#!/bin/bash

# omarchy:summary=Enable sudoless Docker by adding your user to the docker group (root-equivalent!)
# omarchy:requires-sudo=true

set -e

if id -nG "$USER" 2>/dev/null | grep -qw docker; then
  echo "Sudoless Docker is already enabled: $USER is in the docker group."
  echo "To disable it again, run: omarchy-remove-security-sudoless-docker"
  exit 0
fi

echo ""
echo "⚠️  WARNING: Enabling sudoless Docker adds you to the 'docker' group."
echo ""
echo "The Docker daemon runs as root, so membership in the docker group is"
echo "equivalent to passwordless root. Any process running as your user could"
echo "then run, for example:"
echo ""
echo "    docker run -v /:/host alpine   # full read/write of the host, as root"
echo ""
echo "and take over the machine with no password prompt. A single rogue script,"
echo "dependency, or plugin running as you is enough. It is convenient for"
echo "development, but it removes the protection Omarchy keeps by default, where"
echo "Docker access goes through a polkit/sudo prompt."
echo ""

if gum confirm "Enable sudoless Docker? This gives anything running as you passwordless root."; then
  sudo usermod -aG docker "$USER"
  echo ""
  echo "Sudoless Docker ENABLED. Log out and back in (or run 'newgrp docker')"
  echo "for the new group membership to take effect."
  echo "To disable it again, run: omarchy-remove-security-sudoless-docker"
else
  echo "Aborted. No changes made. Docker access still goes through a prompt."
fi
