1
0
mirror of https://github.com/AvengeMedia/DankMaterialShell.git synced 2026-08-04 04:28:30 -04:00

refactor(auth): relay on distro system auth over DMS managed sessions

- Gate greeter external-auth status fprint availability only on confirmed setups
- Reload dankshell-U2F/U2F-Key watchers live

Related: #2874
Port 1.5

(cherry picked from commit 3938e60ce4)
This commit is contained in:
purian23
2026-07-17 17:27:45 -04:00
parent fc11dfbc57
commit f37f4a1f35
8 changed files with 296 additions and 272 deletions
+22 -22
View File
@@ -19,39 +19,39 @@ Item {
function greeterFingerprintDescription() {
if (SettingsData.greeterPamExternallyManaged)
return "greetd PAM is externally managed";
return I18n.tr("Managed by the primary PAM source", "factor managed by PAM source status");
if (SettingsData.greeterFingerprintSource === "pam")
return I18n.tr("PAM already provides fingerprint auth. Enable this to show it at login.", "greeter fingerprint login setting");
switch (SettingsData.greeterFingerprintReason) {
case "ready":
return I18n.tr("Authentication changes apply automatically.", "greeter auth setting description");
return I18n.tr("Authentication changes apply automatically", "greeter auth setting description");
case "missing_enrollment":
return I18n.tr("Fingerprint reader detected, but no prints are enrolled yet. You can enable this now and run Sync later.", "greeter fingerprint login setting");
case "missing_reader":
return I18n.tr("No fingerprint reader detected.", "fingerprint setting status");
return I18n.tr("No fingerprint reader detected", "fingerprint setting status");
case "missing_pam_support":
return I18n.tr("Not available — install fprintd and pam_fprintd, or configure greetd PAM.", "greeter fingerprint login setting");
default:
return I18n.tr("Fingerprint availability could not be confirmed.", "fingerprint setting status");
return I18n.tr("Fingerprint availability could not be confirmed", "fingerprint setting status");
}
}
function greeterU2fDescription() {
if (SettingsData.greeterPamExternallyManaged)
return "greetd PAM is externally managed";
return I18n.tr("Managed by the primary PAM source", "factor managed by PAM source status");
if (SettingsData.greeterU2fSource === "pam")
return I18n.tr("PAM already provides security-key auth. Enable this to show it at login.", "greeter security key login setting");
switch (SettingsData.greeterU2fReason) {
case "ready":
return I18n.tr("Authentication changes apply automatically.", "greeter auth setting description");
return I18n.tr("Authentication changes apply automatically", "greeter auth setting description");
case "missing_key_registration":
return I18n.tr("Security-key support was detected, but no registered key was found yet. You can enable this now and register one later.", "security key setting status");
case "missing_pam_support":
return I18n.tr("Not available — install or configure pam_u2f, or configure greetd PAM.", "greeter security key login setting");
default:
return I18n.tr("Security-key availability could not be confirmed.", "security key setting status");
return I18n.tr("Security-key availability could not be confirmed", "security key setting status");
}
}
@@ -305,7 +305,7 @@ Item {
onExited: exitCode => {
root.greeterSyncRunning = false;
if (exitCode === 0) {
var launched = root.greeterTerminalFallbackFromPrecheck ? I18n.tr("Terminal opened. Complete sync authentication there; it will close automatically when done.") : I18n.tr("Terminal fallback opened. Complete sync there; it will close automatically when done.");
var launched = root.greeterTerminalFallbackFromPrecheck ? I18n.tr("Terminal opened. Complete authentication there; it will close automatically when done.") : I18n.tr("Terminal fallback opened. Complete authentication there; it will close automatically when done.");
root.greeterStatusText = root.greeterStatusText ? root.greeterStatusText + "\n\n" + launched : launched;
SettingsData.clearGreeterSyncPending();
return;
@@ -396,11 +396,11 @@ Item {
SettingsCard {
width: parent.width
iconName: "info"
title: I18n.tr("Greeter Status")
title: I18n.tr("Status")
settingKey: "greeterStatus"
StyledText {
text: I18n.tr("Sync applies your theme and settings to the login screen. Other users should run dms greeter sync --profile instead of a full sync. Authentication changes apply automatically.")
text: I18n.tr("Sync applies your theme and settings to the login screen. Shared users should run dms greeter sync --profile instead of a primary user sync.")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -470,11 +470,11 @@ Item {
SettingsCard {
width: parent.width
iconName: "fingerprint"
title: I18n.tr("Login Authentication")
title: I18n.tr("Authentication")
settingKey: "greeterAuth"
StyledText {
text: I18n.tr("Enable fingerprint or security key for DMS Greeter. Authentication changes apply automatically.")
