Cherry-picked from quattro (7d58bb9a).
Stop world-writable Chromium and Firefox policy directories: create them
root-owned at 0755, purge non-root entries, refuse planted symlinks, and
write the browser theme colour through a passwordless helper instead of
a world-writable policy file.
Conflict resolution for v4-0-2:
- bin/omarchy-install-browser: dropped the `chromium)` case, which does
not exist on this branch.
- test/shell.d/default-apps-test.sh: dropped; the file does not exist on
this branch.
9 lines
614 B
Plaintext
9 lines
614 B
Plaintext
# Theme switching is a menu action with no terminal to carry a password prompt,
|
|
# and it repaints the browser accent on every switch, so this one write must not
|
|
# stop for a password. The argument is spelled out as six hex digits rather than
|
|
# a wildcard: the grant covers a color and nothing else, and sudoers matches a
|
|
# command's arguments exactly, so it cannot be stretched into extra ones. The
|
|
# helper revalidates the same shape, since the terminal path does not come
|
|
# through this rule.
|
|
%wheel ALL=(root) NOPASSWD: /usr/bin/omarchy-theme-set-browser-policy [0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f][0-9a-f]
|