for it, unless it brings its own. Change the password and everyone is asked again.
This suits a client you show work to every week: one password, which each of their browsers asks for once a week at most.
Only the people you invite (Pro)
Instead of a password everyone shares, list the people who may open the link:
ouicu share 3000 --allow [email protected],[email protected]@acme.com lets in everyone with an address at that domain. A list holds up to 50 entries, and your own address can always open your links. What your visitor does:
- They open the link, and ouicu asks for their email address.
- If the address is on your list, ouicu emails them a link. The page says the same either way, so it tells a stranger nothing.
- The link in the email works for 24 hours. It opens the preview in that browser for 7 days.
They need no account and have nothing to remember. A list can sit on a reserved name too, on the Shares page. To shut someone out, take them off it there: everyone is asked for their address again, so the person you removed is out straight away.
A share or an upload takes --password or --allow, not both.
Out of search results
Every page at a ouicu.app address is sent with X-Robots-Tag: noindex, nofollow, which asks search engines not to list it or follow its links. Behind a password or an invite list, there is nothing for them to read anyway. On a custom domain of yours, ouicu leaves that to your site.
Which to choose
| Who gets in | Plans | |
|---|---|---|
| Anyone with the link | Everyone who has it | All |
| A password | Everyone who has the link and the password | Hobby and Pro |
| Invited people | Only the addresses you list | Pro |
A password is quickest for a small team who can share one. An invite list is better when you want to know who opened it, or to let people go one at a time: on Hobby and Pro, your visitor emails name the invited people who opened the link.