draft: flatseal
This commit is contained in:
+1
-1
@@ -1 +1 @@
|
||||
{"readable":true,"books":{"\/book\/esp":3,"\/book\/les-commandes-linux":2,"\/book\/linux-architecture-des-dossiers":1},"as":[{"asn":"","name":"LAN","country":"","hits":12885},{"asn":"8075","name":"Cloud","country":"US","hits":828},{"asn":"14618","name":"AWS EC2 (us-east-1)","country":"US","hits":441},{"asn":"24940","name":"Hetzner","country":"FI","hits":396},{"asn":"16276","name":"OVH","country":"FR","hits":150},{"asn":"32934","name":"Meta Platforms Ireland Limited","country":"US","hits":130},{"asn":"48230","name":"LLC MONOLITH.NET","country":"UA","hits":83},{"asn":"15169","name":"Google LLC","country":"US","hits":64},{"asn":"36352","name":"HostPapa","country":"US","hits":18},{"asn":"174","name":"Code 200, UAB","country":"FR","hits":12},{"asn":"16509","name":"Anthropic, PBC","country":"US","hits":11},{"asn":"18779","name":"EGIHosting","country":"US","hits":10},{"asn":"46261","name":"BraveWay","country":"US","hits":10},{"asn":"51207","name":"Free Mobile","country":"FR","hits":7},{"asn":"210743","name":"Babbar SAS","country":"FR","hits":6},{"asn":"29695","name":"Lyse Tele AS","country":"NO","hits":5},{"asn":"41281","name":"KeFF Networks Ltd","country":"SE","hits":5},{"asn":"9443","name":"Vocus Retail","country":"AU","hits":5},{"asn":"58087","name":"Datalix","country":"DE","hits":4},{"asn":"37054","name":"Telma Madagascar","country":"MG","hits":3},{"asn":"136907","name":"Huawei Cloud","country":"SG","hits":2},{"asn":"51167","name":"Contabo GmbH","country":"FR","hits":2},{"asn":"45102","name":"Alibaba.com LLC","country":"SG","hits":2},{"asn":"396982","name":"Google Cloud (us-east5)","country":"US","hits":2}]}
|
||||
{"readable":true,"books":{"\/book\/esp":4,"\/book\/les-commandes-linux":3,"\/book\/linux-architecture-des-dossiers":2,"\/book\/la-domotique-chez-soi":1},"as":[{"asn":"","name":"LAN","country":"","hits":13001},{"asn":"8075","name":"Cloud","country":"US","hits":841},{"asn":"14618","name":"AWS EC2 (us-east-1)","country":"US","hits":424},{"asn":"24940","name":"Hetzner","country":"FI","hits":396},{"asn":"32934","name":"Meta Platforms Ireland Limited","country":"US","hits":190},{"asn":"16276","name":"OVH","country":"FR","hits":150},{"asn":"48230","name":"LLC MONOLITH.NET","country":"UA","hits":83},{"asn":"15169","name":"Google LLC","country":"US","hits":68},{"asn":"36352","name":"HostPapa","country":"US","hits":18},{"asn":"174","name":"Code 200, UAB","country":"FR","hits":12},{"asn":"18779","name":"EGIHosting","country":"US","hits":10},{"asn":"46261","name":"BraveWay","country":"US","hits":10},{"asn":"3209","name":"Vodafone Kabel Deutschland GmbH","country":"DE","hits":9},{"asn":"51207","name":"Free Mobile","country":"FR","hits":7},{"asn":"16509","name":"Anthropic, PBC","country":"US","hits":7},{"asn":"210743","name":"Babbar SAS","country":"FR","hits":6},{"asn":"29695","name":"Lyse Tele AS","country":"NO","hits":5},{"asn":"41281","name":"KeFF Networks Ltd","country":"SE","hits":5},{"asn":"9443","name":"Vocus Retail","country":"AU","hits":5},{"asn":"396982","name":"Google Cloud (us-east5)","country":"US","hits":4},{"asn":"58087","name":"Datalix","country":"DE","hits":4},{"asn":"45102","name":"Alibaba.com LLC","country":"SG","hits":4},{"asn":"37054","name":"Telma Madagascar","country":"MG","hits":3},{"asn":"136907","name":"Huawei Cloud","country":"SG","hits":2},{"asn":"51167","name":"Contabo GmbH","country":"FR","hits":2}]}
|
||||
@@ -0,0 +1,4 @@
|
||||
{
|
||||
"title": "Flatseal",
|
||||
"_updated_at": "2026-05-16 17:17:45"
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
# Flatseal
|
||||
|
||||

|
||||
|
||||
**Flatseal** est une application Linux qui permet de visualiser et de modifier les autorisations accordées aux applications **Flatpak**. Pour rappel, les applications Flatpak sont empaquetées avec leurs dépendances et exécutées dans un environnement isolé (*sandbox*), ce qui renforce la sécurité du système en cloisonnant chaque programme.
