blob: e78e5952c9db2a29d3e1cd3bdb2b5ddcd9978556 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
|
# Standard Unix password manager
{
config,
lib,
pkgs,
...
}:
{
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
package = lib.mkOption {
type = lib.types.package;
readOnly = true;
default = config.programs.password-store.package;
description = "The gopass package to use.";
};
sync = {
enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
remote = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
};
credential = {
username = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Username for HTTPS git authentication against the gopass remote.";
};
passwordGopassPath = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "gopass entry path holding the password or token used.";
};
};
};
};
config = lib.mkMerge [
(lib.mkIf config.security.gopass.enable {
programs.password-store = {
enable = true;
package = pkgs.gopass.override { passAlias = true; };
settings = {
PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
};
};
# use a different username and email to show these commits are auto
# generated by gopass
programs.git.includes = lib.mkIf config.development.git.enable [
{
condition = "gitdir:${config.programs.password-store.settings.PASSWORD_STORE_DIR}/";
contents = {
user = {
name = "Gopass of ${config.home.username}";
email = "${config.home.username}@gopass.localhost";
};
commit = {
gpgSign = false;
};
tag = {
gpgSign = false;
};
}
//
lib.optionalAttrs
(
config.security.gopass.sync.enable
&& config.security.gopass.sync.credential.passwordGopassPath != null
)
{
credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
};
}
];
home.sessionVariables = {
PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
};
home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = {
source = ../../../assets/icons/apps/gopass.svg;
};
xdg.desktopEntries."gopass" = {
name = "gopass";
exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}";
icon = "gopass";
comment = "Standard Unix password manager (Go implementation)";
categories = [ "Utility" ];
terminal = false;
type = "Application";
};
})
(lib.mkIf config.security.gopass.sync.enable {
home.activation.gopassSyncInit =
let
gopassSyncInit = pkgs.writeShellApplication {
name = "gopass-sync-init";
runtimeInputs = [
config.terminal.bash.package
config.development.git.package
];
text =
builtins.replaceStrings
[ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
[ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
(builtins.readFile ./gopass-sync-init.sh);
};
in
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run ${lib.getExe gopassSyncInit} || true
'';
})
];
}
|