SWS-12500-custom-component/custom_components/sws12500
SchiZzA a467c4b6e5
fix(security): authenticate health endpoint and stop webhook-id leak
The /station/health route is registered directly on the aiohttp router, so HA's
auth middleware only flags requests without blocking them - the endpoint was
reachable unauthenticated and returned the full health snapshot.

- health_status now requires HA authentication (bearer token or signed request)
  via KEY_AUTHENTICATED and returns 401 otherwise.
- Mask the Ecowitt webhook id (the endpoint's only credential) in last_ingress
  paths via _sanitize_path, so it never enters the snapshot exposed by the health
  endpoint or the diagnostics download.
- Redact ECOWITT_WEBHOOK_ID in diagnostics.
- Compare the Ecowitt webhook id in constant time (hmac.compare_digest), matching
  the WU/WSLink credential checks.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-25 21:47:52 +02:00
..
translations Add stall sensor detection. 2026-07-25 21:47:50 +02:00
__init__.py fix(routes): rebind sticky health route on reload; defensive resolve 2026-07-25 21:47:51 +02:00
battery_sensors.py Implement Ecowitt protocol support and dynamic binary sensor discovery. 2026-07-25 21:47:48 +02:00
battery_sensors_def.py fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
binary_sensor.py fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
config_flow.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
const.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
coordinator.py fix(security): authenticate health endpoint and stop webhook-id leak 2026-07-25 21:47:52 +02:00
data.py Add stall sensor detection. 2026-07-25 21:47:50 +02:00
diagnostics.py fix(security): authenticate health endpoint and stop webhook-id leak 2026-07-25 21:47:52 +02:00
ecowitt.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
health_coordinator.py fix(security): authenticate health endpoint and stop webhook-id leak 2026-07-25 21:47:52 +02:00
health_sensor.py fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
icons.json Refactor SWS12500 integration for push-based updates 2026-07-25 21:45:07 +02:00
legacy.py fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
manifest.json Implement Ecowitt protocol support and dynamic binary sensor discovery. 2026-07-25 21:47:48 +02:00
pocasti_cz.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
routes.py fix(routes): rebind sticky health route on reload; defensive resolve 2026-07-25 21:47:51 +02:00
sensor.py fix(ecowitt): Connect Ecowitt bridge to sensor platform earlier 2026-07-25 21:47:50 +02:00
sensors_common.py fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
sensors_weather.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
sensors_wslink.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00
staleness.py Add stall sensor detection. 2026-07-25 21:47:50 +02:00
strings.json fix: coordinator reuse, route dispatcher, binary sensor translations & test suite alignment 2026-07-25 21:47:50 +02:00
sws12500 Add health diagnostic sensor and extensive tests for sws12500 2026-07-25 21:45:08 +02:00
utils.py fix(utils): widen wind_dir_to_text param to float | str | None 2026-07-25 21:47:51 +02:00
windy_func.py fix: address review findings across forwarders and helpers 2026-07-25 21:47:51 +02:00