|
||||
|
||||
Cet isolement a une contrepartie : les applications Flatpak disposent par défaut d'un accès très restreint aux ressources du système (fichiers, caméra, microphone, réseau, etc.). Flatseal sert précisément à ajuster ces restrictions, application par application, lorsqu'un accès supplémentaire est nécessaire.
|
||||
|
||||
Son interface graphique simple en fait un outil de choix pour quiconque souhaite garder un contrôle fin sur ses applications sans passer par la ligne de commande.
|
||||
|
||||

|
||||
|
||||
## Les autorisations modifiables
|
||||
|
||||
Les autorisations disponibles dépendent de ce que chaque application Flatpak prend en charge. Les plus courantes sont :
|
||||
|
||||
- **Accès au réseau** : autorise l'application à se connecter à Internet et aux autres machines du réseau local.
|
||||
- **Accès au système de fichiers** : autorise la lecture et l'écriture de fichiers et dossiers.
|
||||
- **Accès aux périphériques** : imprimantes, scanners, caméras, microphones, etc.
|
||||
- **Accès à la localisation** : position géographique de l'utilisateur.
|
||||
- **Notifications** : affichage de notifications sur le bureau.
|
||||
- **Accès au serveur d'affichage** : autorisation d'afficher des fenêtres via X11 ou Wayland.
|
||||
|
||||
Chacune de ces autorisations peut être activée ou désactivée selon les besoins.
|
||||
|
||||
> Lien officiel : https://flathub.org/apps/details/com.github.tchx84.Flatseal
|
||||
|
||||
## Alternative en ligne de commande
|
||||
|
||||
En coulisses, Flatseal ne fait qu'écrire des fichiers de *surcharge* (*overrides*) lus par Flatpak. La commande `flatpak override` permet d'obtenir le même résultat depuis un terminal — plus puissant, mais aussi plus verbeux.
|
||||
|
||||
**Pour l'utilisateur courant :**
|
||||
|
||||
```bash
|
||||
flatpak override --user <option> <application> -v
|
||||
```
|
||||
|
||||
Le fichier modifié sera `~/.local/share/flatpak/overrides/<application>`.
|
||||
|
||||
**Pour tous les utilisateurs :**
|
||||
|
||||
```bash
|
||||
sudo flatpak override <option> <application> -v
|
||||
```
|
||||
|
||||
Le fichier modifié sera `/var/lib/flatpak/overrides/<application>`.
|
||||
|
||||
**Exemple** — couper l'accès réseau d'une application tout en lui laissant l'accès au système de fichiers :
|
||||
|
||||
```bash
|
||||
sudo flatpak override --nofilesystem=xdg-run/dot-flatpak-info --filesystem=host --unshare=network <application>
|
||||
```
|
||||
|
||||
Pour la plupart des usages quotidiens, l'interface graphique de Flatseal reste plus rapide et moins sujette aux erreurs que la ligne de commande.
|
||||
@@ -246,3 +246,4 @@
|
||||
{"ts":"2026-05-16 17:03:56","url":"/electronique/arduino/xbee","ref":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"}
|
||||
{"ts":"2026-05-16 17:11:25","url":"/informatique/linux/system/dossiers-remarquables/dev","ref":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"}
|
||||
{"ts":"2026-05-16 17:11:37","url":"/informatique/le-wifi-du-raspberry-pi","ref":"","ua":"Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"}
|
||||
{"ts":"2026-05-16 17:17:06","url":"/article","ref":"https://www.abonnel.fr/article?idx=informatique%3Ainternet%3Amarque-ta-page%3Ainformatique%3Alogiciels","ua":"Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (HTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)"}
|
||||
|
||||
Reference in New Issue
Block a user