mirror of
https://github.com/Matysh/houseplan-card
synced 2026-07-31 16:38:31 +00:00
fix v1.44.4: audit follow-up B2, B5, L4 sub-item
B2: the HTTP upload view failed OPEN when the config entry was unavailable while the WS path failed closed — both now share one may_write() policy helper (new auth.py) that denies non-admins when the policy cannot be read. B5: _finite now guards room rects, polygon vertices, view_box and opening coordinates, not just layout positions; the declared MAX_OPENINGS cap is finally enforced. L4 (sub-item): every drag pipeline captures the pointer through the tolerant helper (an inactive pointerId used to kill device/label/resize drags); decor shapes gained a bounds clamp so they cannot be dragged far outside the plan and persisted there. +2 backend tests (16); both changelogs updated in this commit
This commit is contained in:
@@ -19,7 +19,7 @@ except ImportError: # older HA versions
|
||||
from homeassistant.core import HomeAssistant
|
||||
|
||||
from .const import CONF_ADMIN_ONLY, CONTENT_URL, FILES_DIR, FILES_URL, PLANS_DIR
|
||||
from .store import get_entry
|
||||
from .auth import may_write
|
||||
from .validation import (
|
||||
FILE_EXTENSIONS,
|
||||
MAX_FILE_BYTES,
|
||||
@@ -95,12 +95,8 @@ class HouseplanUploadView(HomeAssistantView):
|
||||
|
||||
async def post(self, request: web.Request) -> web.Response:
|
||||
hass: HomeAssistant = request.app[KEY_HASS]
|
||||
entry = get_entry(hass)
|
||||
admin_only = bool(entry and entry.options.get(CONF_ADMIN_ONLY, False))
|
||||
if admin_only:
|
||||
user = request.get("hass_user")
|
||||
if user is None or not user.is_admin:
|
||||
return web.json_response({"error": "unauthorized"}, status=403)
|
||||
if not may_write(hass, request.get("hass_user")):
|
||||
return web.json_response({"error": "unauthorized"}, status=403)
|
||||
|
||||
marker_id = "misc"
|
||||
filename: str | None = None
|
||||
|
||||
Reference in New Issue
Block a user