mirror of
https://github.com/Matysh/houseplan-card
synced 2026-07-31 16:38:31 +00:00
The card signs content urls because a browser cannot authenticate an <image href>. But _display() was called inside _buildModel(), and the space model is memoized on the config fingerprint — so the UNSIGNED url froze in the cache and the signature, which did arrive, never reached the element. The plan never loaded, and the browser kept hitting the unsigned path: 401, which Home Assistant reports as a failed login attempt from the viewer's own IP (that is how the owner spotted it). PDF links were unaffected: they already resolved at render time. - _buildModel() keeps the raw plan_url; the render pass calls _display(). - _display() returns '' for an unsigned content url instead of the plain path, and the <image> is not emitted at all until the signature lands — no 401, no spurious login-attempt warning. - _resign() replaces 'drop everything and re-request': the previous urls are kept until the new ones arrive, so a wall tablet never blanks. - demo/smoke_plan_signed.mjs: reproduces on v1.44.6 (href stays ?v=..., never ?authSig=), passes here. TESTING.md row added. - docs: CHANGELOG.md + CHANGELOG.ru.md + STATUS.md.
23 lines
682 B
Python
Executable File
23 lines
682 B
Python
Executable File
"""Constants of the House Plan integration."""
|
|
|
|
DOMAIN = "houseplan"
|
|
STORAGE_KEY = f"{DOMAIN}.layout"
|
|
STORAGE_CONFIG_KEY = f"{DOMAIN}.config"
|
|
STORAGE_VERSION = 1
|
|
STORAGE_MINOR_VERSION = 1
|
|
FRONTEND_URL = "/houseplan_files/houseplan-card.js"
|
|
PLANS_URL = "/houseplan_files/plans"
|
|
PLANS_DIR = "houseplan/plans" # relative to the HA configuration directory
|
|
FILES_URL = "/houseplan_files/files"
|
|
# authenticated read path (audit B1): /api/houseplan/content/<plans|files>/<sub>/<name>
|
|
CONTENT_URL = "/api/houseplan/content"
|
|
FILES_DIR = "houseplan/files"
|
|
CONF_ADMIN_ONLY = "admin_only"
|
|
VERSION = "1.44.7"
|
|
|
|
DEFAULT_CONFIG: dict = {
|
|
"spaces": [],
|
|
"markers": [],
|
|
"settings": {},
|
|
}
|