Skip to content

Add opt-in Windows Hello unlock for guest 1Password #176

Description

@btsouth

Goal

Give the installed Linux 1Password app in Try Omarchy an opt-in Windows Hello system-authentication path, comparable to the Mac Touch ID integration. Keep 1Password's account password, vault, and passkeys inside the guest.

Dependency and design

Build this after the signed Windows Hello guest-approval bridge in #165. Reuse its per-guest enrolled public key and fresh challenge, with a distinct onepassword-unlock operation. A guest-side, root-owned polkit agent should accept only com.1password.1Password.unlock from the exact main installed 1Password process and matching guest user, then ask the focused host VM for a signed Hello approval. Any denial, timeout, unavailable Hello device, or untrusted caller must fall back to the normal guest password or 1Password account-password path. Do not grant general polkit or sudo approval from this operation.

The Mac implementation and its process checks are documented in docs/onepassword-touch-id.md in omacom/try-omarchy; adapt its trust boundary to Windows rather than forwarding an unverified success boolean.

Acceptance

  • Opt-in install, disable, repair, and upgrade paths leave the existing password flow usable.
  • Exact executable/process/user/polkit-action checks pass; requests from a copy, helper, other user, SSH, CLI, or unrelated polkit action fail closed.
  • Signed challenge is fresh, operation-bound, guest-bound, and verified in the guest; replay and focus-loss attempts fail.
  • A Hello-capable Windows host proves approval, denial, timeout, and fallback with a real installed guest 1Password; unsupported hosts retain the normal password path.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions