Allow the timelimit to be extending by passing in an explicit set of minutes
This commit is contained in:
@@ -1,12 +1,19 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
# Toggle passwordless sudo for the current user.
|
# Toggle passwordless sudo for the current user.
|
||||||
|
# Usage: omarchy-sudo-passwordless-toggle [MINUTES]
|
||||||
# First run: enables passwordless sudo for 15 minutes (after confirmation).
|
# First run: enables passwordless sudo for 15 minutes (after confirmation).
|
||||||
# Second run: disables it early.
|
# Second run: disables it early.
|
||||||
|
|
||||||
NOPASSWD_FILE="/etc/sudoers.d/99-omarchy-nopasswd-${USER}"
|
NOPASSWD_FILE="/etc/sudoers.d/99-omarchy-nopasswd-${USER}"
|
||||||
TIMER_NAME="omarchy-nopasswd-expire-${USER}"
|
TIMER_NAME="omarchy-nopasswd-expire-${USER}"
|
||||||
|
|
||||||
|
MINUTES=${1:-15}
|
||||||
|
if [[ $1 && ! $1 =~ ^[0-9]+$ ]]; then
|
||||||
|
echo "Usage: omarchy-sudo-passwordless-toggle [MINUTES]" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
# Safety: if the file exists but the timer doesn't (e.g. after reboot), clean up
|
# Safety: if the file exists but the timer doesn't (e.g. after reboot), clean up
|
||||||
if sudo test -f "$NOPASSWD_FILE" && ! systemctl is-active "${TIMER_NAME}.timer" &>/dev/null; then
|
if sudo test -f "$NOPASSWD_FILE" && ! systemctl is-active "${TIMER_NAME}.timer" &>/dev/null; then
|
||||||
sudo rm "$NOPASSWD_FILE"
|
sudo rm "$NOPASSWD_FILE"
|
||||||
@@ -14,28 +21,37 @@ fi
|
|||||||
|
|
||||||
# Check for the file directly — sudo -n can stay cached or be granted by other rules
|
# Check for the file directly — sudo -n can stay cached or be granted by other rules
|
||||||
if sudo test -f "$NOPASSWD_FILE"; then
|
if sudo test -f "$NOPASSWD_FILE"; then
|
||||||
sudo rm "$NOPASSWD_FILE"
|
if [[ $1 ]]; then
|
||||||
sudo systemctl stop "${TIMER_NAME}.timer" 2>/dev/null
|
sudo systemctl stop "${TIMER_NAME}.timer" 2>/dev/null
|
||||||
echo "Passwordless sudo has been DISABLED. Sudo will require a password again."
|
sudo systemd-run --on-active=${MINUTES}m --timer-property=AccuracySec=1s --unit="$TIMER_NAME" \
|
||||||
|
rm "$NOPASSWD_FILE"
|
||||||
|
echo "Passwordless sudo timer updated. It will now automatically disable in ${MINUTES} minutes."
|
||||||
|
else
|
||||||
|
sudo rm "$NOPASSWD_FILE"
|
||||||
|
sudo systemctl stop "${TIMER_NAME}.timer" 2>/dev/null
|
||||||
|
echo "Passwordless sudo has been DISABLED. Sudo will require a password again."
|
||||||
|
fi
|
||||||
else
|
else
|
||||||
echo ""
|
echo ""
|
||||||
echo "⚠️ WARNING: This will allow ANY process running as your user to"
|
echo "⚠️WARNING: This will allow ANY process running as your user to"
|
||||||
echo "execute ANY command as root WITHOUT a password for 15 minutes."
|
echo "execute ANY command as root WITHOUT a password for ${MINUTES} minutes."
|
||||||
echo ""
|
echo ""
|
||||||
echo "This is useful for AI agents that need to run sudo commands,"
|
echo "This is useful for AI agents that need to run sudo commands,"
|
||||||
echo "but it significantly weakens the security of your system."
|
echo "but it significantly weakens the security of your system."
|
||||||
echo "Anyone or anything with access to your user account gets full root."
|
echo "Anyone or anything with access to your user account gets full root."
|
||||||
echo ""
|
echo ""
|
||||||
echo "Passwordless sudo will automatically disable after 15 minutes."
|
echo "Passwordless sudo will automatically disable after ${MINUTES} minutes."
|
||||||
echo "Run this command again to disable it early."
|
echo "Run this command again to disable it early."
|
||||||
echo ""
|
echo ""
|
||||||
|
|
||||||
if gum confirm "Enable passwordless sudo for 15 minutes? This is a significant security risk!"; then
|
if gum confirm "Enable passwordless sudo for ${MINUTES} minutes? This is a significant security risk!"; then
|
||||||
echo "${USER} ALL=(ALL) NOPASSWD: ALL" | sudo tee "$NOPASSWD_FILE" > /dev/null
|
echo "${USER} ALL=(ALL) NOPASSWD: ALL" | sudo tee "$NOPASSWD_FILE" > /dev/null
|
||||||
sudo chmod 440 "$NOPASSWD_FILE"
|
sudo chmod 440 "$NOPASSWD_FILE"
|
||||||
sudo systemd-run --on-active=15m --timer-property=AccuracySec=1s --unit="$TIMER_NAME" \
|
sudo systemd-run --on-active=${MINUTES}m --timer-property=AccuracySec=1s --unit="$TIMER_NAME" \
|
||||||
rm "$NOPASSWD_FILE"
|
rm "$NOPASSWD_FILE"
|
||||||
echo "Passwordless sudo has been ENABLED. It will automatically disable in 15 minutes."
|
|
||||||
|
echo ""
|
||||||
|
echo "Passwordless sudo has been ENABLED. It will automatically disable in ${MINUTES} minutes."
|
||||||
echo "Note: if you restart before then, run omarchy-sudo-passwordless-toggle again to disable it."
|
echo "Note: if you restart before then, run omarchy-sudo-passwordless-toggle again to disable it."
|
||||||
else
|
else
|
||||||
echo "Aborted. No changes made."
|
echo "Aborted. No changes made."
|
||||||
|
|||||||
Reference in New Issue
Block a user