aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass/default.nix
blob: 123b33f5e89cbbd1bbc796c0eefd186be6d9161c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
# Standard Unix password manager
{
  config,
  lib,
  pkgs,
  ...
}:
{
  options.security.gopass = {
    enable = lib.mkEnableOption "Enables gopass.";
    package = lib.mkOption {
      type = lib.types.package;
      readOnly = true;
      default = config.programs.password-store.package;
      description = "The gopass package to use.";
    };
    sync = {
      enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
      remote = lib.mkOption {
        type = lib.types.nullOr lib.types.str;
        default = null;
        description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
      };
      credential = {
        username = lib.mkOption {
          type = lib.types.nullOr lib.types.str;
          default = null;
          description = "Username for HTTPS git authentication against the gopass remote.";
        };
        passwordGopassPath = lib.mkOption {
          type = lib.types.nullOr lib.types.str;
          default = null;
          description = "gopass entry path holding the password or token used.";
        };
      };
    };
    creation-templates = {
      enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
    };
  };

  config = lib.mkMerge [
    (lib.mkIf config.security.gopass.enable {
      programs.password-store = {
        enable = true;
        package = pkgs.gopass.override { passAlias = true; };
        settings = {
          PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
        };
      };

      # use a different username and email to show these commits are auto
      # generated by gopass
      programs.git.includes = lib.mkIf config.development.git.enable [
        {
          condition = "gitdir:${config.programs.password-store.settings.PASSWORD_STORE_DIR}/";
          contents = {
            user = {
              name = "Gopass of ${config.home.username}";
              email = "${config.home.username}@gopass.localhost";
            };
            commit = {
              gpgSign = false;
            };
            tag = {
              gpgSign = false;
            };
          }
          //
            lib.optionalAttrs
              (
                config.security.gopass.sync.enable
                && config.security.gopass.sync.credential.passwordGopassPath != null
              )
              {
                credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
              };
        }
      ];

      home.sessionVariables = {
        PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
      };

      home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = {
        source = ../../../assets/icons/apps/gopass.svg;
      };

      home.activation.copyCreationTemplatesForGopass =
        lib.mkIf config.security.gopass.creation-templates.enable
          (
            lib.hm.dag.entryAfter [ "writeBoundary" ] ''
              $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
              $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
              $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
            ''
          );

      xdg.desktopEntries."gopass" = {
        name = "gopass";
        exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}";
        icon = "gopass";
        comment = "Standard Unix password manager (Go implementation)";
        categories = [ "Utility" ];
        terminal = false;
        type = "Application";
      };
    })

    (lib.mkIf config.security.gopass.sync.enable {
      home.activation.gopassSyncInit =
        let
          gopassSyncInit = pkgs.writeShellApplication {
            name = "gopass-sync-init";
            runtimeInputs = [
              config.terminal.bash.package
              config.development.git.package
            ];
            text =
              builtins.replaceStrings
                [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
                [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
                (builtins.readFile ./gopass-sync-init.sh);
          };
        in
        lib.hm.dag.entryAfter [ "writeBoundary" ] ''
          run ${lib.getExe gopassSyncInit} || true
        '';
    })
  ];
}