The card signs content urls because a browser cannot authenticate an <image
href>. But _display() was called inside _buildModel(), and the space model is
memoized on the config fingerprint — so the UNSIGNED url froze in the cache and
the signature, which did arrive, never reached the element. The plan never
loaded, and the browser kept hitting the unsigned path: 401, which Home
Assistant reports as a failed login attempt from the viewer's own IP (that is
how the owner spotted it). PDF links were unaffected: they already resolved at
render time.
- _buildModel() keeps the raw plan_url; the render pass calls _display().
- _display() returns '' for an unsigned content url instead of the plain path,
and the <image> is not emitted at all until the signature lands — no 401, no
spurious login-attempt warning.
- _resign() replaces 'drop everything and re-request': the previous urls are
kept until the new ones arrive, so a wall tablet never blanks.
- demo/smoke_plan_signed.mjs: reproduces on v1.44.6 (href stays ?v=..., never
?authSig=), passes here. TESTING.md row added.
- docs: CHANGELOG.md + CHANGELOG.ru.md + STATUS.md.
After v1.44.5 read the area registry instead of visible icons, every hidden
temperature entity in the area became a candidate, including ones measuring
something other than room air. Verified against a live 60-area install: a NAS
processor temperature, kettle water, a 90 C sauna heater and a virtual
better_thermostat all leaked into room averages.
- areaClimate(): skip entity_category (diagnostic/config), skip EXCLUDED_DOMAINS
platforms, skip entity ids naming a non-air medium (water/coolant/flow_temp/
return_temp/target/setpoint/chip/cpu/processor/board/device_temp/batter/
freezer/fridge/oven/kettle/boiler).
- rules.ts: kettle/thermopot -> mdi:kettle, sauna/harvia -> mdi:hot-tub, so they
no longer fall through to the generic thermometer rule.
- test: all four real false positives asserted out, one real sensor left.
- docs: CHANGELOG.md + CHANGELOG.ru.md + STATUS.md snapshot.
- areaClimate() walks the HA registry for the area instead of the list
of VISIBLE icons: a thermometer hidden by curation or by the user was
silently dropped from the room card, tooltip and temperature fill
(field report). Curation still filters fridges/TRVs; the auto icon is
used on purpose so a custom marker icon cannot change what a device
measures; an explicit per-room source still wins
- room tooltip no longer says 'open the area' — room clicks were removed
in v1.40.1 (the link icon does it)
- +1 unit test (120); both changelogs updated
B2: the HTTP upload view failed OPEN when the config entry was
unavailable while the WS path failed closed — both now share one
may_write() policy helper (new auth.py) that denies non-admins when the
policy cannot be read.
B5: _finite now guards room rects, polygon vertices, view_box and
opening coordinates, not just layout positions; the declared
MAX_OPENINGS cap is finally enforced.
L4 (sub-item): every drag pipeline captures the pointer through the
tolerant helper (an inactive pointerId used to kill device/label/resize
drags); decor shapes gained a bounds clamp so they cannot be dragged far
outside the plan and persisted there.
+2 backend tests (16); both changelogs updated in this commit
- 10 most recent releases translated; older entries stay English-only
- policy updated in STATUS.md and CONTRIBUTING: user-visible changes go
into BOTH changelogs in the same commit (the user base is largely
Russian-speaking — see the Telegram chat)
- cross-links between the two files and from both READMEs