Replace --exec-arg with an ergonomic --exec that consumes the rest of the line as the click command. The caller's shell tokenizes the words into discrete arguments before the tool sees them, and the shell runs them as positional parameters (never a re-parsed string), so safety is identical to the argv form while the call sites read naturally: `--exec omarchy toggle something`. Crucially the tool never splits a string itself — a single quoted whole-command argument is rejected and points at the unquoted form, because whitespace- splitting a string hands argument boundaries to whoever controls its content (the injection we are avoiding). --exec must come last; migrate every caller.
31 lines
1.1 KiB
Bash
31 lines
1.1 KiB
Bash
notify_update() {
|
|
omarchy-notification-send -u critical -g "Update System" "Click to update the system." \
|
|
--exec omarchy-launch-floating-terminal-with-presentation omarchy-update
|
|
}
|
|
|
|
notify_wifi() {
|
|
omarchy-notification-send -u critical -g "Setup Wi-Fi" "Click to configure the wireless network." \
|
|
--exec omarchy-shell shell toggle omarchy.network
|
|
}
|
|
|
|
announce_network() {
|
|
# Ethernet is still negotiating DHCP when the session starts, so probing
|
|
# right away calls a working machine offline. NetworkManager reports startup
|
|
# complete once it has tried every connection it could auto-activate, which
|
|
# is the first moment the answer means anything.
|
|
nm-online -q -s -t 30
|
|
|
|
# -x takes that answer as it stands rather than waiting out the timeout, so
|
|
# a laptop with nothing to connect to gets prompted immediately.
|
|
if ! nm-online -q -x -t 30; then
|
|
notify_wifi
|
|
# Nothing to update against until a link lands, so hold that prompt.
|
|
nm-online -q -t 3600 || return
|
|
fi
|
|
|
|
notify_update
|
|
}
|
|
|
|
# Detached, so a slow or absent connection never holds up the rest of first run.
|
|
announce_network &
|