nixos/immich: restrict media filesystem permissions (#361627)
This commit is contained in:
@@ -37,6 +37,7 @@ let
|
||||
RestrictNamespaces = true;
|
||||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
UMask = "0077";
|
||||
};
|
||||
inherit (lib)
|
||||
types
|
||||
@@ -353,6 +354,21 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
systemd.tmpfiles.settings = {
|
||||
immich = {
|
||||
# Redundant to the `UMask` service config setting on new installs, but installs made in
|
||||
# early 24.11 created world-readable media storage by default, which is a privacy risk. This
|
||||
# fixes those installs.
|
||||
"${cfg.mediaLocation}" = {
|
||||
e = {
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
mode = "0700";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
users.users = mkIf (cfg.user == "immich") {
|
||||
immich = {
|
||||
name = "immich";
|
||||
|
||||
Reference in New Issue
Block a user