Customize the lock screen

quarto-lock is localizable. The default interface is English, but every user-facing string on the lock screen can be changed without editing the extension source.

Use a local .env

The repository includes .env.example. Copy it to .env in the root of your Quarto project:

cp .env.example .env

quarto-lock automatically reads .env when it runs. Regular environment variables and GitHub Actions variables/Secrets take precedence over values from .env.

The recommended .env is for local UI configuration only. The real shared password should still be supplied through your shell or a GitHub Actions Secret rather than committed to a file.

QUARTO_LOCK_LANG=en
QUARTO_LOCK_TITLE="Protected content"
QUARTO_LOCK_MESSAGE="Enter the password to unlock this content."
QUARTO_LOCK_PASSWORD_LABEL="Password"
QUARTO_LOCK_BUTTON_LABEL="Unlock"
QUARTO_LOCK_FOOTER="Protected by Quarto Lock"
QUARTO_LOCK_ERROR_INCORRECT="Incorrect password."
QUARTO_LOCK_ERROR_SECURE_CONTEXT="This site must be opened over HTTPS (or localhost)."

Then render your project normally:

export QUARTO_LOCK_PASSWORD='your-long-private-passphrase'
quarto render

To inspect the locked output locally, serve the rendered _site directly:

python3 -m http.server 3073 -d _site

Do not run quarto preview after the locked render, because an incremental preview render can recreate clear HTML in _site.

Example: Portuguese

QUARTO_LOCK_LANG=pt-BR
QUARTO_LOCK_TITLE="Área reservada"
QUARTO_LOCK_MESSAGE="Digite a senha para abrir este conteúdo."
QUARTO_LOCK_PASSWORD_LABEL="Senha"
QUARTO_LOCK_BUTTON_LABEL="Entrar"
QUARTO_LOCK_FOOTER="Protegido por Quarto Lock"
QUARTO_LOCK_ERROR_INCORRECT="Senha incorreta."
QUARTO_LOCK_ERROR_SECURE_CONTEXT="Este site precisa ser aberto por HTTPS (ou localhost)."

Example: Spanish

QUARTO_LOCK_LANG=es
QUARTO_LOCK_TITLE="Contenido protegido"
QUARTO_LOCK_MESSAGE="Introduce la contraseña para abrir este contenido."
QUARTO_LOCK_PASSWORD_LABEL="Contraseña"
QUARTO_LOCK_BUTTON_LABEL="Abrir"
QUARTO_LOCK_FOOTER="Protegido por Quarto Lock"
QUARTO_LOCK_ERROR_INCORRECT="Contraseña incorrecta."
QUARTO_LOCK_ERROR_SECURE_CONTEXT="Este sitio debe abrirse mediante HTTPS (o localhost)."

Use translated text in GitHub Actions

Because .env is intentionally ignored, it is not uploaded to GitHub. For deployment, put public UI strings directly in the workflow and keep only the password in a Secret:

jobs:
  build-deploy:
    runs-on: ubuntu-latest
    env:
      QUARTO_LOCK_PASSWORD: ${{ secrets.QUARTO_LOCK_PASSWORD }}
      QUARTO_LOCK_LANG: pt-BR
      QUARTO_LOCK_TITLE: "Área reservada"
      QUARTO_LOCK_MESSAGE: "Digite a senha para abrir este conteúdo."
      QUARTO_LOCK_PASSWORD_LABEL: "Senha"
      QUARTO_LOCK_BUTTON_LABEL: "Entrar"
      QUARTO_LOCK_FOOTER: "Protegido por Quarto Lock"
      QUARTO_LOCK_ERROR_INCORRECT: "Senha incorreta."
      QUARTO_LOCK_ERROR_SECURE_CONTEXT: "Este site precisa ser aberto por HTTPS (ou localhost)."

The UI strings are ordinary configuration and do not need to be Secrets. QUARTO_LOCK_PASSWORD is the value that must remain private.

Configuration precedence

When the same variable is defined in more than one place, quarto-lock uses this order:

  1. an existing environment variable, including GitHub Actions env values and Secrets;
  2. the local .env file;
  3. the built-in English default.

This lets local development use .env while production uses workflow variables and a GitHub Actions Secret for the password.

WarningDo not commit real passwords

.env is ignored by this repository on purpose. Commit .env.example to document the available settings, but keep QUARTO_LOCK_PASSWORD out of version control. For GitHub Actions, use Settings → Secrets and variables → Actions.