The /station/health route is registered directly on the aiohttp router, so HA's
auth middleware only flags requests without blocking them - the endpoint was
reachable unauthenticated and returned the full health snapshot.
- health_status now requires HA authentication (bearer token or signed request)
via KEY_AUTHENTICATED and returns 401 otherwise.
- Mask the Ecowitt webhook id (the endpoint's only credential) in last_ingress
paths via _sanitize_path, so it never enters the snapshot exposed by the health
endpoint or the diagnostics download.
- Redact ECOWITT_WEBHOOK_ID in diagnostics.
- Compare the Ecowitt webhook id in constant time (hmac.compare_digest), matching
the WU/WSLink credential checks.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>