Files
Panama/config/dot/quickshell/services/UserAccounts.qml
T
Gabriel Brown a23b42841a Own user accounts and sharing
Two of the panels this desktop still handed to GNOME Settings.

Users manages the account through accountsservice -- the same daemon
GNOME's panel drives, so a name or picture set here is what the login
screen and lock screen read. Name, picture, account type, password,
automatic login, and adding or removing other accounts. Every change is
authorized by polkit through the agent this session already runs; a
dismissed prompt is a normal outcome and says so.

A new password is read from the helper's stdin, hashed by openssl
reading its own stdin, and handed over D-Bus from inside that process.
It is never an argument: argv is world-readable through /proc, so a
password passed that way is published to every process on the machine.
Removing an account takes two presses and says it destroys their files;
the last administrator cannot be removed or demoted, because a machine
nobody can administer is not a state to offer.

Sharing reports what is actually true, including "the software for this
is not installed" -- the honest answer for Samba here, and the case the
panel it replaces shows as a switch that does nothing. Password sign-in
is reported from sshd's configuration rather than assumed: claiming
"keys only" when the file is silent would state a security property that
cannot be backed up.

The Control Center now draws the account's real picture and name. A
generic glyph sat there while a real avatar was already set, which made
the desktop look like it did not know whose it was.

Also here: the KDE Connect contract no longer requires a phone to be
awake. kdeconnectd drops its device objects for a phone it has not seen
recently while the pairing survives in its config, so demanding one
failed whenever the phone was off.

Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
2026-08-19 13:05:13 -04:00

163 lines
5.9 KiB
QML

pragma Singleton
// User accounts, through accountsservice -- the daemon GNOME's Users panel
// drives, so what this changes is what every other login surface reads.
//
// Every change is authorized by polkit, which prompts through the agent this
// session already runs. A refused prompt is a normal outcome, not an error to
// apologize for, and it comes back as a plain sentence.
//
// No password ever crosses this file. Setting one writes it to the helper's
// stdin, which is the only path that keeps it off a command line.
import Quickshell
import Quickshell.Io
import QtQuick
Singleton {
id: root
readonly property string helperPath: Quickshell.shellDir + "/scripts/panama-users"
property var users: []
property string currentUser: ""
property int administratorCount: 0
property bool scanned: false
property string lastError: ""
// Guards read the Process objects rather than a derived "busy" binding. A
// binding hands back its cached value inside the handler that changes it,
// which silently turns a refresh after a successful change into a no-op --
// the write lands and the page never notices. See DefaultApps.qml.
readonly property bool busy: query.running || mutation.running || passwordWrite.running
readonly property var me: {
for (const user of root.users) {
if (user.userName === root.currentUser)
return user;
}
return root.users.length > 0 ? root.users[0] : null;
}
readonly property var others: root.users.filter(user => user.userName !== root.currentUser)
// The avatar, as a URL the shell can draw, or "" when none is set.
readonly property string avatarUrl: root.me && String(root.me.iconFile ?? "") !== ""
? "file://" + root.me.iconFile
: ""
function displayName(user: var): string {
const real = String(user?.realName ?? "").trim();
return real !== "" ? real : String(user?.userName ?? "");
}
function refresh(): void {
if (query.running)
return;
query.command = [root.helperPath, "snapshot"];
query.running = true;
}
function absorb(text: string): void {
try {
const parsed = JSON.parse(text);
root.users = Array.isArray(parsed.users) ? parsed.users : [];
root.currentUser = String(parsed.currentUser ?? "");
root.administratorCount = Number(parsed.administratorCount ?? 0);
root.lastError = String(parsed.error ?? "");
} catch (error) {
root.lastError = "Could not read the account service's answer.";
console.warn("Accounts: could not parse helper output:", error);
}
root.scanned = true;
}
function run(arguments: var): void {
if (mutation.running)
return;
root.lastError = "";
mutation.command = [root.helperPath].concat(arguments);
mutation.running = true;
}
function setRealName(userName: string, name: string): void {
root.run(["set-real-name", userName, name]);
}
function setIcon(userName: string, path: string): void {
root.run(["set-icon", userName, path]);
}
function setAccountType(userName: string, kind: string): void {
root.run(["set-account-type", userName, kind]);
}
function setAutomaticLogin(userName: string, enabled: bool): void {
root.run(["set-automatic-login", userName, enabled ? "true" : "false"]);
}
function createUser(userName: string, realName: string, kind: string): void {
root.run(["create-user", userName, realName, kind]);
}
function deleteUser(userName: string, removeFiles: bool): void {
root.run(["delete-user", userName, removeFiles ? "remove-files" : "keep-files"]);
}
// The password goes to the helper's stdin and nowhere else: never an
// argument, because argv is readable by every process on this machine.
//
// It is written from onStarted rather than here, because a process has no
// stdin to write to until it is actually running. The same pattern
// HomeAssistantConfig uses for its token.
property string pendingPassword: ""
function setPassword(userName: string, password: string): void {
if (passwordWrite.running)
return;
root.lastError = "";
root.pendingPassword = password;
passwordWrite.command = [root.helperPath, "set-password", userName];
passwordWrite.running = true;
}
// Self-initializing: the Control Center draws the avatar too, and a
// singleton is constructed on first use, so whichever surface asks first
// gets a populated service without having to know to ask.
Component.onCompleted: root.refresh()
Process {
id: query
stdout: StdioCollector { onStreamFinished: root.absorb(this.text) }
stderr: StdioCollector {
onStreamFinished: if (this.text.trim() !== "") root.lastError = this.text.trim()
}
}
Process {
id: passwordWrite
stdinEnabled: true
onStarted: {
passwordWrite.write(root.pendingPassword + "\n");
// Held for as long as it takes to hand over, and no longer.
root.pendingPassword = "";
passwordWrite.stdinEnabled = false;
}
stdout: StdioCollector { onStreamFinished: root.absorb(this.text) }
stderr: StdioCollector {
onStreamFinished: if (this.text.trim() !== "") root.lastError = this.text.trim()
}
onExited: root.pendingPassword = ""
}
Process {
id: mutation
// The helper answers with the fresh state, so the page updates from the
// mutation itself and never has to ask again.
stdout: StdioCollector { onStreamFinished: root.absorb(this.text) }
stderr: StdioCollector {
onStreamFinished: if (this.text.trim() !== "") root.lastError = this.text.trim()
}
}
}