Files
omarchy/etc/sudoers.d/omarchy-theme-browser
T
Ryan Hughes da0fe6d89f Harden browser policy directories (#7972)
Cherry-picked from quattro (7d58bb9a).

Stop world-writable Chromium and Firefox policy directories: create them
root-owned at 0755, purge non-root entries, refuse planted symlinks, and
write the browser theme colour through a passwordless helper instead of
a world-writable policy file.

Conflict resolution for v4-0-2:
- bin/omarchy-install-browser: dropped the `chromium)` case, which does
  not exist on this branch.
- test/shell.d/default-apps-test.sh: dropped; the file does not exist on
  this branch.
2026-08-28 18:25:24 -04:00

9 lines
614 B
Plaintext

# Theme switching is a menu action with no terminal to carry a password prompt,
# and it repaints the browser accent on every switch, so this one write must not
# stop for a password. The argument is spelled out as six hex digits rather than
# a wildcard: the grant covers a color and nothing else, and sudoers matches a
# command's arguments exactly, so it cannot be stretched into extra ones. The
# helper revalidates the same shape, since the terminal path does not come
# through this rule.
%wheel ALL=(root) NOPASSWD: /usr/bin/omarchy-theme-set-browser-policy [0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f]