feat: add a setting for sudo over ssh

This commit is contained in:
Felitendo committed 2026-09-28 14:38:02 +02:00
1 parent 658adb7da7
commit d8bbefed8a
22 files changed
+1367 -1320

No files matched your search

+2
View File
@@ -309,6 +309,7 @@ FU_SETTINGS=(
"pam|sudo|bool|no|sudo in a terminal"
"pam|polkit-1|bool|no|Admin prompts"
"pam|lockscreens|bool|yes|Lock screens|||lockers"
"sys|SshSessions|bool|no|In SSH sessions"
"group|Recognition"
"sys|Liveness|choice|light|Photo check|off,light,heavy"
"sys|Strictness|choice|normal|How closely the face has to match|relaxed,normal,strict"
@@ -348,6 +349,7 @@ fu_setting_help() {
LockBlur:*) fu_msg "Blurs the picture behind face-unlock's own lock screen." ;;
lockscreens:*) fu_msg "The lock screen takes your face in its password check. Press Enter on the empty field to scan. Found here: %s." "$(fu_pam_lockers_list)" ;;
polkit-1:*) fu_msg "The password windows of your desktop and apps, for example when you install software. No match: you type the password." ;;
SshSessions:*) fu_msg "sudo in an SSH session takes your face too, if you sit at this computer. Off by default: the person at the camera may not be the one typing." ;;
Liveness:heavy) fu_msg "You have to blink or turn your head a little. This also stops printed photos." ;;
Liveness:off) fu_msg "No check at all. Only for trying out a camera." ;;
Liveness:*) fu_msg "Stops photos on a phone, a tablet or glossy paper. You do not have to blink. A matte printed photo can get through." ;;
+1
View File
@@ -28,6 +28,7 @@ declare -A FU_SYS_VALID=(
[ScanSeconds]='^([2-9]|1[0-5])$'
[Adapt]='^(yes|no)$'
[SkipLidClosed]='^(yes|no)$'
[SshSessions]='^(yes|no)$'
[MaxFailures]='^([1-9]|1[0-9]|20)$'
[LockoutMinutes]='^[1-9][0-9]{0,3}$'
)