Try just to give it 15 mins at a time

This commit is contained in:
David Heinemeier Hansson
2026-03-15 16:18:58 +01:00
parent 2bd0e23a5f
commit 0495ac2363
+11 -7
View File
@@ -1,32 +1,36 @@
#!/bin/bash #!/bin/bash
# Toggle passwordless sudo for the current user. # Toggle passwordless sudo for the current user.
# First run: enables passwordless sudo (after confirmation). # First run: enables passwordless sudo for 15 minutes (after confirmation).
# Second run: disables it. # Second run: disables it early.
NOPASSWD_FILE="/etc/sudoers.d/99-omarchy-nopasswd-${USER}" NOPASSWD_FILE="/etc/sudoers.d/99-omarchy-nopasswd-${USER}"
TIMER_NAME="omarchy-nopasswd-expire-${USER}"
# Check for the file directly — sudo -n can stay cached or be granted by other rules # Check for the file directly — sudo -n can stay cached or be granted by other rules
if sudo test -f "$NOPASSWD_FILE"; then if sudo test -f "$NOPASSWD_FILE"; then
sudo rm "$NOPASSWD_FILE" sudo rm "$NOPASSWD_FILE"
sudo systemctl stop "${TIMER_NAME}.timer" 2>/dev/null
echo "Passwordless sudo has been DISABLED. Sudo will require a password again." echo "Passwordless sudo has been DISABLED. Sudo will require a password again."
else else
echo "" echo ""
echo "⚠️ WARNING: This will allow ANY process running as your user to" echo "⚠️ WARNING: This will allow ANY process running as your user to"
echo "execute ANY command as root WITHOUT a password." echo "execute ANY command as root WITHOUT a password for 15 minutes."
echo "" echo ""
echo "This is useful for AI agents that need to run sudo commands," echo "This is useful for AI agents that need to run sudo commands,"
echo "but it significantly weakens the security of your system." echo "but it significantly weakens the security of your system."
echo "Anyone or anything with access to your user account gets full root." echo "Anyone or anything with access to your user account gets full root."
echo "" echo ""
echo "Only enable this while actively using an AI agent, then run" echo "Passwordless sudo will automatically disable after 15 minutes."
echo "this command again to disable it." echo "Run this command again to disable it early."
echo "" echo ""
if gum confirm "Enable passwordless sudo? This is a significant security risk!"; then if gum confirm "Enable passwordless sudo for 15 minutes? This is a significant security risk!"; then
echo "${USER} ALL=(ALL) NOPASSWD: ALL" | sudo tee "$NOPASSWD_FILE" > /dev/null echo "${USER} ALL=(ALL) NOPASSWD: ALL" | sudo tee "$NOPASSWD_FILE" > /dev/null
sudo chmod 440 "$NOPASSWD_FILE" sudo chmod 440 "$NOPASSWD_FILE"
echo "Passwordless sudo has been ENABLED. Run this command again to disable it." sudo systemd-run --on-active=15m --timer-property=AccuracySec=1s --unit="$TIMER_NAME" \
rm "$NOPASSWD_FILE"
echo "Passwordless sudo has been ENABLED. It will automatically disable in 15 minutes."
else else
echo "Aborted. No changes made." echo "Aborted. No changes made."
fi fi