# Standard Unix password manager { config, lib, pkgs, ... }: let cfg = config.security.gopass; icons = config.desktop.icons.apps; in { imports = [ ./assertions.nix ]; options.security.gopass = { enable = lib.mkEnableOption "Enables gopass."; package = lib.mkOption { type = lib.types.package; readOnly = true; default = config.programs.password-store.package; description = "The gopass package to use."; }; sync = lib.mkOption { type = lib.types.submodule { options = { enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; remote = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; }; credential = lib.mkOption { type = lib.types.submodule { options = { username = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Username for HTTPS git authentication against the gopass remote."; }; password-gopass-secret = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "gopass entry path holding the password or token used."; }; }; }; default = { }; description = "Credentials for HTTPS git authentication."; }; }; }; default = { }; description = "Git-backed syncing configuration."; }; creation-templates = lib.mkOption { type = lib.types.submodule { options = { enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; }; }; default = { }; description = "Creation templates configuration."; }; }; config = lib.mkMerge [ (lib.mkIf cfg.enable { programs.password-store = { enable = true; package = pkgs.gopass.override { passAlias = true; }; settings = { PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; }; }; # use a different username and email to show these commits are auto # generated by gopass programs.git.includes = lib.mkIf config.development.git.enable [ { condition = "gitdir:${config.programs.password-store.settings.PASSWORD_STORE_DIR}/"; contents = { user = { name = "Gopass of ${config.home.username}"; email = "${config.home.username}@gopass.localhost"; }; commit = { gpgSign = false; }; tag = { gpgSign = false; }; } // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) { credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe cfg.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; }; } ]; home.sessionVariables = { PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR; }; home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable ( lib.hm.dag.entryAfter [ "writeBoundary" ] '' $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" '' ); }) (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."gopass" = { name = "gopass"; exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}"; icon = icons.gopass; comment = "Standard Unix password manager (Go implementation)"; categories = [ "Utility" ]; terminal = false; type = "Application"; }; }) (lib.mkIf cfg.sync.enable { home.activation.gopassSyncInit = let gopassSyncInit = pkgs.writeShellApplication { name = "gopass-sync-init"; runtimeInputs = [ config.terminal.bash.package config.development.git.package ]; text = builtins.replaceStrings [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ] (builtins.readFile ./gopass-sync-init.sh); }; in lib.hm.dag.entryAfter [ "writeBoundary" ] '' run ${lib.getExe gopassSyncInit} || true ''; }) ]; }