feat: first version
check / tests and shellcheck (push) Failing after 56s

This commit is contained in:
Felitendo committed 2026-10-02 10:39:46 +02:00
commit 3e98dd1e7e
48 files changed
+13025

No files matched your search

+173
View File
@@ -0,0 +1,173 @@
rdfeed(1)
# NAME
rdfeed - the RemoteApps of your company in the Linux app menu
# SYNOPSIS
*rdfeed* [_command_]
# DESCRIPTION
Companies publish their Windows apps (Word, Excel, their own tools) as an RD
Web Access feed. Windows subscribes to it under "RemoteApp and Desktop
Connections" and puts the apps in the start menu, in a folder with the name of
the workspace. rdfeed does the same on Linux: each app gets an entry in the
app menu and opens as a window of its own, not as a whole Windows desktop.
The apps run on the company's servers, through FreeRDP.
Run without a command it shows an interactive menu. Everything it can be told
is reachable from there; the files behind it do not need to be edited by
hand.
# COMMANDS
*add* [_address_] [*--user* _name_]
Add a workspace. The address is the one of the feed, as Windows takes it
(*https://server/RDWeb/Feed/webfeed.aspx*), or just the server name, or
the RD Web Access page, or a work e-mail address. For an e-mail address
the feed is looked up in the TXT record *\_msradc.*_domain_, as Windows
does it. The user name can be _DOMAIN\\name_, _name@domain_, or just the
name, which takes the server's own domain.
Without a terminal, the user name and the password are read from stdin,
one per line.
*refresh* [_workspace_]
Load the apps of every workspace again, or of the one given. Apps that
were added show up in the app menu, apps that were taken away disappear.
*list*
The workspaces with their apps, each as _workspace/app_, the name *run*
takes.
*run* _app_ [_file_]
Start an app. _app_ is enough when only one workspace has an app of that
name, otherwise _workspace/app_. This is what the app menu entries run.
With a file, the app opens it. The folder of the file is shared as a
drive for that session, and the app is started with the path on it,
_\\\\tsclient\\folder\\file_, the way Windows does it. If the server
does not let the app take a file this way, it opens empty, and the file
is on that drive.
*remove* _workspace_
Remove a workspace: its app menu entries, its folder, the downloaded
files, the saved password.
*-h*, *--help*
Show the help.
*-V*, *--version*
Show the version.
# SETTINGS
*Share a folder*
Off, Documents, Downloads or the home folder. The apps see it as a drive
and can open and save files there. Off by default: then they only see the
files on the server.
*Open files with the apps*
On by default. The app menu entries name the file types of each app, so
file managers offer it under "Open with", for example Word for .docx
files. The types come from the feed when the administrator entered them,
as Windows takes them. Most feeds have none, and then rdfeed knows the
usual ones: Word, Excel, PowerPoint, OneNote, Outlook, Visio, Access,
Project, Publisher, PDF readers, AutoCAD and DWG TrueView, Notepad. Your
default apps stay as they are.
*Size*
How big the apps are drawn on the server. Automatic takes the scale your
desktop gives X11 programs that scale themselves (KDE Plasma's Xwayland
scale, or Xft.dpi), so the apps come out sharp and the right size.
*Sound*
Play the sound of the apps on this computer.
*Graphics*
GFX (the default) or classic. See *FREERDP PROBLEMS*.
*Wait for the second MFA prompt*
Automatic (the default), always or never. See *FREERDP PROBLEMS*.
*Refresh the apps every day*
A systemd user timer (*rdfeed-refresh.timer*) that loads the apps again
once a day, as Windows does. It is switched on with the first workspace.
When the password stops working it says so in a notification.
# FREERDP PROBLEMS
rdfeed starts each app with *xfreerdp3* (*xfreerdp* on Fedora) in RemoteApp
mode, with *rdfeed-hook.so* loaded into it. The hook works around two
problems that leave FreeRDP hanging or windows half painted:
*The second MFA prompt*
Most companies run a connection broker, which sends the client on to the
server that hosts the session. FreeRDP then opens a second tunnel through
the RD Gateway at once. With MFA on the gateway (the Azure MFA extension
of NPS), that second sign-in needs a second prompt in the authenticator
app. When it comes less than about ten seconds after the first one was
confirmed, no prompt is sent and the gateway waits forever. So the hook
waits 12 seconds before a new gateway connection, and a notification says
a second prompt is coming. Automatic waits only when the first sign-in
took long enough for somebody to confirm a prompt.
*Windows that stay empty*
In RemoteApp mode with the graphics pipeline (GFX), FreeRDP may not
repaint a window after it was minimized or resized. FreeRDP 3 has no
switch to turn GFX off. With *Graphics* on classic, the hook keeps it off
and every window paints right. But some servers end the session right
after signing in without GFX, so GFX stays the default. Not fixed yet.
# HOW SAFE IS THIS
The password goes into the keyring (the Secret Service, as GNOME Keyring or
KWallet provide it), never into a file. FreeRDP gets it on stdin, never on its
command line, so it shows in no process list.
The .rdp files from the server can ask to share every drive, camera and USB
device of this computer. rdfeed removes those lines. Only the folder picked
under *Share a folder* is shared, and the folder of a file you open in an app,
for as long as that session runs.
The server's certificate is trusted the first time and checked after that
(*/cert:tofu*). The feed itself is fetched over HTTPS with the system's
certificates.
# FILES
_~/.config/rdfeed/config_
The settings.
_~/.config/rdfeed/workspaces/_
One file per workspace: the address, the name, the user.
_~/.local/share/rdfeed/_
The apps of each workspace: the .rdp files and the icons.
_~/.local/share/applications/rdfeed-\*.desktop_
The app menu entries, with a folder per workspace in
_~/.config/menus/applications-merged/_.
_~/.cache/rdfeed/_
The log of the last start of each app, for when something goes wrong.
# LIMITS
Only feeds that sign in with Windows (NTLM) authentication, which is what RD
Web Access uses. Azure Virtual Desktop and Windows 365 sign in with Microsoft
Entra and are not supported.
Starting a second app of the same workspace opens a second connection, which
takes over the session of the first: its windows move into the new one.
Nothing closes.
# SEE ALSO
*xfreerdp3*(1), *secret-tool*(1)
# AUTHORS
Felitendo. Source and bug reports: https://github.com/LoonixTools/rdfeed