Bring the fingerprint affordance to the Quickshell lock screen and polkit dialog, matching what hyprlock did on master. Lock screen: render the md-fingerprint glyph inside the password field's right edge when a sensor is enrolled, reserving space so long passwords never run under it. Polkit dialog: show one method at a time. When a sensor is enrolled and the reader is reachable, the dialog is just the centered fingerprint icon (square card); the moment PAM asks for a password it switches to the password field. Detects pam_fprintd anywhere in the auth stack now that a gate can precede it. Lid awareness: a closed lid means the reader is unreachable, so both surfaces fall back to the password. polkit gets a pam_exec clamshell gate (auth [success=1 default=ignore] before pam_fprintd) so a shut lid drops straight to the password prompt instead of blocking on the reader for the pam_fprintd timeout; the lock screen hides the icon and skips scanning. The gate points at the fixed /usr/bin path the package always provides so it survives switching between package installs and dev-link. A migration adds the gate for existing fingerprint setups. New helper omarchy-hw-laptop-closed (pure lid state); omarchy-hw-clamshell now composes it with the external-monitor check. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
50 lines
1.5 KiB
Bash
50 lines
1.5 KiB
Bash
#!/bin/bash
|
|
|
|
set -euo pipefail
|
|
|
|
source "$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/base-test.sh"
|
|
|
|
run_node_test <<'JS'
|
|
const polkit = requireFromRoot('shell/plugins/polkit/PolkitModel.js')
|
|
|
|
assert(polkit.promptLooksFingerprint('Swipe your finger'), 'polkit detects fingerprint prompts')
|
|
assert(polkit.promptLooksFingerprint('fprintd verification'), 'polkit detects fprint prompts')
|
|
assert(!polkit.promptLooksFingerprint('Password:'), 'polkit ignores password prompts')
|
|
|
|
assertEqual(
|
|
polkit.authorizationLabel("Authentication is needed to run `/usr/bin/true' as the super user"),
|
|
"Authorize running '/usr/bin/true'",
|
|
'polkit shortens the standard pkexec message'
|
|
)
|
|
assertEqual(
|
|
polkit.authorizationLabel('Authentication is required to change system settings'),
|
|
'Authentication is required to change system settings',
|
|
'polkit preserves custom authorization messages'
|
|
)
|
|
|
|
assert(
|
|
polkit.fingerprintConfiguredFromPamConfig(`
|
|
# comment
|
|
auth sufficient pam_fprintd.so
|
|
auth include system-auth
|
|
`),
|
|
'polkit detects fingerprint in a PAM config'
|
|
)
|
|
assert(
|
|
polkit.fingerprintConfiguredFromPamConfig(`
|
|
auth [success=1 default=ignore] pam_exec.so quiet /usr/bin/omarchy-hw-laptop-closed
|
|
auth sufficient pam_fprintd.so
|
|
auth required pam_unix.so
|
|
`),
|
|
'polkit detects fingerprint even behind a clamshell gate'
|
|
)
|
|
assert(
|
|
!polkit.fingerprintConfiguredFromPamConfig(`
|
|
account include system-auth
|
|
auth include system-auth
|
|
auth required pam_unix.so
|
|
`),
|
|
'polkit reports no fingerprint when pam_fprintd is absent'
|
|
)
|
|
JS
|