Goal
Give the installed Linux 1Password app in Try Omarchy an opt-in Windows Hello system-authentication path, comparable to the Mac Touch ID integration. Keep 1Password's account password, vault, and passkeys inside the guest.
Dependency and design
Build this after the signed Windows Hello guest-approval bridge in #165. Reuse its per-guest enrolled public key and fresh challenge, with a distinct onepassword-unlock operation. A guest-side, root-owned polkit agent should accept only com.1password.1Password.unlock from the exact main installed 1Password process and matching guest user, then ask the focused host VM for a signed Hello approval. Any denial, timeout, unavailable Hello device, or untrusted caller must fall back to the normal guest password or 1Password account-password path. Do not grant general polkit or sudo approval from this operation.
The Mac implementation and its process checks are documented in docs/onepassword-touch-id.md in omacom/try-omarchy; adapt its trust boundary to Windows rather than forwarding an unverified success boolean.
Acceptance
- Opt-in install, disable, repair, and upgrade paths leave the existing password flow usable.
- Exact executable/process/user/polkit-action checks pass; requests from a copy, helper, other user, SSH, CLI, or unrelated polkit action fail closed.
- Signed challenge is fresh, operation-bound, guest-bound, and verified in the guest; replay and focus-loss attempts fail.
- A Hello-capable Windows host proves approval, denial, timeout, and fallback with a real installed guest 1Password; unsupported hosts retain the normal password path.
Goal
Give the installed Linux 1Password app in Try Omarchy an opt-in Windows Hello system-authentication path, comparable to the Mac Touch ID integration. Keep 1Password's account password, vault, and passkeys inside the guest.
Dependency and design
Build this after the signed Windows Hello guest-approval bridge in #165. Reuse its per-guest enrolled public key and fresh challenge, with a distinct
onepassword-unlockoperation. A guest-side, root-owned polkit agent should accept onlycom.1password.1Password.unlockfrom the exact main installed 1Password process and matching guest user, then ask the focused host VM for a signed Hello approval. Any denial, timeout, unavailable Hello device, or untrusted caller must fall back to the normal guest password or 1Password account-password path. Do not grant general polkit or sudo approval from this operation.The Mac implementation and its process checks are documented in
docs/onepassword-touch-id.mdinomacom/try-omarchy; adapt its trust boundary to Windows rather than forwarding an unverified success boolean.Acceptance