Skip to content

Conversation

@Makhuta
Copy link
Contributor

@Makhuta Makhuta commented Feb 18, 2025

  • fixed the issue with the redirect being security threat

Makhuta added 4 commits May 26, 2024 12:12
- logging all used/possible images for fanart/poster
- fixed the issue with the redirect being security threat
@mkanet
Copy link
Collaborator

mkanet commented Feb 18, 2025

Wow @Makhuta I didnt think you would even see my message, let alone provide a fix so quickly! Thank you so much! Ill check it out.

@mkanet mkanet merged commit 43bf9ed into custom-components:master Feb 18, 2025
1 check passed
@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 18, 2025

Yeah, I was just readying myself to go to bed and I got the notification 😄
Let's hope this will be enough

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 18, 2025

Let me know if any other issue arisees 😄

Won't mind the ping if the fix go through 😁

@mkanet
Copy link
Collaborator

mkanet commented Feb 18, 2025

Let me know if any other issue arisees 😄

Won't mind the ping if the fix go through 😁

Ill let you know if this is good enough or not. Thanks again for the quick response!

@mkanet
Copy link
Collaborator

mkanet commented Feb 19, 2025

@Makhuta Sorry to bother you again. This is the response I got:

It's better, but you are still providing an unauthenticated endpoint.

Any ideas how to satisfy his request?

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 19, 2025

OMG... Then it needs to be changed by downloading the images into some folder and providing like that so the only access would be inside the integration and everything else will be already cached inside HA

Edit: I will look into it later today.

@mkanet
Copy link
Collaborator

mkanet commented Feb 19, 2025

OMG... Then it needs to be changed by downloading the images into some folder and providing like that so the only access would be inside the integration and everything else will be already cached inside HA

Edit: I will look into it later today.

Are there any cases where new images wouldn't be downloadable/available to the integration from the Plex server?

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 19, 2025

I don't think so and even if there was this could be checked in the current redirect which will also need rewrite acording to the necessary changes

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 19, 2025

Just made pull request @mkanet hope it will now suffice 🤞

@mkanet
Copy link
Collaborator

mkanet commented Feb 20, 2025

@Makhuta unfortunately, he said this is actually worse. However, he offered a solution. Do you think you could use the solution he offered? I think this is the only way he will approve this integration from being added to HACS.


Ludeeus — Yesterday at 10:04 PM
The thing is, this is actually worse.
That there is similar to what caused:

https://www.home-assistant.io/blog/2021/01/22/security-disclosure/
And there is now a lot of disk I/O using:
https://github.com/home-assistant/core/blob/dev/homeassistant/components/http/auth.py#L45

It is the only option.

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 20, 2025

Maaaan I understand the issue but this is so frustrating. Ok I will look into it. 😑

@mkanet
Copy link
Collaborator

mkanet commented Feb 20, 2025

Maaaan I understand the issue but this is so frustrating. Ok I will look into it. 😑

Yeah, I know it sucks. Unfortunately, this appears to be the only way we can get this integration approved on HACS.

@Makhuta
Copy link
Contributor Author

Makhuta commented Feb 20, 2025

BTW if you have Discord you can contact me here Makhuta#makhuta @mkanet luckily at these times I am mostly on my PC so I am able to respond quickly but I don't think I will be able to solve that alone so I think it would be easier and probably faster to communicate there for this and probably for future projects

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants