aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/enteauth/default.nix
blob: a883d1a4097752ec595409ed9083bd8b3d7b6849 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
# Ente Auth - end-to-end encrypted authentication (2FA)
{
  config,
  lib,
  pkgs,
  ...
}:
let
  enteAuthWithKeyring = pkgs.symlinkJoin {
    name = "ente-auth-wrapped";
    paths = [ pkgs.ente-auth ];
    buildInputs = [ pkgs.makeWrapper ];
    postBuild = ''
      wrapProgram $out/bin/enteauth \
        --prefix PATH : ${
          lib.makeBinPath [
            pkgs.gnome-keyring
            pkgs.dbus
          ]
        } \
        --run "echo 'password' | ${pkgs.gnome-keyring}/bin/gnome-keyring-daemon --unlock --components=secrets"

    '';
  };
in
{
  options.security.enteauth = {
    enable = lib.mkEnableOption "Enables wrapped ente-auth with automated keyring unlocks and a desktop entry.";
    package = lib.mkOption {
      type = lib.types.package;
      default = enteAuthWithKeyring;
      description = "The customized version of ente-auth with a self-unlocking daemon backend.";
    };
  };

  config = lib.mkIf config.security.enteauth.enable {
    home.packages = [ config.security.enteauth.package ];

    xdg.desktopEntries."enteauth" = {
      name = "Ente Auth";
      exec = "enteauth";
      icon = "io.ente.auth";
      comment = "End-to-end encrypted 2FA authenticator";
      genericName = "2FA Authenticator";
      categories = [
        "Utility"
        "Security"
      ];
      terminal = false;
      type = "Application";
    };

    xdg.mimeApps.defaultApplications = {
      "x-scheme-handler/enteauth" = "enteauth.desktop";
    };
  };
}