Omahub
← All plugins
S

OmaOneDrive

by Salem Sayed

OneDrive status, timed pause controls, cloud storage, and recent sync activity in the Omarchy bar, for one account or several.

Security review

Potentially dangerous behavior detected · 32 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
d4eb4ce
Scanned
2 weeks ago
  • high persistence …/qml/Harness.qml:420

    Registers scheduled or boot-time system tasks.

    systemd-run vector -- the one that decides which account
  • high persistence …/qml/Harness.qml:426

    Registers scheduled or boot-time system tasks.

    systemd-run")
  • high persistence …/qml/Harness.qml:781

    Registers scheduled or boot-time system tasks.

    systemd-run")
  • Registers scheduled or boot-time system tasks.

    systemd-run refuses. The account is already stopped by
  • Registers scheduled or boot-time system tasks.

    systemd-run")
  • Registers scheduled or boot-time system tasks.

    systemd-run") !== -1) {
  • Registers scheduled or boot-time system tasks.

    systemd-run")
  • Registers scheduled or boot-time system tasks.

    systemd-run") !== -1) timers[t].failToStart()
  • Registers scheduled or boot-time system tasks.

    systemd-run that cannot START recovers the account, like one that fails")
  • Registers scheduled or boot-time system tasks.

    systemd-run")
  • Registers scheduled or boot-time system tasks.

    systemd-run that HANGS -- starts, never exits -- is different from one
  • Registers scheduled or boot-time system tasks.

    systemd-run is abandoned and the account recovered")
  • Registers scheduled or boot-time system tasks.

    systemd-run").length === 1,
  • Registers scheduled or boot-time system tasks.

    systemd-run").length === 0,
  • Registers scheduled or boot-time system tasks.

    systemd-run reads a --unit value ending in a unit suffix as THAT unit, so
  • Registers scheduled or boot-time system tasks.

    systemd-run creates
  • Registers scheduled or boot-time system tasks.

    systemd-run", "--user",
  • Registers scheduled or boot-time system tasks.

    systemd-run", "--user",
  • high persistence Account.qml:69

    Registers scheduled or boot-time system tasks.

    systemd-run that is not on PATH. Every one of these processes cleans
  • high persistence Account.qml:878

    Registers scheduled or boot-time system tasks.

    systemd-run failing to START is the same outcome for the user as it
  • high persistence Commands.js:30

    Registers scheduled or boot-time system tasks.

    systemd-run reads a --unit value ending in a unit suffix as THAT unit, so
  • high persistence Commands.js:36

    Registers scheduled or boot-time system tasks.

    systemd-run creates a .timer AND a .service, so the longer suffix is what
  • high persistence Commands.js:107

    Registers scheduled or boot-time system tasks.

    systemd-run", "--user",
  • medium package_manager …/workflows/ci.yml:23

    System package manager operation.

    apt-get update
  • medium package_manager …/workflows/ci.yml:24

    System package manager operation.

    apt-get install --yes jq qt6-declarative-dev-tools qmlscene-qt6 \
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get update
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install --yes jq qt6-declarative-dev-tools qmlscene-qt6 \
  • low obfuscation onedrive-status.py:314

    Augments a command with octal/hex escape sequences.

    \x20space.service"); "/" is not, so
  • Augments a command with octal/hex escape sequences.

    \x20space.service"):
  • Docs persistence docs/ARCHITECTURE.md:31

    Registers scheduled or boot-time system tasks.

    systemd-run --user` — `omaonedrive-resume` for the plain service,
  • Docs persistence docs/ARCHITECTURE.md:35

    Registers scheduled or boot-time system tasks.

    systemd-run` derive the same unit as a different account,
  • Docs persistence CHANGELOG.md:41

    Registers scheduled or boot-time system tasks.

    systemd-run` that fails to start, hangs,

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d4eb4ce
Reviewed
2 weeks ago

The plugin is a well-structured bar widget that reads OneDrive status and controls the user's OneDrive systemd service via systemctl --user and systemd-run for timed pauses. The deterministic scan's high-risk findings are false positives: the systemd-run usage is a legitimate timed-pause feature, the sudo/apt-get operations are confined to GitHub Actions CI, and the 'obfuscation' flags are escape sequences in test fixtures and comments, not real obfuscation. No install-time scripts, credential theft, or destructive commands were found.

  • The deterministic scan flagged systemd-run usage as persistence, but it is only used to schedule a transient user timer to resume the OneDrive service after a user-initiated timed pause.
  • The CI workflow uses sudo apt-get, but that runs only in GitHub Actions, not on the user's machine.
  • The obfuscation flags refer to octal/hex escape sequences in test files and a comment, not to any obfuscated executable code.
  • The plugin reads the refresh_token file only to check presence, never its contents, and does not contact Microsoft except on explicit user actions.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/salemsayed/omaonedrive --enable
System #bar #quickshell #system

OmaOneDrive

OneDrive in the Omarchy bar. OmaOneDrive follows the installed OneDrive Client for Linux and its systemd user service: sync status, cloud storage, recent activity, and pause/resume — in a panel like Omarchy's own Dropbox widget.

