From 44b8624d201e70c8418ada5db3c46e9ba130ea30 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 24 Sep 2026 03:42:34 +0530 Subject: refactor(naming): use kebab-case option names and consistent gopass secret naming --- modules/security/gopass/default.nix | 97 +++++++++++++++++++++---------------- 1 file changed, 55 insertions(+), 42 deletions(-) (limited to 'modules/security/gopass/default.nix') diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 616baeb..17624ef 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -5,6 +5,9 @@ pkgs, ... }: +let + cfg = config.security.gopass; +in { imports = [ ./assertions.nix ]; @@ -16,33 +19,51 @@ default = config.programs.password-store.package; description = "The gopass package to use."; }; - sync = { - enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; - remote = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; - }; - credential = { - username = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Username for HTTPS git authentication against the gopass remote."; - }; - passwordGopassPath = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "gopass entry path holding the password or token used."; + sync = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; + }; + credential = lib.mkOption { + type = lib.types.submodule { + options = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the gopass remote."; + }; + password-gopass-secret = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used."; + }; + }; + }; + default = { }; + description = "Credentials for HTTPS git authentication."; + }; }; }; + default = { }; + description = "Git-backed syncing configuration."; }; - creation-templates = { - enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + creation-templates = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + }; + }; + default = { }; + description = "Creation templates configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.security.gopass.enable { + (lib.mkIf cfg.enable { programs.password-store = { enable = true; package = pkgs.gopass.override { passAlias = true; }; @@ -68,15 +89,9 @@ gpgSign = false; }; } - // - lib.optionalAttrs - ( - config.security.gopass.sync.enable - && config.security.gopass.sync.credential.passwordGopassPath != null - ) - { - credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; - }; + // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${cfg.package}/bin/gopass show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; + }; } ]; @@ -88,20 +103,18 @@ source = ../../../assets/icons/apps/gopass.svg; }; - home.activation.copyCreationTemplatesForGopass = - lib.mkIf config.security.gopass.creation-templates.enable - ( - lib.hm.dag.entryAfter [ "writeBoundary" ] '' - $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create - $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - '' - ); + home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable ( + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create + $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + '' + ); }) - (lib.mkIf (config.security.gopass.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."gopass" = { name = "gopass"; - exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}"; icon = "gopass"; comment = "Standard Unix password manager (Go implementation)"; categories = [ "Utility" ]; @@ -109,7 +122,7 @@ type = "Application"; }; }) - (lib.mkIf config.security.gopass.sync.enable { + (lib.mkIf cfg.sync.enable { home.activation.gopassSyncInit = let gopassSyncInit = pkgs.writeShellApplication { @@ -121,7 +134,7 @@ text = builtins.replaceStrings [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] - [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] + [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ] (builtins.readFile ./gopass-sync-init.sh); }; in -- cgit v1.2.3 From c5bdaefa94c3cd9bb7e55747f1682edef4168932 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 24 Sep 2026 03:48:37 +0530 Subject: chore: use lib.getExe and string activation data --- modules/file-management/yazi/default.nix | 2 +- modules/office/calcurse/default.nix | 6 +++--- modules/security/gopass/default.nix | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) (limited to 'modules/security/gopass/default.nix') diff --git a/modules/file-management/yazi/default.nix b/modules/file-management/yazi/default.nix index 3ba7045..72a4568 100644 --- a/modules/file-management/yazi/default.nix +++ b/modules/file-management/yazi/default.nix @@ -65,7 +65,7 @@ in }; home.file.".local/share/icons/hicolor/scalable/apps/yazi.png" = { - source = lib.file.mkOutOfStoreSymlink "${cfg.package}/share/pixmaps/yazi.png"; + source = config.lib.file.mkOutOfStoreSymlink "${cfg.package}/share/pixmaps/yazi.png"; }; home.sessionVariables = { diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix index 7c1df5e..c4053da 100644 --- a/modules/office/calcurse/default.nix +++ b/modules/office/calcurse/default.nix @@ -149,9 +149,9 @@ in } ]; - home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] ( - pkgs.writeText "calcurse-sync-init.sh" ("run " + cfg.package + "/bin/calcurse-sync init || true") - ); + home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run ${lib.getExe cfg.package} init || true + ''; }) ]; } diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 17624ef..173318b 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -90,7 +90,7 @@ in }; } // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) { - credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${cfg.package}/bin/gopass show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; + credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe cfg.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; }; } ]; -- cgit v1.2.3