Skip to content

Commit fed70cf

Browse files
authored
Merge pull request #51 from junkerderprovinz/docs/disable-window-buttons
Document DISABLE_WINDOW_BUTTONS
2 parents 70e5118 + 198c297 commit fed70cf

2 files changed

Lines changed: 3 additions & 1 deletion

File tree

‎docs/selkies/developer-guide/building-images.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -161,6 +161,7 @@ At container init, `init-selkies-config` rewrites the rc.xml based on environmen
161161
| `NO_DECOR` | Flips the decoration rules to `serverDecoration="no"` (Openbox: injects `<decor>no</decor>`) |
162162
| `NO_FULL` | Deletes the maximize on launch window rule |
163163
| `DISABLE_CLOSE_BUTTON` | Strips `close` from the titlebar button layout |
164+
| `DISABLE_WINDOW_BUTTONS` | Strips `iconify`, `max` and `close` from the titlebar button layout (Openbox: `I`, `M` and `C` from `titleLayout`) |
164165
| `DISABLE_MOUSE_BUTTONS` | Deletes the right and middle click mousebinds, removing the root menu and client list |
165166
| `HARDEN_KEYBINDS` | Comments out the escape hatch keybinds (`alt+f4`, `alt+escape`, `alt+space`, Super+E) |
166167

‎docs/selkies/user-guide/security.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ Modern browser features the client depends on, WebCodecs for video and audio in
3434

3535
For kiosk deployments, single app terminals, classrooms, or any situation where the person at the keyboard is not the administrator, the baseimage ships lockdown variables.
3636

37-
Note that the window manager level switches (`HARDEN_OPENBOX`, `DISABLE_CLOSE_BUTTON`, `DISABLE_MOUSE_BUTTONS`, `HARDEN_KEYBINDS`) only apply to **single application containers**, which run under labwc or Openbox. Full desktop Webtops manage their own windows, so only the desktop wide switches (`HARDEN_DESKTOP` and the `SELKIES_*` locks) matter there. The mechanics are documented in depth in [the developer guide](../developer-guide/building-images.md#the-window-manager-layer-labwc-and-openbox).
37+
Note that the window manager level switches (`HARDEN_OPENBOX`, `DISABLE_CLOSE_BUTTON`, `DISABLE_WINDOW_BUTTONS`, `DISABLE_MOUSE_BUTTONS`, `HARDEN_KEYBINDS`) only apply to **single application containers**, which run under labwc or Openbox. Full desktop Webtops manage their own windows, so only the desktop wide switches (`HARDEN_DESKTOP` and the `SELKIES_*` locks) matter there. The mechanics are documented in depth in [the developer guide](../developer-guide/building-images.md#the-window-manager-layer-labwc-and-openbox).
3838

3939
### Umbrella switches
4040

@@ -51,6 +51,7 @@ Note that the window manager level switches (`HARDEN_OPENBOX`, `DISABLE_CLOSE_BU
5151
| `DISABLE_SUDO` | Disables `sudo` by removing execute permissions and invalidating the passwordless sudo configuration |
5252
| `DISABLE_TERMINALS` | Disables common terminal emulators and hides them from the right click menu |
5353
| `DISABLE_CLOSE_BUTTON` | Removes the close button from window title bars |
54+
| `DISABLE_WINDOW_BUTTONS` | Removes the minimize, maximize and close buttons from window title bars |
5455
| `DISABLE_MOUSE_BUTTONS` | Disables right click and middle click context menus and actions in the window manager |
5556
| `HARDEN_KEYBINDS` | Disables window manager keybinds that could bypass the other options, such as `alt+f4` to close windows or `alt+escape` for the root menu |
5657
| `RESTART_APP` | Watchdog that restarts the main application if it is closed. The user's autostart script is made read only and root owned to prevent tampering |

0 commit comments

Comments
 (0)