mirror of
https://github.com/Matysh/houseplan-card
synced 2026-09-29 03:09:36 +00:00
- Default admin_only on; config/get returns can_write; card editors follow it and fail closed without hass.user (P0-4). - README EN/RU differentiation vs GUI draw cards / easy-floorplan (P0-3). - Tighten marker binding, ripple_color, decor extents, space id (P3-4). - quality_scale test path + deprecated card tap_action note (P3-5). - Demo hass.user + can_write; unique marker id in upload overwrite test. Co-authored-by: Matysh <Matysh@users.noreply.github.com>
32 lines
1.2 KiB
Python
32 lines
1.2 KiB
Python
"""Single source of truth for the write-authorization policy.
|
|
|
|
The WS and HTTP paths used to duplicate this decision and drifted apart: the
|
|
WS copy was fixed to fail closed while the upload view still failed OPEN when
|
|
the config entry was unavailable (audit follow-up B2, 2026-07-27). One helper,
|
|
one behaviour.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
from homeassistant.core import HomeAssistant
|
|
|
|
from .const import CONF_ADMIN_ONLY
|
|
from .store import get_entry
|
|
|
|
|
|
def may_write(hass: HomeAssistant, user) -> bool:
|
|
"""True when `user` may modify House Plan data.
|
|
|
|
Fails CLOSED: when the entry cannot be read — during a reload, or while the
|
|
integration is disabled — the policy is unknown, and "unknown" is not the
|
|
same as "permissive": only admins are allowed through.
|
|
"""
|
|
is_admin = bool(getattr(user, "is_admin", False))
|
|
entry = get_entry(hass)
|
|
if entry is None:
|
|
return is_admin
|
|
# Default TRUE when the key is absent (audit P0-4, 2026-08-05): the card
|
|
# UI has always been admin-gated, and an unset option must not open every
|
|
# write WS/HTTP path to every authenticated household user.
|
|
admin_only = bool(entry.options.get(CONF_ADMIN_ONLY, True))
|
|
return is_admin if admin_only else True
|