feat: add adaptive pinentry module (rofi on TTY, curses on SSH)

This commit is contained in:
hermes-bot
2026-07-23 10:44:22 -03:00
committed by jpporta
parent 15d4a06719
commit d4c2b37d46
2 changed files with 34 additions and 7 deletions
+2 -7
View File
@@ -33,6 +33,7 @@
../../modules/home-manager/openspec ../../modules/home-manager/openspec
../../modules/home-manager/power-profiles ../../modules/home-manager/power-profiles
../../modules/home-manager/ntfy-notify ../../modules/home-manager/ntfy-notify
../../modules/home-manager/pinentry
inputs.zen-browser.homeModules.beta inputs.zen-browser.homeModules.beta
]; ];
@@ -148,13 +149,7 @@
gpg.enable = true; gpg.enable = true;
}; };
services.gpg-agent = { custom.pinentry.enable = true;
enable = true;
pinentry.package = pkgs.pinentry-rofi;
enableSshSupport = true; # only if you use gpg keys as ssh keys
defaultCacheTtl = 3600;
maxCacheTtl = 86400;
};
services.swaync.enable = true; services.swaync.enable = true;
} }
+32
View File
@@ -0,0 +1,32 @@
{
lib,
config,
pkgs,
...
}:
let
pinentry-wrapper = pkgs.writeShellScriptBin "pinentry-wrapper" ''
if [ -n "''${SSH_CONNECTION:-}" ] || [ -n "''${SSH_TTY:-}" ]; then
exec ${pkgs.pinentry-curses}/bin/pinentry-curses "$@"
else
exec ${pkgs.pinentry-rofi}/bin/pinentry-rofi "$@"
fi
'';
in {
options.custom.pinentry = {
enable = lib.mkEnableOption "adaptive pinentry: rofi on TTY, curses on SSH";
};
config = lib.mkIf config.custom.pinentry.enable {
home.packages = [ pinentry-wrapper ];
services.gpg-agent = {
enable = true;
pinentry.package = pinentry-wrapper;
enableSshSupport = true;
defaultCacheTtl = 3600;
maxCacheTtl = 86400;
};
};
}