Skip to content

studio2201/scan

Repository files navigation

Scan

Interactive self-hosted minesweeper arcade and tactical sector scanner written in Rust.


Instant One-Line Install (Docker Container)

Run the official zero-dependency container on port 4505:

docker run -d --name scan -p 4505:4505 -v /mnt/user/appdata/scan:/config ghcr.io/studio2201/scan:latest

Open your browser to http://localhost:4505 to start scanning sectors immediately.


One-Line Install (Native Package Manager)

On Debian, Ubuntu, Fedora, or RHEL:

curl -fsSL https://studio2201.github.io/packages/install.sh | sudo bash

Unraid NAS Deployment

Deploy via the official Unraid Template:

  1. Copy scan.xml to your Unraid flash drive under /boot/config/plugins/dockerMan/templates-user/.
  2. Open Docker -> Add Container -> Select scan from the template dropdown.
  3. Click Apply.

Environment Configuration

The backend service can be customized using the following environment variables:

Variable Description Default
PORT Network port the web server binds to 4505
SCAN_PIN Security PIN required for application access (Disabled)
SCAN_DATA_DIR Directory path for persistent data and high scores /config
SCAN_ALLOWED_ORIGINS CORS allowed origins list (comma-separated) *
TRUST_PROXY Honor reverse proxy headers (X-Forwarded-For) false
TRUSTED_PROXY_IPS Comma-separated CIDR list of trusted reverse proxies (None)
LOG_LEVEL Tracing filter (error, warn, info, debug) info

Administration CLI & TUI Dashboard

Every container and package includes a built-in administration utility (scan).

Launch interactive TUI dashboard:

docker exec -it scan scan tui

System diagnostics and self-healing check:

docker exec -it scan scan doctor

CLI Command Reference:

  • scan tui — Interactive terminal user interface.
  • scan doctor — Diagnoses storage permissions, ports, and database health.
  • scan status — Displays network configuration and security parameters.
  • scan data stats — Shows storage utilization and leaderboard metrics.

Architecture & Security

  • Axum Web Backend: High-concurrency async HTTP runtime built on Tokio.
  • Yew WebAssembly Frontend: Type-safe client bundle running natively in browser WASM runtime.
  • Strict Input & Path Sanitization: Path canonicalization guards preventing directory traversal escapes.
  • Fail-Closed Security PIN Authentication: Rate-limited brute force protection with automatic lockout timers.

License

Distributed under the Apache 2.0 License. See LICENSE for details.

Releases

Packages

Used by

Contributors

Languages