mirror of
https://github.com/Matysh/houseplan-card
synced 2026-07-31 08:28:31 +00:00
The v1.43.0 auth fix closed the hole but left the DISPLAY path unauthenticated: HA authenticates by a Bearer header or an authSig signed path, and an <image href> / <a href> sends neither, so plan backgrounds and manual links returned 401. Reproduced live before the fix (fetch 401, Image onerror). - new WS houseplan/content/sign mints async_sign_path urls (24 h, bound to the connection's refresh token, only for our own endpoint) - the card resolves display urls through _display(): signed when known, requests a batched signature otherwise, re-renders when it lands, and drops all signatures every 12 h so long-lived wall tablets stay valid - houseplan-space-card signs its background too - backend test asserts the unsigned url is refused and the signed one returns the bytes WITHOUT an Authorization header
Synthetic demo home
A fully fictional house (plans, devices, states) used for README screenshots, the demo GIF and headless smoke tests — so no real home data ever appears in public materials.
srv/demo.html— self-contained host page:<ha-icon>/<ha-card>stubs and a fakehass(registries, states,callWS,callService, floors).srv/assets/— generated plan SVGs andicons.js(node demo/gen_icons.mjs, needs the repo's devDependencies). The card bundle is copied fromdist/:cp dist/houseplan-card.js demo/srv/assets/.serve.mjs— playwright launcher (route interception, no web server).smoke_*.mjs— feature smoke tests; run with a Chromium installed viaPLAYWRIGHT_BROWSERS_PATH=<dir> npx playwright install chromium-headless-shell.
Note for sandboxed sessions: /tmp does not survive; this directory is the
persistent home of the harness (docs/DEVELOPMENT.md has the LD_LIBRARY_PATH recipe).