diff --git a/hosts/jpporta-nixos/home.nix b/hosts/jpporta-nixos/home.nix index 0128a30..359d57c 100644 --- a/hosts/jpporta-nixos/home.nix +++ b/hosts/jpporta-nixos/home.nix @@ -36,6 +36,7 @@ Warning: Identity file /home/jpporta/.ssh/id_rsa not accessible: No such file or ../../modules/home-manager/openspec ../../modules/home-manager/power-profiles ../../modules/home-manager/ntfy-notify + ../../modules/home-manager/pinentry inputs.zen-browser.homeModules.beta ]; @@ -150,13 +151,7 @@ Warning: Identity file /home/jpporta/.ssh/id_rsa not accessible: No such file or gpg.enable = true; }; - services.gpg-agent = { - enable = true; - pinentry.package = pkgs.pinentry-rofi; - enableSshSupport = true; # only if you use gpg keys as ssh keys - defaultCacheTtl = 3600; - maxCacheTtl = 86400; - }; + custom.pinentry.enable = true; services.swaync.enable = true; } diff --git a/modules/home-manager/pinentry/default.nix b/modules/home-manager/pinentry/default.nix new file mode 100644 index 0000000..49e84fd --- /dev/null +++ b/modules/home-manager/pinentry/default.nix @@ -0,0 +1,32 @@ +{ + lib, + config, + pkgs, + ... +}: + +let + pinentry-wrapper = pkgs.writeShellScriptBin "pinentry-wrapper" '' + if [ -n "''${SSH_CONNECTION:-}" ] || [ -n "''${SSH_TTY:-}" ]; then + exec ${pkgs.pinentry-curses}/bin/pinentry-curses "$@" + else + exec ${pkgs.pinentry-rofi}/bin/pinentry-rofi "$@" + fi + ''; +in { + options.custom.pinentry = { + enable = lib.mkEnableOption "adaptive pinentry: rofi on TTY, curses on SSH"; + }; + + config = lib.mkIf config.custom.pinentry.enable { + home.packages = [ pinentry-wrapper ]; + + services.gpg-agent = { + enable = true; + pinentry.package = pinentry-wrapper; + enableSshSupport = true; + defaultCacheTtl = 3600; + maxCacheTtl = 86400; + }; + }; +}