feat(deploy): authorize bitspire for pcscd (polkit) + NFC diagnostics
pcscd gates clients via polkit; the sandboxed bitspire user was "Rejected unauthorized PC/SC client", so add a polkit rule granting it access_pcsc/access_card. Also log NFC reader status + taps from the main process to journald (value redacted — it carries the card's SUN p/c) so reader detection and taps are observable during testing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
51dcf0d6f6
commit
0a3156855c
2 changed files with 24 additions and 2 deletions
|
|
@ -92,6 +92,19 @@
|
|||
# attached — pcscd just idles.
|
||||
services.pcscd.enable = true;
|
||||
|
||||
# pcscd gates client access via polkit; without a rule the sandboxed
|
||||
# `bitspire` service user is "Rejected unauthorized PC/SC client". Authorize
|
||||
# it to talk to the daemon and the card.
|
||||
security.polkit.extraConfig = ''
|
||||
polkit.addRule(function(action, subject) {
|
||||
if ((action.id == "org.debian.pcsc-lite.access_pcsc" ||
|
||||
action.id == "org.debian.pcsc-lite.access_card") &&
|
||||
subject.user == "bitspire") {
|
||||
return polkit.Result.YES;
|
||||
}
|
||||
});
|
||||
'';
|
||||
|
||||
# Disable suspend/hibernate for kiosk
|
||||
systemd.targets = {
|
||||
sleep.enable = false;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue