Autostart entries showed "Enabled" or "Disabled" as plain text. The row did toggle on click the whole time, so this is an affordance rather than a missing capability -- but a control that reads as static text is one nobody knows they have. It is a switch now, with removal alongside it behind a confirmation: disabling writes Hidden=true and can be undone, deleting the file cannot. remove-autostart is confined to files the autostart directory owns. It resolves the path and compares the parent, so a name like "../../.bashrc" cannot escape, and it refuses symlinks rather than following them -- deleting through one would remove whatever it points at, which is somewhere else and not ours. Each refusal was tested against a fixture directory, including a symlink aimed at /etc/hostname, which survived. Sharing says who is signed in from another machine: user, origin and since when. An empty list on this machine proves nothing, so the parser was checked against sample `who` output -- it picks out remote sessions and leaves out local seats and the :0 display, which would otherwise report the person at the keyboard as a remote login. Media sharing was "Available" and nothing else: rygel installed, rygel.service disabled, no way to change that from here. It is a switch now, and it says what it does before you touch it rather than afterwards -- turning it on publishes media folders to every device on the network with no password in front of them. Per-application camera and microphone permissions come from the portal's permission store, which is where an application that asked through the portal has its answer recorded. The page states the limit plainly instead of implying a protection that does not exist: a program installed outside the portal opens the device directly and nothing here stands in its way. Anything that is not an explicit "yes" is treated as withheld, because guessing generously about a camera is the wrong way to be wrong. The first version of the write silently did nothing -- SetPermission takes an array of strings and was being handed one string -- and the test did not notice, because it discarded the helper's output and only checked that state was unchanged afterwards, which was trivially true. The contract now requires the value to move, and was proven to fail by putting that exact bug back. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
93 lines
3.2 KiB
QML
93 lines
3.2 KiB
QML
pragma Singleton
|
|
|
|
// Which applications may use the camera and microphone.
|
|
//
|
|
// Backed by xdg-desktop-portal's permission store, which records the answer an
|
|
// application got when it asked through the portal. That is the whole of what
|
|
// this controls, and the limit belongs on the page rather than in a comment: a
|
|
// native binary opens /dev/video0 directly and no desktop setting stands in its
|
|
// way. What this covers is Flatpaks and anything else going through the portal.
|
|
|
|
import Quickshell
|
|
import Quickshell.Io
|
|
import QtQuick
|
|
|
|
Singleton {
|
|
id: root
|
|
|
|
readonly property string helperPath: Quickshell.shellDir + "/scripts/panama-permissions"
|
|
|
|
property bool available: false
|
|
property var devices: []
|
|
property bool scanned: false
|
|
property string lastError: ""
|
|
|
|
// Guards read the Processes directly rather than a derived binding, which
|
|
// returns its cached value inside the handler that changes its dependency.
|
|
readonly property bool busy: query.running || mutation.running
|
|
|
|
// Devices something has actually asked for. A device nothing has asked for
|
|
// is still reported, so the page can say so rather than omit it.
|
|
readonly property var recorded: root.devices.filter(
|
|
device => (device.applications ?? []).length > 0)
|
|
|
|
readonly property int grantedCount: root.devices.reduce(
|
|
(total, device) => total + (device.applications ?? []).filter(app => app.allowed).length, 0)
|
|
|
|
function refresh(): void {
|
|
if (query.running)
|
|
return;
|
|
query.command = [root.helperPath, "snapshot"];
|
|
query.running = true;
|
|
}
|
|
|
|
function absorb(text: string): void {
|
|
try {
|
|
const parsed = JSON.parse(text);
|
|
root.available = parsed.available === true;
|
|
root.devices = Array.isArray(parsed.devices) ? parsed.devices : [];
|
|
root.lastError = String(parsed.error ?? "");
|
|
} catch (error) {
|
|
root.lastError = "Could not read the portal's permissions.";
|
|
console.warn("Permissions: could not parse helper output:", error);
|
|
}
|
|
root.scanned = true;
|
|
}
|
|
|
|
function run(arguments: var): void {
|
|
if (mutation.running)
|
|
return;
|
|
root.lastError = "";
|
|
mutation.command = [root.helperPath].concat(arguments);
|
|
mutation.running = true;
|
|
}
|
|
|
|
function setAllowed(device: string, app: string, allowed: bool): void {
|
|
root.run(["set", device, app, allowed ? "allow" : "deny"]);
|
|
}
|
|
|
|
// Drops the recorded answer entirely, so the application is asked again the
|
|
// next time it wants the device.
|
|
function forget(device: string, app: string): void {
|
|
root.run(["forget", device, app]);
|
|
}
|
|
|
|
Component.onCompleted: root.refresh()
|
|
|
|
Process {
|
|
id: query
|
|
stdout: StdioCollector { onStreamFinished: root.absorb(this.text) }
|
|
stderr: StdioCollector {
|
|
onStreamFinished: if (this.text.trim() !== "") root.lastError = this.text.trim()
|
|
}
|
|
}
|
|
|
|
Process {
|
|
id: mutation
|
|
stdout: StdioCollector { onStreamFinished: root.absorb(this.text) }
|
|
stderr: StdioCollector {
|
|
onStreamFinished: if (this.text.trim() !== "") root.lastError = this.text.trim()
|
|
}
|
|
}
|
|
}
|