Files
omarchy/bin/omarchy-hook
T
Adolanium 0a65b45ab1 Refuse hook and state names that are paths
omarchy-hook and omarchy-state set join a name straight into a path. A name
with a slash, or a bare . or .., points outside the hooks or state directory.
Every caller in the repo passes a fixed label, so this is a footgun guard for
future callers, not a fix for anything that ships today.

Names with dots in the middle (a..b) stay allowed. omarchy-state clear is
untouched: find -name matches basenames only.
2026-09-01 23:21:37 +03:00

41 lines
1.1 KiB
Bash
Executable File

#!/bin/bash
# omarchy:summary=Run a named hook from ~/.config/omarchy/hooks/<name> and ~/.config/omarchy/hooks/<name>.d/.
# omarchy:args=[name] [args...]
set -e
if (( $# < 1 )); then
echo "Usage: omarchy-hook [name] [args...]"
exit 1
fi
HOOK=$1
# Hook names are fixed labels chosen by Omarchy code (post-update, theme-set,
# font-set). The name becomes a filename under the hooks directory. A slash
# would turn it into directory levels, and a bare `.` or `..` would point bash
# at the directory itself or its parent. Refuse those rather than follow them.
# Dots inside a name (a..b) are fine; once slashes are out, only the whole
# name being `.` or `..` can leave the directory.
if [[ -z $HOOK || $HOOK == */* || $HOOK == "." || $HOOK == ".." ]]; then
echo "Invalid hook name: $HOOK" >&2
exit 2
fi
HOOK_PATH="$HOME/.config/omarchy/hooks/$1"
HOOK_DIR="$HOOK_PATH.d"
shift
if [[ -f $HOOK_PATH ]]; then
bash "$HOOK_PATH" "$@" || echo "Hook failed: $HOOK_PATH"
fi
if [[ -d $HOOK_DIR ]]; then
for hook in "$HOOK_DIR"/*; do
[[ -f $hook ]] || continue
[[ $hook == *.sample ]] && continue
bash "$hook" "$@" || echo "Hook failed: $hook"
done
fi