Files
omarchy/bin/omarchy-theme-set-browser
T
Ryan Hughes da0fe6d89f Harden browser policy directories (#7972)
Cherry-picked from quattro (7d58bb9a).

Stop world-writable Chromium and Firefox policy directories: create them
root-owned at 0755, purge non-root entries, refuse planted symlinks, and
write the browser theme colour through a passwordless helper instead of
a world-writable policy file.

Conflict resolution for v4-0-2:
- bin/omarchy-install-browser: dropped the `chromium)` case, which does
  not exist on this branch.
- test/shell.d/default-apps-test.sh: dropped; the file does not exist on
  this branch.
2026-08-28 18:25:24 -04:00

37 lines
1.2 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Apply the current theme color to Chromium, Chrome, Edge, and Brave
# omarchy:hidden=true
source "$OMARCHY_PATH/install/helpers/browser-policy.sh"
CHROMIUM_THEME=$HOME/.local/state/omarchy/current/theme/chromium.theme
THEME_HEX_COLOR=$BROWSER_POLICY_DEFAULT_COLOR
if [[ -f $CHROMIUM_THEME ]]; then
THEME_HEX_COLOR=$(browser_policy_theme_hex "$(<$CHROMIUM_THEME)")
fi
refresh_running_browser() {
local process="$1"
local command="$2"
local pgrep_args="${3:--x}"
if omarchy-cmd-present "$command" && pgrep $pgrep_args "$process" >/dev/null; then
"$command" --refresh-platform-policy --no-startup-window &>/dev/null
fi
}
failed=0
omarchy-theme-set-browser-policy "${THEME_HEX_COLOR#\#}" || failed=1
refresh_running_browser chromium chromium
refresh_running_browser chrome google-chrome-stable || refresh_running_browser chrome google-chrome
refresh_running_browser msedge microsoft-edge-stable
refresh_running_browser brave brave
# Match on the binary path: the running process is named plain "brave", and a
# bare -f brave-origin pattern would also match the installer's own terminal.
refresh_running_browser /opt/brave-origin-bin/ brave-origin -f
exit "$failed"