blob: 173318b71b857f2c7735f6f6500fb6a4a395afea (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
|
# Standard Unix password manager
{
config,
lib,
pkgs,
...
}:
let
cfg = config.security.gopass;
in
{
imports = [ ./assertions.nix ];
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
package = lib.mkOption {
type = lib.types.package;
readOnly = true;
default = config.programs.password-store.package;
description = "The gopass package to use.";
};
sync = lib.mkOption {
type = lib.types.submodule {
options = {
enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
remote = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
};
credential = lib.mkOption {
type = lib.types.submodule {
options = {
username = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Username for HTTPS git authentication against the gopass remote.";
};
password-gopass-secret = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "gopass entry path holding the password or token used.";
};
};
};
default = { };
description = "Credentials for HTTPS git authentication.";
};
};
};
default = { };
description = "Git-backed syncing configuration.";
};
creation-templates = lib.mkOption {
type = lib.types.submodule {
options = {
enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
};
};
default = { };
description = "Creation templates configuration.";
};
};
config = lib.mkMerge [
(lib.mkIf cfg.enable {
programs.password-store = {
enable = true;
package = pkgs.gopass.override { passAlias = true; };
settings = {
PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
};
};
# use a different username and email to show these commits are auto
# generated by gopass
programs.git.includes = lib.mkIf config.development.git.enable [
{
condition = "gitdir:${config.programs.password-store.settings.PASSWORD_STORE_DIR}/";
contents = {
user = {
name = "Gopass of ${config.home.username}";
email = "${config.home.username}@gopass.localhost";
};
commit = {
gpgSign = false;
};
tag = {
gpgSign = false;
};
}
// lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) {
credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe cfg.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f";
};
}
];
home.sessionVariables = {
PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
};
home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = {
source = ../../../assets/icons/apps/gopass.svg;
};
home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable (
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
$DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
$DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
$DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
''
);
})
(lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."gopass" = {
name = "gopass";
exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}";
icon = "gopass";
comment = "Standard Unix password manager (Go implementation)";
categories = [ "Utility" ];
terminal = false;
type = "Application";
};
})
(lib.mkIf cfg.sync.enable {
home.activation.gopassSyncInit =
let
gopassSyncInit = pkgs.writeShellApplication {
name = "gopass-sync-init";
runtimeInputs = [
config.terminal.bash.package
config.development.git.package
];
text =
builtins.replaceStrings
[ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
[ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ]
(builtins.readFile ./gopass-sync-init.sh);
};
in
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run ${lib.getExe gopassSyncInit} || true
'';
})
];
}
|