The /station/health route is registered directly on the aiohttp router, so HA's auth middleware only flags requests without blocking them - the endpoint was reachable unauthenticated and returned the full health snapshot. - health_status now requires HA authentication (bearer token or signed request) via KEY_AUTHENTICATED and returns 401 otherwise. - Mask the Ecowitt webhook id (the endpoint's only credential) in last_ingress paths via _sanitize_path, so it never enters the snapshot exposed by the health endpoint or the diagnostics download. - Redact ECOWITT_WEBHOOK_ID in diagnostics. - Compare the Ecowitt webhook id in constant time (hmac.compare_digest), matching the WU/WSLink credential checks. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| sws12500 | ||