#!/usr/bin/env bash # scripts/auth-restart.sh # Performs an authenticated reboot using fdesetup echo "Enter your Mac password to perform an authenticated restart for FileVault:" echo "(Typing will be hidden. The Mac will reboot immediately upon success.)" read -s -p "Password: " PASS echo "" if [ -z "$PASS" ]; then echo "Operation cancelled or no password provided." exit 1 fi echo "Verifying password..." # Verify and cache sudo credentials so we don't have to expect the sudo prompt echo "$PASS" | sudo -S -v 2>/dev/null if [ $? -ne 0 ]; then echo "Incorrect password or sudo authorization failed." PASS="" exit 1 fi echo "Authorization successful. Initiating FileVault authenticated restart..." # Run fdesetup and feed the password using expect using env variables for safety export PASS expect -c ' set timeout 30 spawn sudo fdesetup authrestart expect { -re "(?i)(password|recovery key)" { send "$env(PASS)\r" exp_continue } timeout { puts "\nError: Timeout waiting for fdesetup prompt." exit 1 } eof { puts "\nAuthenticated restart initiated." exit 0 } } ' PASS=""