session management: Allow for restricted shells

Allows the AlternateShell specified by the user in the TS_INFO_PACKET
to be passed to startwm.sh as an environment variable.
This commit is contained in:
matt335672
2025-10-17 11:33:26 +01:00
parent 23e12403e3
commit 6b6edca8ca
6 changed files with 47 additions and 1 deletions
+7
View File
@@ -45,6 +45,13 @@ RestrictOutboundClipboard=none
RestrictInboundClipboard=none
; Set to 'no' to prevent users from logging in with alternate shells
#AllowAlternateShell=true
; Normally, alternate shells (if permitted) are executed directly, as
; specified.
; If this is set, alternate shells are not actioned directly, but
; passed in to the default window manager in the specified environment
; variable. This allows the system manager more control over exactly
; what alternate shells are permitted.
#PassShellAsEnv=XRDP_ALTERNATE_SHELL
; On Linux systems, the Xorg X11 server is normally invoked using
; no_new_privs to avoid problems if the executable is suid. This may,
; however, interfere with the use of security modules such as AppArmor.