{ config, lib, pkgs, ... }: let inherit (lib) mkOption mkEnableOption types mkIf mkMerge; inherit (pkgs.stdenv.hostPlatform) isDarwin; cfg = config.ryan.zen; extensionType = types.submodule { options = { enable = mkOption { type = types.bool; default = true; description = "Set false to drop an entry defined elsewhere (attrsOf can't delete keys)."; }; id = mkOption { type = types.str; description = "Add-on GUID; also the policy key and the AMO API lookup key."; }; version = mkOption { type = types.nullOr types.str; default = null; description = "Hard pin. null = whatever extensions.lock.json holds (bump with lock.sh)."; }; mode = mkOption { type = types.enum [ "force_installed" "normal_installed" ]; default = "force_installed"; }; privateBrowsing = mkOption { type = types.nullOr types.bool; default = null; description = "Emit private_browsing only when non-null."; }; extraSettings = mkOption { type = types.attrsOf types.anything; default = { }; description = "Merged last into the ExtensionSettings entry (e.g. default_area)."; }; }; }; in { imports = [ ./extensions.nix ]; options.ryan.zen = { enable = mkEnableOption "Zen browser with locked policies, profile and extensions"; extensions = mkOption { type = types.attrsOf extensionType; default = { }; description = "Policy-managed extensions, resolved through extensions.lock.json."; }; exclusive = mkOption { type = types.bool; default = true; description = "Disallow all undeclared extensions and disable all temporary loading"; }; }; config = mkIf cfg.enable (mkMerge [ { programs.zen-browser = { enable = true; policies = import ./policies.nix; profiles.default = import ./profile.nix; }; ryan.zen.extensions = { ublock-origin = { id = "uBlock0@raymondhill.net"; privateBrowsing = true; }; bitwarden = { id = "{446900e4-71c2-419f-a6a7-df9c091e268b}"; mode = "normal_installed"; privateBrowsing = true; }; sponsorblock.id = "sponsorBlocker@ajay.app"; dearrow.id = "deArrow@ajay.app"; return-youtube-dislikes.id = "{762f9885-5a13-4abd-9c77-433dcd38b8fd}"; youtube-nonstop.id = "{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}"; tampermonkey.id = "firefox@tampermonkey.net"; floccus.id = "floccus@handmadeideas.org"; mailvelope.id = "jid1-AQqSMBYb0a8ADg@jetpack"; }; } (mkIf isDarwin { programs.zen-browser = { package = null; # managed via homebrew darwinDefaultsId = "app.zen-browser.zen"; }; }) ]); }