mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-01 20:45:12 +00:00
nixos/autobrr: remove secretFile
autobrr no longer uses a session secret since version 1.82.0.
This commit is contained in:
@@ -148,6 +148,8 @@
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
|
||||
- `services.autobrr.secretFile` has been removed, as autobrr no longer uses a session secret since version 1.82.0. Remove the option from your configuration.
|
||||
|
||||
- Artalk has been updated to 2.10.0. Its default configuration and data
|
||||
directory discovery changed; see the [upstream migration
|
||||
guide](https://artalk.js.org/en/guide/releases/v2.10.0.html) when invoking
|
||||
|
||||
@@ -11,6 +11,14 @@ let
|
||||
configFile = configFormat.generate "autobrr.toml" cfg.settings;
|
||||
in
|
||||
{
|
||||
imports = [
|
||||
(lib.mkRemovedOptionModule [
|
||||
"services"
|
||||
"autobrr"
|
||||
"secretFile"
|
||||
] "autobrr no longer uses a session secret since version 1.82.0.")
|
||||
];
|
||||
|
||||
options = {
|
||||
services.autobrr = {
|
||||
enable = lib.mkEnableOption "Autobrr";
|
||||
@@ -21,11 +29,6 @@ in
|
||||
description = "Open ports in the firewall for the Autobrr web interface.";
|
||||
};
|
||||
|
||||
secretFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "File containing the session secret for the Autobrr web interface.";
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
type = lib.types.submodule {
|
||||
freeformType = configFormat.type;
|
||||
@@ -67,17 +70,6 @@ in
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = !(cfg.settings ? sessionSecret);
|
||||
message = ''
|
||||
Session secrets should not be passed via settings, as
|
||||
these are stored in the world-readable nix store.
|
||||
|
||||
Use the secretFile option instead.'';
|
||||
}
|
||||
];
|
||||
|
||||
systemd = {
|
||||
tmpfiles.settings = {
|
||||
"10-autobrr" = {
|
||||
@@ -101,8 +93,6 @@ in
|
||||
serviceConfig = {
|
||||
Type = "simple";
|
||||
DynamicUser = true;
|
||||
LoadCredential = "sessionSecret:${cfg.secretFile}";
|
||||
Environment = [ "AUTOBRR__SESSION_SECRET_FILE=%d/sessionSecret" ];
|
||||
StateDirectory = "autobrr";
|
||||
ExecStart = "${lib.getExe cfg.package} --config %S/autobrr";
|
||||
Restart = "on-failure";
|
||||
|
||||
@@ -4,28 +4,17 @@
|
||||
name = "autobrr";
|
||||
meta.maintainers = with lib.maintainers; [ av-gal ];
|
||||
|
||||
nodes.machine =
|
||||
{ pkgs, ... }:
|
||||
let
|
||||
# We create this secret in the Nix store (making it readable by everyone).
|
||||
# DO NOT DO THIS OUTSIDE OF TESTS!!
|
||||
testSecretFile = pkgs.writeText "session_secret" "not-secret";
|
||||
in
|
||||
{
|
||||
nodes.machine = {
|
||||
services.autobrr.enable = true;
|
||||
|
||||
# Use port other than default to test if settings options work.
|
||||
specialisation.settingsPort.configuration = {
|
||||
services.autobrr = {
|
||||
enable = true;
|
||||
secretFile = testSecretFile;
|
||||
};
|
||||
|
||||
# Use port other than default to test if settings options work.
|
||||
specialisation.settingsPort.configuration = {
|
||||
services.autobrr = {
|
||||
enable = true;
|
||||
secretFile = testSecretFile;
|
||||
settings.port = 7777;
|
||||
};
|
||||
settings.port = 7777;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
testScript =
|
||||
{ nodes, ... }:
|
||||
|
||||
Reference in New Issue
Block a user