2015-08-28 14:31:05 +00:00
|
|
|
{ config, lib, pkgs, ... }:
|
2015-07-16 13:51:01 +00:00
|
|
|
|
|
|
|
let
|
2016-02-21 23:50:01 +00:00
|
|
|
inherit (config.krebs.lib) genid;
|
|
|
|
|
2015-07-16 13:51:01 +00:00
|
|
|
mainUser = config.users.extraUsers.mainUser;
|
2015-09-19 21:42:05 +00:00
|
|
|
createChromiumUser = name: extraGroups: packages:
|
2015-08-28 14:31:05 +00:00
|
|
|
{
|
2015-10-03 12:37:56 +00:00
|
|
|
users.extraUsers.${name} = {
|
|
|
|
inherit name;
|
|
|
|
inherit extraGroups;
|
|
|
|
home = "/home/${name}";
|
2016-02-21 23:50:01 +00:00
|
|
|
uid = genid name;
|
2015-10-03 12:37:56 +00:00
|
|
|
useDefaultShell = true;
|
|
|
|
createHome = true;
|
2015-08-28 14:31:05 +00:00
|
|
|
};
|
2016-05-04 15:17:48 +00:00
|
|
|
krebs.per-user.${name}.packages = packages;
|
2015-08-28 14:31:05 +00:00
|
|
|
security.sudo.extraConfig = ''
|
|
|
|
${mainUser.name} ALL=(${name}) NOPASSWD: ALL
|
|
|
|
'';
|
|
|
|
environment.systemPackages = [
|
2015-12-12 17:24:32 +00:00
|
|
|
(pkgs.writeScriptBin name ''
|
|
|
|
/var/setuid-wrappers/sudo -u ${name} -i chromium $@
|
2015-08-28 14:31:05 +00:00
|
|
|
'')
|
|
|
|
];
|
|
|
|
};
|
2015-07-16 13:51:01 +00:00
|
|
|
|
2015-09-19 21:42:05 +00:00
|
|
|
createFirefoxUser = name: extraGroups: packages:
|
|
|
|
{
|
2015-10-03 12:37:56 +00:00
|
|
|
users.extraUsers.${name} = {
|
|
|
|
inherit name;
|
|
|
|
inherit extraGroups;
|
|
|
|
home = "/home/${name}";
|
2016-02-21 23:50:01 +00:00
|
|
|
uid = genid name;
|
2015-10-03 12:37:56 +00:00
|
|
|
useDefaultShell = true;
|
|
|
|
createHome = true;
|
2015-09-19 21:42:05 +00:00
|
|
|
};
|
2016-05-04 15:17:48 +00:00
|
|
|
krebs.per-user.${name}.packages = packages;
|
2015-09-19 21:42:05 +00:00
|
|
|
security.sudo.extraConfig = ''
|
|
|
|
${mainUser.name} ALL=(${name}) NOPASSWD: ALL
|
|
|
|
'';
|
|
|
|
environment.systemPackages = [
|
2015-12-12 17:24:32 +00:00
|
|
|
(pkgs.writeScriptBin name ''
|
|
|
|
/var/setuid-wrappers/sudo -u ${name} -i firefox $@
|
2015-09-19 21:42:05 +00:00
|
|
|
'')
|
|
|
|
];
|
|
|
|
};
|
|
|
|
|
2015-09-05 10:13:14 +00:00
|
|
|
#TODO: abstract this
|
|
|
|
|
2015-07-16 13:51:01 +00:00
|
|
|
in {
|
|
|
|
|
2015-09-05 10:13:14 +00:00
|
|
|
environment.systemPackages = [
|
2015-12-12 17:24:32 +00:00
|
|
|
(pkgs.writeScriptBin "browser-select" ''
|
2016-02-21 23:51:22 +00:00
|
|
|
BROWSER=$(echo -e "ff\ncr\nwk\nfb\ngm\nflash" | dmenu)
|
2015-09-05 10:13:14 +00:00
|
|
|
$BROWSER $@
|
|
|
|
'')
|
|
|
|
];
|
|
|
|
|
2015-08-28 14:31:05 +00:00
|
|
|
imports = [
|
2016-02-21 23:51:22 +00:00
|
|
|
( createFirefoxUser "ff" [ "audio" ] [ pkgs.firefox ] )
|
2015-09-19 21:42:05 +00:00
|
|
|
( createChromiumUser "cr" [ "audio" ] [ pkgs.chromium ] )
|
2016-02-21 23:51:22 +00:00
|
|
|
( createChromiumUser "wk" [ "audio" ] [ pkgs.chromium ] )
|
|
|
|
( createChromiumUser "fb" [ "audio" ] [ pkgs.chromium ] )
|
|
|
|
( createChromiumUser "gm" [ "audio" ] [ pkgs.chromium ] )
|
2016-02-16 16:12:39 +00:00
|
|
|
( createChromiumUser "flash" [ "audio" ] [ pkgs.flash ] )
|
2015-07-16 13:51:01 +00:00
|
|
|
];
|
|
|
|
|
2015-08-28 14:31:05 +00:00
|
|
|
nixpkgs.config.packageOverrides = pkgs : {
|
|
|
|
flash = pkgs.chromium.override {
|
2015-10-01 20:29:20 +00:00
|
|
|
# pulseSupport = true;
|
2015-08-28 14:31:05 +00:00
|
|
|
enablePepperFlash = true;
|
2015-07-16 13:51:01 +00:00
|
|
|
};
|
2015-10-01 20:17:43 +00:00
|
|
|
#chromium = pkgs.chromium.override {
|
|
|
|
# pulseSupport = true;
|
|
|
|
#};
|
2015-07-16 13:51:01 +00:00
|
|
|
};
|
|
|
|
}
|