Backport of the notification click-command hardening (PR #7926, merged to
quattro as 43bfe9b9) onto the v4-0-1 release branch. Click actions are argv
vectors run without a shell, omarchy-notification-send calls the Notify D-Bus
method directly via busctl instead of notify-send, and --exec takes the command
as rest-of-line words. Excludes docs/notifications.md, which does not exist on
v4-0-1.
13 lines
527 B
Bash
13 lines
527 B
Bash
#!/bin/bash
|
|
|
|
set -e
|
|
|
|
# Only invite when there's a reader to use and it isn't set up yet (the lock
|
|
# PAM file is the last thing the setup writes on success).
|
|
if omarchy-hw-fingerprint && [[ ! -f /etc/pam.d/omarchy-lock-fingerprint ]] &&
|
|
omarchy-done ensure fingerprint-setup-invitation; then
|
|
omarchy-notification-send -u critical -g "Setup Fingerprint Reader" \
|
|
"Enable sudo and unlocking with your fingerprint." \
|
|
--exec omarchy-launch-floating-terminal-with-presentation omarchy-setup-security-fingerprint
|
|
fi
|