text: I18n.tr("Enable fingerprint or security key for DMS Greeter")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -485,8 +485,8 @@ Item {
SettingsToggleRow {
settingKey: "greeterPamExternallyManaged"
tags: ["greeter", "pam", "managed", "external", "greetd", "auth"]
text: "greetd PAM is externally managed"
description: "DMS removes its managed block from /etc/pam.d/greetd and stops writing to it"
text: I18n.tr("Use system PAM authentication", "system PAM policy toggle")
description: I18n.tr("DMS removes its managed block from /etc/pam.d/greetd and stops write services", "greeter system PAM toggle description")
checked: SettingsData.greeterPamExternallyManaged
onToggled: checked => SettingsData.set("greeterPamExternallyManaged", checked)
}
@@ -517,7 +517,7 @@ Item {
SettingsCard {
width: parent.width
iconName: "palette"
title: I18n.tr("Greeter Appearance")
title: I18n.tr("Appearance")
settingKey: "greeterAppearance"
StyledText {
@@ -553,12 +553,12 @@ Item {
settingKey: "greeterLockDateFormat"
tags: ["greeter", "date", "format"]
text: I18n.tr("Date Format")
description: I18n.tr("Greeter only — format for the date on the login screen")
description: I18n.tr("Format the date on the login screen")
options: root._lockDateFormatPresets.map(p => p.label)
currentValue: {
var current = (SettingsData.greeterLockDateFormat !== undefined && SettingsData.greeterLockDateFormat !== "") ? SettingsData.greeterLockDateFormat : SettingsData.lockDateFormat || "";
var match = root._lockDateFormatPresets.find(p => p.format === current);
return match ? match.label : (current ? I18n.tr("Custom: ") + current : root._lockDateFormatPresets[0].label);
return match ? match.label : (current ? I18n.tr("Custom") + ": " + current : root._lockDateFormatPresets[0].label);
}
onValueChanged: value => {
var preset = root._lockDateFormatPresets.find(p => p.label === value);
@@ -577,7 +577,7 @@ Item {
}
StyledText {
text: I18n.tr("Use a custom image for the login screen, or leave empty to use your desktop wallpaper.")
text: I18n.tr("Use a custom image for the login screen, or leave empty to use desktop wallpaper")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -601,11 +601,11 @@ Item {
SettingsCard {
width: parent.width
iconName: "history"
title: I18n.tr("Greeter Behavior")
title: I18n.tr("Behavior")
settingKey: "greeterBehavior"
StyledText {
text: I18n.tr("Convenience options for the login screen. Sync to apply.")
text: I18n.tr("Convenience options for the login screen")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -649,7 +649,7 @@ Item {
settingKey: "greeterDeps"
StyledText {
text: I18n.tr("Requires greetd, dms-greeter, and your user in the greeter group (plus fprintd/pam_fprintd for fingerprint, pam_u2f for security keys). Auth changes apply automatically and may open a terminal for sudo.")
text: I18n.tr("Requires greetd, dms-greeter, and your user in the greeter group (plus fprintd/pam_fprintd for fingerprint, pam_u2f for security keys).")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -658,7 +658,7 @@ Item {
}
StyledText {
text: I18n.tr("Installation and PAM setup: see the ") + "<a href=\"https://danklinux.com/docs/dankgreeter/installation\" style=\"text-decoration:none; color:" + Theme.primary + ";\">DankGreeter docs</a> " + I18n.tr("or run ") + "'dms greeter install'."
text: I18n.tr("Installation and PAM setup are documented in the ") + "<a href=\"https://danklinux.com/docs/dankgreeter/installation\" style=\"text-decoration:none; color:" + Theme.primary + ";\">DankGreeter docs.</a> "
textFormat: Text.RichText
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
+27 -38
View File
@@ -96,28 +96,28 @@ Item {
function lockFingerprintDescription() {
switch (SettingsData.lockFingerprintReason) {
case "ready":
return I18n.tr("Use fingerprint authentication for the lock screen.", "lock screen fingerprint setting");
return I18n.tr("Use fingerprint authentication for the lock screen", "lock screen fingerprint setting");
case "missing_enrollment":
return I18n.tr("Fingerprint reader detected, but no prints are enrolled yet. You can enable this now and enroll later.", "lock screen fingerprint setting");
case "missing_reader":
return I18n.tr("No fingerprint reader detected.", "fingerprint setting status");
return I18n.tr("No fingerprint reader detected", "fingerprint setting status");
case "missing_pam_support":
return I18n.tr("Not available install fprintd and pam_fprintd.", "lock screen fingerprint setting");
