diff options
Diffstat (limited to 'flake.nix')
| -rw-r--r-- | flake.nix | 73 |
1 files changed, 73 insertions, 0 deletions
diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..9daf707 --- /dev/null +++ b/flake.nix @@ -0,0 +1,73 @@ +{ + description = "PAM module that runs multiple PAM modules in parallel, succeeding if any one succeeds"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; + }; + + outputs = { self, nixpkgs }: + let + system = "x86_64-linux"; + pkgs = nixpkgs.legacyPackages.${system}; + in + { + packages.${system}.default = pkgs.callPackage ./default.nix {}; + + nixosModules.default = { config, pkgs, lib, ... }: + let + cfg = config.security.pam-any; + pam-any = self.packages.${pkgs.stdenv.hostPlatform.system}.default; + + pamAnyConfig = builtins.toJSON { + mode = "One"; + modules = cfg.modules; + }; + in + { + options.security.pam-any = { + enable = lib.mkEnableOption "pam-any parallel authentication"; + + modules = lib.mkOption { + type = lib.types.attrsOf lib.types.str; + default = { + pam-any-fingerprint = "Fingerprint"; + pam-any-password = "Password"; + }; + description = "Map of PAM service names to display labels for parallel auth."; + }; + + services = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ "sudo" "login" ]; + description = "PAM services to apply pam-any to."; + }; + + order = lib.mkOption { + type = lib.types.int; + default = 1000; + description = "Order of the pam-any rule in the auth stack."; + }; + }; + + config = lib.mkIf cfg.enable { + security.pam.services = { + pam-any-fingerprint.text = '' + auth required ${pkgs.fprintd}/lib/security/pam_fprintd.so + ''; + + pam-any-password.text = '' + auth required ${pkgs.linux-pam}/lib/security/pam_unix.so + ''; + } // lib.genAttrs cfg.services (_name: { + fprintAuth = false; + rules.auth.pam-any = { + order = cfg.order; + control = "sufficient"; + modulePath = "${pam-any}/lib/security/pam_any.so"; + args = [ pamAnyConfig ]; + }; + }); + }; + }; + }; +} |
