3 ms·
A step further so you don't have to think about enabling it: sudo() { unset -f sudo if [[ "$(uname)" == 'Darwin' ]] && ! grep 'pam_tid.so' /etc/pam.d
by jmarcher 6y ago
A step further so you don't have to think about enabling it:
sudo() {
unset -f sudo
if [[ "$(uname)" == 'Darwin' ]] && ! grep 'pam_tid.so' /etc/pam.d/sudo --silent; then
sudo sed -i -e '1s;^;auth sufficient pam_tid.so\n;' /etc/pam.d/sudo
fi
sudo "$@"
}
- beyondcompute 6y agoThanks! That looks good! Thought on the second thought, I’ll continue to use the more “manual” method for now. As it gives me more control and it would be easier to switch off when touch ID sudo will be supported more officially.
- mkskm 6y agoHere's another function in Fish that incorporates the other suggestions offered in this thread. function sudo --description "Execute a command as another user." if [ (uname) = "Darwin" ] set --local needle "^auth\b.*\bpam_\(reattach\|tid\|watchid\)\.so\$" if ! grep $needle --silent /etc/pam.d/sudo && \ [ -f /usr/local/lib/pam/pam_reattach.so* ] && \ [ -f /usr/local/lib/pam/pam_watchid.so* ] command sudo sh -c " cat << EOF >/etc/pam.d/sudo auth optional pam_reattach.so auth sufficient pam_tid.so auth sufficient pam_watchid.so \$(grep -v '$needle' /etc/pam.d/sudo) EOF"; or return $status end end command sudo $argv end