{ lib, pkgs, config, ... }: { options = { myServices.pub.enable = lib.mkOption { type = lib.types.bool; default = false; description = '' Whether to enable pub user. ''; }; }; config = lib.mkIf config.myServices.pub.enable { myServices.chatonsProperties.services.vm-like = { file.datetime = "2022-08-22T01:00:00"; service = { name = "Comptes shell"; description = "Compte shell cloisonné"; logo = "https://www.openssh.com/favicon.ico"; website = "pub.immae.eu"; status.level = "OK"; status.description = "OK"; registration."" = ["MEMBER" "CLIENT"]; registration.load = "OPEN"; install.type = "PACKAGE"; }; software = { name = "Openssh"; website = "https://www.openssh.com/"; license.url = "https://github.com/openssh/openssh-portable/blob/master/LICENCE"; license.name = "BSD Licence"; version = pkgs.openssh.version; source.url = "https://github.com/openssh/openssh-portable"; }; }; myServices.ssh.modules = [{ snippet = builtins.readFile ./ldap_pub.sh; dependencies = [ pkgs.coreutils ]; }]; users.users.pub = let restrict = pkgs.runCommand "restrict" { file = ./restrict; buildInputs = [ pkgs.makeWrapper ]; } '' mkdir -p $out/bin cp $file $out/bin/restrict chmod a+x $out/bin/restrict patchShebangs $out/bin/restrict wrapProgram $out/bin/restrict \ --prefix PATH : ${lib.makeBinPath [ pkgs.bubblewrap pkgs.rrsync ]} \ --set TMUX_RESTRICT ${./tmux.restrict.conf} ''; purple-hangouts = pkgs.purple-hangouts.overrideAttrs(old: { installPhase = '' install -Dm755 -t $out/lib/purple-2/ libhangouts.so for size in 16 22 24 48; do install -TDm644 hangouts$size.png $out/share/pixmaps/pidgin/protocols/$size/hangouts.png done ''; }); in { createHome = true; description = "Restricted shell user"; home = "/var/lib/pub"; uid = config.myEnv.users.pub.uid; isNormalUser = true; group = "nogroup"; useDefaultShell = true; packages = [ restrict pkgs.tmux (pkgs.pidgin.override { plugins = [ pkgs.purple-plugin-pack purple-hangouts pkgs.purple-discord pkgs.purple-facebook pkgs.telegram-purple ]; }) ]; }; }; }