return I18n.tr("Not available - install fprintd and pam_fprintd", "lock screen fingerprint setting");
default:
return I18n.tr("Fingerprint availability could not be confirmed.", "fingerprint setting status");
return I18n.tr("Fingerprint availability could not be confirmed", "fingerprint setting status");
}
}
function lockU2fDescription() {
switch (SettingsData.lockU2fReason) {
case "ready":
return I18n.tr("Use a security key for lock screen authentication.", "lock screen U2F security key setting");
return I18n.tr("Use a security key for lock screen authentication", "lock screen U2F security key setting");
case "missing_key_registration":
return I18n.tr("Security-key support was detected, but no registered key was found yet. You can enable this now and register one later.", "security key setting status");
case "missing_pam_support":
return I18n.tr("Not available install or configure pam_u2f.", "lock screen security key setting");
return I18n.tr("Not available - install or configure pam_u2f", "lock screen security key setting");
default:
return I18n.tr("Security-key availability could not be confirmed.", "security key setting status");
return I18n.tr("Security-key availability could not be confirmed", "security key setting status");
}
}
@@ -192,12 +192,12 @@ Item {
} catch (e) {}
if (!data) {
root.authValidateMessage = "Validation failed — is DMS in PATH?";
root.authValidateMessage = I18n.tr("Config validation failed");
return;
}
if (!data.valid) {
const errs = Array.isArray(data.errors) ? data.errors : [];
root.authValidateMessage = ["Not applied.", ...errs].join("\n");
root.authValidateMessage = [I18n.tr("Config validation failed"), ...errs].join("\n");
return;
}
@@ -207,7 +207,7 @@ Item {
const warns = Array.isArray(data.warnings) ? data.warnings : [];
root.authValidateOk = true;
root.authValidateWarn = warns.length > 0;
root.authValidateMessage = warns.length > 0 ? ["Applied with warnings.", ...warns].join("\n") : "Applied.";
root.authValidateMessage = [I18n.tr("Authentication changes applied"), ...warns].join("\n");
}
}
@@ -232,12 +232,12 @@ Item {
} catch (e) {}
if (!data) {
root.u2fValidateMessage = "Validation failed — is DMS in PATH?";
root.u2fValidateMessage = I18n.tr("Config validation failed");
return;
}
if (!data.valid) {
const errs = Array.isArray(data.errors) ? data.errors : [];
root.u2fValidateMessage = ["Not applied.", ...errs].join("\n");
root.u2fValidateMessage = [I18n.tr("Config validation failed"), ...errs].join("\n");
return;
}
@@ -245,7 +245,7 @@ Item {
const warns = Array.isArray(data.warnings) ? data.warnings : [];
root.u2fValidateOk = true;
root.u2fValidateWarn = warns.length > 0;
root.u2fValidateMessage = warns.length > 0 ? ["Applied with warnings.", ...warns].join("\n") : "Applied.";
root.u2fValidateMessage = [I18n.tr("Authentication changes applied"), ...warns].join("\n");
root.refreshAuthDetection();
}
}
@@ -266,7 +266,7 @@ Item {
SettingsCard {
width: parent.width
iconName: "lock"
title: I18n.tr("Lock Screen layout")
title: I18n.tr("Layout")
settingKey: "lockLayout"
SettingsToggleRow {
@@ -345,7 +345,7 @@ Item {
SettingsCard {
width: parent.width
iconName: "palette"
title: I18n.tr("Lock Screen Appearance")
title: I18n.tr("Appearance")
settingKey: "lockAppearance"
StyledText {
@@ -396,11 +396,11 @@ Item {
SettingsCard {
width: parent.width
iconName: "key"
title: I18n.tr("Lock Screen Authentication")
title: I18n.tr("Authentication")
settingKey: "lockAuthSource"
StyledText {
text: I18n.tr("Changes apply automatically")
text: I18n.tr("Authentication changes apply automatically")
font.pixelSize: Theme.fontSizeSmall
color: Theme.surfaceVariantText
width: parent.width
@@ -410,8 +410,8 @@ Item {
SettingsDropdownRow {
settingKey: "lockPamPath"
tags: ["lock", "screen", "pam", "authentication", "source", "service"]
text: "Authentication Source"
description: SettingsData.lockPamPath !== "" ? SettingsData.lockPamPath : "Which PAM service the lock screen uses to authenticate"
text: I18n.tr("Authentication Source", "lock screen PAM source setting")
description: SettingsData.lockPamPath !== "" ? SettingsData.lockPamPath : I18n.tr("Which PAM service the lock screen uses to authenticate", "lock screen PAM source setting")
options: root.authOptions
currentValue: root.authCurrentValue
onValueChanged: value => {
@@ -472,21 +472,10 @@ Item {
}
}
StyledText {
visible: !SettingsData.lockPamExternallyManaged && (root.primaryPamHasFprint || root.primaryPamHasU2f)
text: I18n.tr("Selected PAM source already manages the detected factors.")
