diff --git a/custom_components/houseplan/auth.py b/custom_components/houseplan/auth.py index d78c96e6..d6e1c48e 100644 --- a/custom_components/houseplan/auth.py +++ b/custom_components/houseplan/auth.py @@ -32,6 +32,12 @@ def may_write(hass: HomeAssistant, user) -> bool: if admin_only: return is_admin + # Administrators retain write access regardless of their group payload. + # HA normally exposes admin groups too, but authorization must be based on + # the explicit admin flag rather than incidental group serialization. + if is_admin: + return True + # Turning off ``admin_only`` grants editing to ordinary household users, # not to HA's explicitly read-only role (#626). ``groups`` is part of the # supported HA User model; if a non-admin connection cannot provide a diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index 104242b2..7d98696f 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -6,7 +6,8 @@ House Plan editing is opened to ordinary household members. They keep the complete View experience, including vacuum paths, but cannot edit, upload or delete data; the maintenance list of stored plan files is writer-only and - vacuum responses no longer expose the internal map-source entity ID + vacuum responses no longer expose the internal map-source entity ID; + administrators retain full access ([#626](https://github.com/Matysh/houseplan-card/issues/626)). - The main toolbar no longer shows the device count (“37 dev.”), and it stops jumping sideways when you open, close or switch editors: the editor’s close diff --git a/docs/CHANGELOG.ru.md b/docs/CHANGELOG.ru.md index c9b4060a..9b2199e6 100755 --- a/docs/CHANGELOG.ru.md +++ b/docs/CHANGELOG.ru.md @@ -13,7 +13,7 @@ Полноценный просмотр, включая маршруты пылесоса, сохраняется, но редактировать, загружать и удалять данные нельзя; служебный список файлов планов доступен только редакторам, а ответ с маршрутом больше не раскрывает внутренний entity - ID источника карты + ID источника карты; администраторы сохраняют полный доступ ([#626](https://github.com/Matysh/houseplan-card/issues/626)). - Основная панель больше не показывает счётчик устройств («37 устр.») и не дёргается по горизонтали при входе в редактор, выходе из него и diff --git a/tests_backend/test_ha_upload.py b/tests_backend/test_ha_upload.py index 03f0150d..43ee76b1 100644 --- a/tests_backend/test_ha_upload.py +++ b/tests_backend/test_ha_upload.py @@ -29,7 +29,9 @@ async def _household_access_token(hass: HomeAssistant) -> str: user = await hass.auth.async_create_user( "House Plan household", group_ids=[GROUP_ID_USER] ) - refresh_token = await hass.auth.async_create_refresh_token(user) + refresh_token = await hass.auth.async_create_refresh_token( + user, client_id="http://houseplan.test" + ) return hass.auth.async_create_access_token(refresh_token) diff --git a/tests_backend/test_ha_websocket.py b/tests_backend/test_ha_websocket.py index 9a8c6ffa..5ceba033 100644 --- a/tests_backend/test_ha_websocket.py +++ b/tests_backend/test_ha_websocket.py @@ -50,7 +50,9 @@ async def _access_token_for_group(hass: HomeAssistant, group_id: str) -> str: user = await hass.auth.async_create_user( f"House Plan {group_id}", group_ids=[group_id] ) - refresh_token = await hass.auth.async_create_refresh_token(user) + refresh_token = await hass.auth.async_create_refresh_token( + user, client_id="http://houseplan.test" + ) return hass.auth.async_create_access_token(refresh_token)