Demo

OmaOneDrive demo: an upload with live progress, pause and resume, and recovery from a network cut

Screenshots

Multiple accounts: independent controls and activity for the selected Work account

Full layout: status, cloud storage, recent activity

A recovered upload failure shown as a neutral activity row

Compact layout: storage and the primary actions

Resync required, with the guided repair

Highlights

  • Live status — monitoring, syncing, paused, or needs attention, with the file currently transferring and its progress. Interruptions show as "retrying", never as a frozen percentage.
  • Multiple accounts — every configured account is discovered from its own systemd unit, with a selector row in the panel, per-account pause, login and repair, and one bar badge showing whichever account most needs attention. A single-account setup keeps its existing controls and panel layout.
  • Notifications when OneDrive fails, needs a resync or reauthentication, recovers, or storage passes 90% full. Clicking one opens the panel or starts the repair. Events from several accounts are grouped into one notification that names them. Optional.
  • Guided repair — opens the CLI's own interactive --resync flow in a terminal, which asks before it touches anything.
  • Pause and resume with 15-minute, 1-hour and 4-hour timed pauses.
  • Storage meter that turns urgent past 90%.
  • Honest activity feed — service errors and recent local changes, benign client noise filtered out, resolved errors shown as recovered.
  • Full and Compact layouts; arrow-key navigation.
  • Distinct bar badges for missing client, login needed, paused, syncing and healthy.

Controls

  • Left click toggles the panel; middle click opens the OneDrive folder; right click refreshes cloud storage. With several accounts, the panel's selector row chooses which account every control acts on; there is deliberately no pause-everything button.
  • ↑ ↓ move, Enter activates. R refreshes storage, F verifies sync, P pauses or resumes, O opens the folder, W opens OneDrive on the web, Shift+L opens login, Esc closes. Lowercase l follows Omarchy's Vim-style right-arrow navigation.

Routine refreshes are local (service, journal, sync folder). Microsoft is contacted only by Refresh storage (onedrive --display-quota) and Verify sync (onedrive --display-sync-status, slow on large drives, never automatic) — plus one storage retry when you open the panel onto a failed check older than five minutes.

With several accounts the refresh interval is shared rather than multiplied: in steady state each account is polled once per interval, staggered across it, and only one account is read at a time. At startup a faster ramp runs until every account has reported once. Cloud checks stay manual and run one at a time across all accounts.

Accounts are found by reading each onedrive systemd user unit's own ExecStart for its --confdir, so an instance pointed at an unrelated directory is still found correctly. Nothing is guessed from unit names.

Requirements

  • Omarchy 4 (Quattro)
  • Python 3
  • The abraunegg onedrive CLI (tested with 2.5.11) and its onedrive.service user unit
omarchy-pkg-add onedrive-abraunegg
onedrive                                   # sign in once
systemctl --user enable --now onedrive.service

Install

omarchy plugin add https://github.com/salemsayed/omaonedrive.git --enable

Update

omarchy plugin update io.github.salemsayed.omaonedrive
omarchy restart shell

Restart the shell after updating so the running panel uses the new code. Check the installed version and commit with:

jq -r .version ~/.config/omarchy/plugins/io.github.salemsayed.omaonedrive/manifest.json
git -C ~/.config/omarchy/plugins/io.github.salemsayed.omaonedrive rev-parse HEAD

Marketplace verification covers an exact commit. The update command follows upstream HEAD, so compare the installed commit with the marketplace snapshot when checking verification coverage. See the marketplace's official verification workflow for publishing and verifying a newer commit.

Configure

omarchy bar set io.github.salemsayed.omaonedrive refreshIntervalSec 30 --json   # 10–3600
omarchy bar set io.github.salemsayed.omaonedrive recentFileLimit 20 --json      # 5–50
omarchy bar set io.github.salemsayed.omaonedrive panelStyle Compact             # Full | Compact
omarchy bar set io.github.salemsayed.omaonedrive notifications false --json

IPC, for keybindings:

omarchy-shell io.github.salemsayed.omaonedrive open      # also: status, refresh, check
omarchy-shell io.github.salemsayed.omaonedrive pause     # pauseFor 60, resume
omarchy-shell io.github.salemsayed.omaonedrive folder

The pause, pauseFor, resume, and toggleSync replies report whether the control was accepted. ok means it started; busy means a refresh or another control is still running, so retry after it finishes. This can happen immediately after selectAccount, which refreshes the selected account. Other replies explain why the control cannot start. Check the account's status to confirm completion.

Remove

omarchy plugin disable io.github.salemsayed.omaonedrive
omarchy plugin remove io.github.salemsayed.omaonedrive

OneDrive itself is untouched. To drop the status cache as well:

rm -r -- "$HOME/.local/state/omarchy/io.github.salemsayed.omaonedrive"

What it never does

No uploads, downloads, deletions, resyncs, logouts or configuration edits of its own. Pause and resume are systemctl --user stop/start onedrive.service; a timed pause is a transient user timer that only starts that service again. Login and reauthentication open the client in a terminal. The refresh token is never read, copied or stored.

License

MIT