font.pixelSize: Theme.fontSizeSmall
color: Theme.warning
width: parent.width
wrapMode: Text.Wrap
topPadding: Theme.spacingS
}
SettingsToggleRow {
settingKey: "lockPamExternallyManaged"
tags: ["lock", "screen", "pam", "managed", "external", "authentication", "policy"]
text: I18n.tr("Use system PAM authentication")
description: SettingsData.lockPamExternallyManaged ? I18n.tr("System PAM sets the authentication policy.") : I18n.tr("DMS manages the factors below.")
text: I18n.tr("Use system PAM authentication", "system PAM policy toggle")
checked: SettingsData.lockPamExternallyManaged
onToggled: checked => SettingsData.set("lockPamExternallyManaged", checked)
}
@@ -495,7 +484,7 @@ Item {
settingKey: "enableFprint"
tags: ["lock", "screen", "fingerprint", "authentication", "biometric", "fprint"]
text: I18n.tr("Enable fingerprint authentication")
description: root.lockFprintControlledByPrimary ? I18n.tr("Managed by the primary PAM source.") : root.lockFingerprintDescription()
description: root.lockFprintControlledByPrimary ? I18n.tr("Managed by the primary PAM source", "factor managed by PAM source status") : root.lockFingerprintDescription()
descriptionColor: root.lockFprintControlledByPrimary || SettingsData.lockFingerprintReason === "ready" ? Theme.surfaceVariantText : Theme.warning
checked: SettingsData.enableFprint || root.primaryPamHasFprint
enabled: root.lockFprintToggleAvailable && !root.lockFprintControlledByPrimary
@@ -506,7 +495,7 @@ Item {
settingKey: "enableU2f"
tags: ["lock", "screen", "u2f", "yubikey", "security", "key", "fido", "authentication", "hardware"]
text: I18n.tr("Enable security key authentication", "Enable FIDO2/U2F hardware security key for lock screen")
description: root.lockU2fControlledByPrimary ? I18n.tr("Managed by the primary PAM source.") : root.lockU2fDescription()
description: root.lockU2fControlledByPrimary ? I18n.tr("Managed by the primary PAM source", "factor managed by PAM source status") : root.lockU2fDescription()
descriptionColor: root.lockU2fControlledByPrimary || SettingsData.lockU2fReason === "ready" ? Theme.surfaceVariantText : Theme.warning
checked: SettingsData.enableU2f || root.primaryPamHasU2f
enabled: root.lockU2fToggleAvailable && !root.lockU2fControlledByPrimary
@@ -517,7 +506,7 @@ Item {
settingKey: "u2fMode"
tags: ["lock", "screen", "u2f", "yubikey", "security", "key", "mode", "factor", "second"]
text: I18n.tr("Security key mode", "lock screen U2F security key mode setting")
description: I18n.tr("Alternative uses the passkey button. Second factor follows password or fingerprint.", "lock screen U2F security key mode setting")
description: I18n.tr("'Alternative' lets the key unlock on its own. 'Second factor' requires password or fingerprint first, then the key.", "lock screen U2F security key mode setting")
visible: SettingsData.enableU2f && !root.lockU2fControlledByPrimary
options: [I18n.tr("Alternative (OR)", "U2F mode option: key works as standalone unlock method"), I18n.tr("Second Factor (AND)", "U2F mode option: key required after password or fingerprint")]
currentValue: SettingsData.u2fMode === "and" ? I18n.tr("Second Factor (AND)", "U2F mode option: key required after password or fingerprint") : I18n.tr("Alternative (OR)", "U2F mode option: key works as standalone unlock method")
@@ -532,8 +521,8 @@ Item {
SettingsDropdownRow {
settingKey: "lockU2fPamPath"
tags: ["lock", "screen", "pam", "u2f", "security", "key", "source", "service"]
text: I18n.tr("Security Key PAM Source")
description: SettingsData.lockU2fPamPath !== "" ? SettingsData.lockU2fPamPath : I18n.tr("Auto uses an installed or bundled key-only service.")
text: I18n.tr("Security Key PAM Source", "lock screen dedicated U2F PAM source setting")
description: SettingsData.lockU2fPamPath !== "" ? SettingsData.lockU2fPamPath : I18n.tr("Auto uses an installed or bundled key-only service.", "lock screen dedicated U2F PAM source setting")
visible: !root.lockU2fControlledByPrimary
options: [root.authAutoLabel, root.authCustomLabel]
currentValue: root.u2fAuthCurrentValue
@@ -592,7 +581,7 @@ Item {
SettingsCard {
width: parent.width
iconName: "lock"
title: I18n.tr("Lock Screen behaviour")
title: I18n.tr("Behavior")
settingKey: "lockBehavior"
StyledText {
@@ -731,7 +720,7 @@ Item {
SettingsCard {
width: parent.width
iconName: "monitor"
title: I18n.tr("Lock Screen Display")
title: I18n.tr("Display Assignment")
settingKey: "lockDisplay"
StyledText {