Cloudshort

Configuration

Dashboard settings, the admin password, link rules, and the config files Cloudshort uses.

Settings

These are in the dashboard under Settings. Leave a field empty to turn it off.

SettingWhat it doesExample
Root URL RedirectWhere visitors go when they open the short domain with no slughttps://example.com
Short Link DomainThe domain the copy buttons usehttps://s.example.com
404 Fallback RedirectWhere visitors go when a slug does not exist. When empty, they see "Link not found".https://example.com/404

Every value must start with http:// or https://. Changes can take up to a minute to reach every Cloudflare location.

  • A slug is 1 to 64 characters: letters, numbers, ., -, and _. It cannot be only . or ...
  • Slugs are case sensitive: Launch and launch are different links.
  • A destination must start with http:// or https:// and be at most 2048 characters. Spaces around it are removed.
  • Redirects use status 302, so browsers do not cache them. A changed destination reaches new visitors within about a minute.

Admin password

The password is stored as the ADMIN_PASSWORD secret of the cloudshort-dashboard Pages project. To change it:

npx wrangler pages secret put ADMIN_PASSWORD --project-name cloudshort-dashboard
pnpm deploy:dashboard

The new password works after the deploy. Sessions that are already logged in stay logged in until they expire (24 hours).

To log everyone out right away, also replace JWT_SECRET with a new random value (for example the output of node -e "console.log(require('crypto').randomBytes(32).toString('hex'))") the same way, then deploy the dashboard.

Login lockout

After 5 wrong passwords from the same IP address, that address has to wait until 15 minutes have passed since its first wrong try. A correct login resets the count.

Config files

FileWhat it holds
apps/redirector/wrangler.tomlThe redirector's Worker name and the IDs of your KV namespace and D1 database
apps/dashboard/wrangler.tomlThe dashboard's Pages project name and the same two IDs
apps/dashboard/.dev.varsThe password and session secret for local development only

These files are made from the wrangler.example.toml and .dev.vars.example files next to them, and are not committed to git. pnpm run project:setup writes the two wrangler.toml files for you. Both must use the same KV and D1 IDs, so the dashboard writes where the redirector reads.