Omahub
← All plugins
O

eduVPN

by Orjan Ameye

A focused eduVPN controller for the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
08aaae8
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
08aaae8
Reviewed
1 month ago

The plugin is a Qt/QML bar widget that wraps the official eduVPN client (eduvpn-cli) by invoking it as a subprocess with a fixed, vetted argument list. It performs no network fetch of binaries, does not download or execute anything beyond official eduvpn-cli/omarchy commands, and gates the only shell-launched path on an exact allowlisted command. The deterministic scan found nothing, and manual review matches: the code is defensive, caps output reading, quotes arguments, and declines to act when eduvpn-cli is missing.

  • The widget shells out to `eduvpn-cli` (connect/disconnect/renew) on behalf of an IPC API exposed via omarchy-shell; an access-control bug elsewhere could let another panel trigger an unexpected VPN change. The panel only accepts connections on the shell's own IPC, so the surface stays local.
  • The floating-terminal launch is allowlisted to the exact string 'eduvpn interactive' and value-quoted with Util.shellQuote, which prevents argument injection; this was verified.
  • Connect/Renew runs with the user's own privileges via eduvpn-cli; nothing here elevates privileges or writes outside the user's config/cache.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/oameye/omarchy-eduvpn --enable
Widgets #bar #quickshell #security

omarchy-eduvpn

A small Omarchy bar widget for controlling the official eduvpn-cli client. It keeps eduVPN as the owner of authentication and NetworkManager profiles, while providing the useful daily controls in the bar.

<p align="center"> <img src="preview.png" alt="eduVPN Omarchy bar widget showing a connected University Konstanz VPN" width="450"> </p>

Features

  • Shows whether the eduVPN tunnel is connected.
  • Shows the configured server, profile, protocol, and remaining validity.
  • Connects to the single configured eduVPN server.
  • Disconnects through eduvpn-cli, including its normal cleanup.
  • Renews authorization and reconnects with one button.
  • Opens a floating terminal when initial setup or a server selection needs input.
  • Serializes CLI calls across multiple monitors.

The widget does not import or manage WireGuard files itself. eduvpn-cli owns the complete eduVPN lifecycle, including browser authentication and renewal.

Requirements

  • Omarchy with the Quickshell shell.
  • The official eduvpn-cli command, normally installed with python-eduvpn-client.
  • NetworkManager, as required by eduVPN.
  • A working browser and Secret Service/keyring for browser authorization.

Install the eduVPN client and CLI through Omarchy's AUR helper:

omarchy pkg aur add python-eduvpn-client

This provides /usr/bin/eduvpn-cli and pulls in the required python-eduvpn_common dependency. Verify the installation with:

eduvpn-cli --version

Set up eduVPN once from an interactive terminal if no server is configured:

eduvpn-cli interactive

At the [eduVPN]: prompt, enter connect. Search for your institution, select it, and complete the browser authorization. For example, the University Konstanz server is then saved as a configured server and can be listed with:

eduvpn-cli list

After setup, connect to the saved server with its number, for example:

eduvpn-cli connect -n 1

Install

omarchy plugin add https://github.com/oameye/omarchy-eduvpn.git --enable

The widget appears in the right side of the bar. Move it with:

omarchy bar move oameye.eduvpn --before omarchy.clock

To update or remove it:

omarchy plugin update oameye.eduvpn
omarchy plugin remove oameye.eduvpn

Use

  • Left click opens the panel.
  • Right click connects or disconnects.
  • Middle click refreshes status.
  • The panel provides Connect/Disconnect and Renew buttons.
  • Keyboard shortcuts are Enter for connect/disconnect, n for renew, r for refresh, and d for disconnect.

Renewal is always manual. eduVPN renewal can open a browser, so the widget never renews unexpectedly in the background.

IPC

The widget exposes these shell IPC commands:

omarchy-shell oameye.eduvpn status
omarchy-shell oameye.eduvpn connect
omarchy-shell oameye.eduvpn disconnect
omarchy-shell oameye.eduvpn renew
omarchy-shell oameye.eduvpn refresh
omarchy-shell oameye.eduvpn toggle

Derived work

The visual shell and testing approach were derived from jkoestinger/omarchy-vpn, then reduced to one eduVPN-specific backend. The original project is MIT licensed.

License

MIT. See LICENSE.