bread-ecosystem/bread-polkit
Breadway 2897335016 bread-polkit: only auth as an identity polkit actually offered; fail fast without the lock
- The agent prompt's username field is user-editable. It was passed
  straight to `auth::authenticate`, so a request scoped to specific
  accounts (e.g. root only) could have its PAM conversation redirected
  to any local user. `resolve_user` now accepts only the `unix-user`
  identities from `BeginAuthentication` (empty = the prefilled default);
  anything else re-shows the prompt with an explanation. PAM still has to
  clear polkit's own authorization, but this closes the foot-gun at the
  one place the identity list is known.
- A failed single-instance lock now exits(1) instead of continuing: a
  second agent would `serve_at` the same object path, and a prompt held
  by a process that couldn't take the lock is ambiguous state.
2026-08-31 15:37:52 +08:00
..
contrib workspace: add bread-app crate and first-cut bread-polkit agent 2026-08-16 00:34:12 +08:00
src bread-polkit: only auth as an identity polkit actually offered; fail fast without the lock 2026-08-31 15:37:52 +08:00
bakery.toml bread-polkit: add bakery.toml so the agent can be published later 2026-08-23 14:38:04 +08:00
Cargo.toml workspace: add bread-app crate and first-cut bread-polkit agent 2026-08-16 00:34:12 +08:00