From 0495ac236350abf419c444658c834e351531266f Mon Sep 17 00:00:00 2001 From: David Heinemeier Hansson Date: Sun, 15 Mar 2026 16:18:58 +0100 Subject: [PATCH] Try just to give it 15 mins at a time --- bin/omarchy-sudo-passwordless-toggle | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/bin/omarchy-sudo-passwordless-toggle b/bin/omarchy-sudo-passwordless-toggle index 9278a0da..a8857aa5 100755 --- a/bin/omarchy-sudo-passwordless-toggle +++ b/bin/omarchy-sudo-passwordless-toggle @@ -1,32 +1,36 @@ #!/bin/bash # Toggle passwordless sudo for the current user. -# First run: enables passwordless sudo (after confirmation). -# Second run: disables it. +# First run: enables passwordless sudo for 15 minutes (after confirmation). +# Second run: disables it early. NOPASSWD_FILE="/etc/sudoers.d/99-omarchy-nopasswd-${USER}" +TIMER_NAME="omarchy-nopasswd-expire-${USER}" # Check for the file directly — sudo -n can stay cached or be granted by other rules if sudo test -f "$NOPASSWD_FILE"; then sudo rm "$NOPASSWD_FILE" + sudo systemctl stop "${TIMER_NAME}.timer" 2>/dev/null echo "Passwordless sudo has been DISABLED. Sudo will require a password again." else echo "" echo "⚠️ WARNING: This will allow ANY process running as your user to" - echo "execute ANY command as root WITHOUT a password." + echo "execute ANY command as root WITHOUT a password for 15 minutes." echo "" echo "This is useful for AI agents that need to run sudo commands," echo "but it significantly weakens the security of your system." echo "Anyone or anything with access to your user account gets full root." echo "" - echo "Only enable this while actively using an AI agent, then run" - echo "this command again to disable it." + echo "Passwordless sudo will automatically disable after 15 minutes." + echo "Run this command again to disable it early." echo "" - if gum confirm "Enable passwordless sudo? This is a significant security risk!"; then + if gum confirm "Enable passwordless sudo for 15 minutes? This is a significant security risk!"; then echo "${USER} ALL=(ALL) NOPASSWD: ALL" | sudo tee "$NOPASSWD_FILE" > /dev/null sudo chmod 440 "$NOPASSWD_FILE" - echo "Passwordless sudo has been ENABLED. Run this command again to disable it." + sudo systemd-run --on-active=15m --timer-property=AccuracySec=1s --unit="$TIMER_NAME" \ + rm "$NOPASSWD_FILE" + echo "Passwordless sudo has been ENABLED. It will automatically disable in 15 minutes." else echo "Aborted. No changes made." fi