diff options
Diffstat (limited to 'modules/web/chromium/extensions')
| -rw-r--r-- | modules/web/chromium/extensions/aria2-explorer.nix | 33 | ||||
| -rw-r--r-- | modules/web/chromium/extensions/browserpass.nix | 35 | ||||
| -rw-r--r-- | modules/web/chromium/extensions/dark-mode.nix | 32 | ||||
| -rw-r--r-- | modules/web/chromium/extensions/default.nix | 15 | ||||
| -rw-r--r-- | modules/web/chromium/extensions/lib.nix | 116 | ||||
| -rw-r--r-- | modules/web/chromium/extensions/ublock-origin.nix | 32 |
6 files changed, 263 insertions, 0 deletions
diff --git a/modules/web/chromium/extensions/aria2-explorer.nix b/modules/web/chromium/extensions/aria2-explorer.nix new file mode 100644 index 0000000..1f6e5b1 --- /dev/null +++ b/modules/web/chromium/extensions/aria2-explorer.nix @@ -0,0 +1,33 @@ +{ + lib, + pkgs, + extLib, +}: +let + pname = "aria2-explorer"; + owner = "alexhua"; + repo = "Aria2-Explorer"; + version = "2.8.2"; + checkedVersion = extLib.checkExtensionVersion { + inherit + pname + owner + repo + version + ; + tagPrefix = "v"; + urlTemplate = "https://github.com/${owner}/${repo}/releases/download/v<version>/A2E-v<version>.crx"; + }; +in +{ + inherit pname; + version = checkedVersion; + id = "dkcfilkhokojanlmgpbmjidiidoebnbm"; + drv = extLib.fetchUnpackedExtension { + inherit pname; + version = checkedVersion; + url = "https://github.com/${owner}/${repo}/releases/download/v${checkedVersion}/A2E-v${checkedVersion}.crx"; + hash = "sha256-ljTgKd9QJTRJ11rlNx+PTynlQvdLW3IEoYNnCeOU2K8="; + isCrx = true; + }; +} diff --git a/modules/web/chromium/extensions/browserpass.nix b/modules/web/chromium/extensions/browserpass.nix new file mode 100644 index 0000000..527f073 --- /dev/null +++ b/modules/web/chromium/extensions/browserpass.nix @@ -0,0 +1,35 @@ +{ + lib, + pkgs, + extLib, +}: +let + pname = "browserpass"; + owner = "browserpass"; + repo = "browserpass-extension"; + version = "3.12.0"; + checkedVersion = extLib.checkExtensionVersion { + inherit + pname + owner + repo + version + ; + tagPrefix = ""; + urlTemplate = "https://github.com/${owner}/${repo}/releases/download/<version>/browserpass-webstore-<version>.crx"; + }; +in +{ + inherit pname; + version = checkedVersion; + # Stable webstore ID — only holds if the crx's manifest.json embeds "key". + # Verify at chrome://extensions after switching; update if it drifts. + id = "klfoddkbhleoaabpmiigbmpbjfljimgb"; + drv = extLib.fetchUnpackedExtension { + inherit pname; + version = checkedVersion; + url = "https://github.com/${owner}/${repo}/releases/download/${checkedVersion}/browserpass-webstore-${checkedVersion}.crx"; + hash = "sha256-NfLbEe2EBctmntJqbsIpwm2WRFdo8q6yjWGjVK2MmFE="; + isCrx = true; + }; +} diff --git a/modules/web/chromium/extensions/dark-mode.nix b/modules/web/chromium/extensions/dark-mode.nix new file mode 100644 index 0000000..4ac9040 --- /dev/null +++ b/modules/web/chromium/extensions/dark-mode.nix @@ -0,0 +1,32 @@ +{ + lib, + pkgs, + extLib, +}: +let + pname = "dark-mode"; + owner = "code-charity"; + repo = "dark-mode"; + version = "3.3.11"; + checkedVersion = extLib.checkExtensionVersion { + inherit + pname + owner + repo + version + ; + tagPrefix = "v"; + urlTemplate = "https://github.com/${owner}/${repo}/archive/refs/tags/v<version>.zip"; + }; +in +{ + inherit pname; + version = checkedVersion; + id = "ifpghghnlimndidoppdkdnbljddikfoj"; + drv = extLib.fetchUnpackedExtension { + inherit pname; + version = checkedVersion; + url = "https://github.com/${owner}/${repo}/archive/refs/tags/v${checkedVersion}.zip"; + hash = "sha256-Lt3T8i0ylV0l+T0eqnzs6veBcOpizhP79LgSkUx4xI8="; + }; +} diff --git a/modules/web/chromium/extensions/default.nix b/modules/web/chromium/extensions/default.nix new file mode 100644 index 0000000..a44286e --- /dev/null +++ b/modules/web/chromium/extensions/default.nix @@ -0,0 +1,15 @@ +{ + lib, + pkgs, + checkForUpdates ? true, +}: +let + extLib = import ./lib.nix { inherit lib pkgs checkForUpdates; }; + mkExtension = path: import path { inherit lib pkgs extLib; }; +in +{ + ublockOrigin = mkExtension ./ublock-origin.nix; + darkMode = mkExtension ./dark-mode.nix; + browserpass = mkExtension ./browserpass.nix; + aria2Explorer = mkExtension ./aria2-explorer.nix; +} diff --git a/modules/web/chromium/extensions/lib.nix b/modules/web/chromium/extensions/lib.nix new file mode 100644 index 0000000..f5e83a1 --- /dev/null +++ b/modules/web/chromium/extensions/lib.nix @@ -0,0 +1,116 @@ +{ + lib, + pkgs, + checkForUpdates ? true, +}: +rec { + # --- Hit the GitHub releases API and return the latest tag name. --- + # Impure: requires --impure since there's no fixed output hash for the API + # response itself. Optionally uses $GITHUB_TOKEN to dodge rate limits. + fetchLatestGithubReleaseTag = + { owner, repo }: + let + token = builtins.getEnv "GITHUB_TOKEN"; + raw = builtins.fetchurl { + url = "https://api.github.com/repos/${owner}/${repo}/releases/latest"; + name = "${repo}-latest-release.json"; + }; + json = builtins.fromJSON (builtins.readFile raw); + in + json.tag_name; + + # --- Compare pinned version against upstream latest, abort with instructions if stale. --- + # Returns `version` unchanged on success so it can be threaded into the + # derivation below and force this check to actually run. + checkExtensionVersion = + { + pname, + owner, + repo, + version, + urlTemplate, # human-readable template shown in the error message + tagPrefix ? "", # e.g. "v" if tags look like "v1.2.3" + }: + if !checkForUpdates then + version + else + let + latestTag = fetchLatestGithubReleaseTag { inherit owner repo; }; + latestVersion = + if lib.hasPrefix tagPrefix latestTag then lib.removePrefix tagPrefix latestTag else latestTag; + in + if latestVersion != version then + throw '' + [${pname}] A newer release is available upstream — refusing to build a stale extension. + + pinned version : ${version} + latest version : ${latestVersion} (tag: ${latestTag}) + + To upgrade, edit extensions/${pname}.nix: + 1. Set version = "${latestVersion}"; + 2. Point the url at the new release asset: + ${urlTemplate} + 3. Set hash = lib.fakeHash; + then re-run your switch — it'll fail with a hash mismatch showing + the real sha256. Paste that in as the final hash. + 4. Re-run once more. This check passes once pinned == latest. + + To skip this check for now (e.g. offline / pure eval), set: + web.chromium.checkForUpdates = false; + '' + else + version; + + # --- Download + unpack a zip *or* crx into a plain unpacked-extension dir. --- + # A CRX3 file is just: "Cr24" magic (4B) + version (4B) + header length N (4B) + # + N bytes of protobuf header + a normal zip payload. We slice off the + # header when isCrx = true, then unzip exactly like any other release zip — + # so every extension, crx or not, goes through one identical pipeline. + fetchUnpackedExtension = + { + pname, + version, + url, + hash, + isCrx ? false, + }: + pkgs.stdenv.mkDerivation { + inherit pname version; + src = pkgs.fetchurl { inherit url hash; }; + nativeBuildInputs = [ + pkgs.unzip + pkgs.python3 + ]; + dontUnpack = true; + + buildPhase = '' + runHook preBuild + mkdir -p $out + + if [ "${lib.boolToString isCrx}" = "true" ]; then + offset=$(python3 -c " + import struct + with open('$src', 'rb') as f: + magic, ver, hlen = struct.unpack('<4sII', f.read(12)) + assert magic == b'Cr24', 'not a CRX file' + print(12 + hlen) + ") + dd if=$src of=payload.zip bs=1 skip=$offset status=none + unzip -q payload.zip -d $out + else + unzip -q $src -d $out + fi + + # Flatten a single wrapping folder (common in GitHub release zips) + if [ "$(ls -1 $out | wc -l)" -eq 1 ] && [ -d "$out"/* ]; then + shopt -s dotglob + mv "$out"/*/* "$out"/ 2>/dev/null || true + rmdir "$out"/*/ 2>/dev/null || true + shopt -u dotglob + fi + runHook postBuild + ''; + + installPhase = "true"; + }; +} diff --git a/modules/web/chromium/extensions/ublock-origin.nix b/modules/web/chromium/extensions/ublock-origin.nix new file mode 100644 index 0000000..7d11ee4 --- /dev/null +++ b/modules/web/chromium/extensions/ublock-origin.nix @@ -0,0 +1,32 @@ +{ + lib, + pkgs, + extLib, +}: +let + pname = "ublock-origin"; + owner = "gorhill"; + repo = "uBlock"; + version = "1.72.2"; + checkedVersion = extLib.checkExtensionVersion { + inherit + pname + owner + repo + version + ; + tagPrefix = ""; + urlTemplate = "https://github.com/${owner}/${repo}/releases/download/<version>/uBlock0_<version>.chromium.zip"; + }; +in +{ + inherit pname; + version = checkedVersion; + id = "nnpdegnhelmjgchicpfdigllmhgpndeg"; # unpacked, ID derives from manifest key at load time + drv = extLib.fetchUnpackedExtension { + inherit pname; + version = checkedVersion; + url = "https://github.com/${owner}/${repo}/releases/download/${checkedVersion}/uBlock0_${checkedVersion}.chromium.zip"; + hash = "sha256-0QTKxOH0jXaxw/+Irt4uqoJpgUrgbMnIUNJ6+1J05TM="; + }; +} |
