NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

floorp.nix (5774B)


      1 # modules/home/floorp.nix — Floorp, themed with ShyFox. Zen is the default
      2 # browser now (modules/home/zen.nix owns xdg.mimeApps and $BROWSER); Floorp
      3 # stays installed with its profile and bookmarks.
      4 #
      5 # The profile is written by hand under ~/.config/floorp (Floorp 12's location)
      6 # rather than through `programs.floorp.profiles.*`: home-manager's Floorp module
      7 # still targets ~/.floorp (Floorp 11), so anything set there is ignored without
      8 # an error. `programs.floorp.enable` below is used for the package only.
      9 #
     10 # The private parts are sops secrets, not Nix (see .sops.yaml):
     11 #   secrets/floorp/user.js         every pref, placed at <profile>/user.js by
     12 #                                  sops-nix at login and on every switch
     13 #   secrets/floorp/bookmarks.html  the bookmarks export Floorp imports once, on a
     14 #                                  fresh profile (browser.bookmarks.file in user.js)
     15 # Edit either with `TMPDIR=/dev/shm sops secrets/floorp/<file>`, then
     16 # `nh os switch` and restart Floorp, which reads user.js only at startup.
     17 # Saved passwords, cookies, history and sessions are written by Floorp into the
     18 # profile and are never in this repo.
     19 #
     20 # The theme is ShyFox, vendored from the gitlab.com/DAEMON-404/ShyFox fork
     21 # (synced at 6b69ed8, which fixes Gecko 157) into _shyfox/ and linked as
     22 # <profile>/chrome. To pull a newer fork: rsync its chrome/ over _shyfox/
     23 # excluding userChrome.css and userContent.css. `/_` keeps the asset tree out of
     24 # import-tree's reach (see flake.nix).
     25 { ... }:
     26 {
     27   flake.homeModules.floorp =
     28   { config, lib, pkgs, ... }:
     29   let
     30     profile = "shyfox";
     31     profileDir = "floorp/${profile}";
     32     previousProfile = "1il5n65w.default"; # kept, not default
     33 
     34     ##### Extensions ############################################################
     35     # ShyFox needs both of these: Sidebery provides the sidebar the theme is
     36     # built around, and Userchrome Toggle Extended (by Naezr, who writes ShyFox)
     37     # binds the toggle. Each file has to be named for the add-on's own ID.
     38     # `extensions.startupScanScopes`/`autoDisableScopes` in user.js are
     39     # what make a profile-dropped add-on come up enabled instead of parked as a
     40     # disabled sideload.
     41     extensions = {
     42       "{3c078156-979c-498b-8990-85f7987dd929}" = pkgs.fetchurl {
     43         name = "sidebery-5.6.1.xpi";
     44         url = "https://addons.mozilla.org/firefox/downloads/file/4903712/sidebery-5.6.1.xpi";
     45         sha256 = "e8a0a4b556ab7dd536897c1816af9d0918030223068ea6683a04376103a6caf2";
     46       };
     47       "userchrome-toggle-extended@n2ezr.ru" = pkgs.fetchurl {
     48         name = "userchrome_toggle_extended-2.0.1.xpi";
     49         url = "https://addons.mozilla.org/firefox/downloads/file/4341014/userchrome_toggle_extended-2.0.1.xpi";
     50         sha256 = "3f5be2684284c0b79aaad0f70872a87f21a9a1329a5eaf8e60090e6f0e6a741d";
     51       };
     52     };
     53   in
     54   {
     55     # The package only — see the header for why the profile is not built with
     56     # `programs.floorp.profiles.*`.
     57     programs.floorp.enable = true;
     58 
     59     # Every pref (start page, fonts, ShyFox options, Floorp's design settings and
     60     # switched-off extras) as one encrypted file, symlinked to where Floorp reads it.
     61     sops.secrets."floorp-user.js" = {
     62       sopsFile = ../../secrets/floorp/user.js;
     63       format = "binary";
     64       path = "${config.xdg.configHome}/${profileDir}/user.js";
     65     };
     66     # The bookmarks export, at ~/.config/sops-nix/secrets/floorp-bookmarks.html.
     67     sops.secrets."floorp-bookmarks.html" = {
     68       sopsFile = ../../secrets/floorp/bookmarks.html;
     69       format = "binary";
     70     };
     71 
     72     xdg.configFile =
     73       {
     74         # Written here rather than left to Floorp so the themed profile is the
     75         # default. The trade-off: profile changes made in Floorp's own UI are
     76         # reverted on the next `nh os switch`.
     77         "floorp/profiles.ini".text = ''
     78           [Profile0]
     79           Name=${profile}
     80           IsRelative=1
     81           Path=${profile}
     82           Default=1
     83 
     84           [Profile1]
     85           Name=default
     86           IsRelative=1
     87           Path=${previousProfile}
     88 
     89           [General]
     90           StartWithLastProfile=1
     91           Version=2
     92         '';
     93 
     94         # The whole theme tree, read-only out of the store. To change the CSS,
     95         # edit modules/home/floorp/_shyfox/ and rebuild. wallpaper.png and
     96         # wallpaper-light.png are the new-tab backgrounds ShyFox's new-tab CSS
     97         # references; replace either file to change them.
     98         "${profileDir}/chrome".source = ./floorp/_shyfox;
     99       }
    100       // lib.mapAttrs' (id: xpi: lib.nameValuePair "${profileDir}/extensions/${id}.xpi" { source = xpi; }) extensions;
    101 
    102     # One-time bookmark import.
    103     #
    104     # `browser.places.importBookmarksHTML` is the pref that makes Firefox read
    105     # browser.bookmarks.file into the places database. It cannot live in user.js:
    106     # Firefox consumes it and sets it back to false, but user.js re-applies
    107     # every pref at every startup, so the import would run again on each launch
    108     # and duplicate every bookmark. Seeding it into prefs.js instead, only while
    109     # the profile has no places.sqlite yet, imports once on first launch and
    110     # never again.
    111     home.activation.floorpSeedBookmarkImport = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
    112       floorpProfile="${config.xdg.configHome}/${profileDir}"
    113       floorpPrefs="$floorpProfile/prefs.js"
    114       if [ ! -e "$floorpProfile/places.sqlite" ] \
    115         && ! grep -qs 'browser.places.importBookmarksHTML' "$floorpPrefs"; then
    116         verboseEcho "Floorp: seeding the one-time bookmark import in $floorpPrefs"
    117         if [ -z "''${DRY_RUN:-}" ]; then
    118           mkdir -p "$floorpProfile"
    119           printf '%s\n' 'user_pref("browser.places.importBookmarksHTML", true);' >> "$floorpPrefs"
    120         fi
    121       fi
    122     '';
    123   }
    124   ;
    125 }