# Standard Unix password manager { config, lib, pkgs, ... }: let gopassKeys = config.security.ssh.gopassKeys; gopassSshLoadScript = pkgs.writeShellApplication { name = "gopass-ssh-load"; runtimeInputs = [ config.security.gopass.package config.security.gpg.package config.security.ssh.package pkgs.bash ]; text = builtins.replaceStrings [ "@@GOPASS_SSH_KEYS@@" "@@GNUPGHOME@@" ] [ (lib.concatStringsSep " " gopassKeys) config.home.sessionVariables.GNUPGHOME ] (builtins.readFile ./gopass-ssh-load.sh); }; in { options.security.gopass = { enable = lib.mkEnableOption "Enables gopass."; package = lib.mkOption { type = lib.types.package; readOnly = true; default = config.programs.password-store.package; description = "The gopass package to use."; }; ssh-agent = { enable = lib.mkEnableOption "gopass-backed SSH keys for git"; package = lib.mkOption { type = lib.types.package; readOnly = true; default = gopassSshLoadScript; description = "The gopass-ssh-load script package."; }; }; sync = { enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; remote = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; }; credential = { username = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Username for HTTPS git authentication against the gopass remote."; }; passwordGopassPath = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "gopass entry path holding the password or token used."; }; }; }; }; config = lib.mkMerge [ (lib.mkIf config.security.gopass.enable { programs.password-store = { enable = true; package = pkgs.gopass.override { passAlias = true; }; settings = { PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; }; }; # use a different username and email to show these commits are auto # generated by gopass programs.git.includes = lib.mkIf config.development.git.enable [ { condition = "gitdir:${config.programs.password-store.settings.PASSWORD_STORE_DIR}/"; contents = { user = { name = "Gopass of ${config.home.username}"; email = "${config.home.username}@gopass.localhost"; }; commit = { gpgSign = false; }; tag = { gpgSign = false; }; } // lib.optionalAttrs ( config.security.gopass.sync.enable && config.security.gopass.sync.credential.passwordGopassPath != null ) { credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; }; } ]; home.sessionVariables = { PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR; }; home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = { source = ../../../assets/icons/apps/gopass.svg; }; xdg.desktopEntries."gopass" = { name = "gopass"; exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; icon = "gopass"; comment = "Standard Unix password manager (Go implementation)"; categories = [ "Utility" ]; terminal = false; type = "Application"; }; }) (lib.mkIf config.security.gopass.ssh-agent.enable { home.packages = [ config.security.gopass.ssh-agent.package ]; }) (lib.mkIf config.security.gopass.sync.enable { home.activation.gopassSyncInit = let gopassSyncInit = pkgs.writeShellApplication { name = "gopass-sync-init"; runtimeInputs = [ pkgs.bash config.development.git.package ]; text = builtins.replaceStrings [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] (builtins.readFile ./gopass-sync-init.sh); }; in lib.hm.dag.entryAfter [ "writeBoundary" ] '' run ${lib.getExe gopassSyncInit} || true ''; }) ]; }