Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

HA: Putting snapshots in /config/www allows for public access to cameras #660

Closed
jackrosenthal opened this issue Jan 4, 2023 · 2 comments
Labels
enhancement New feature or request

Comments

@jackrosenthal
Copy link

The feature to copy snapshots into /config/www is not only unnecessary (HA can be pointed at http://localhost:5000 just fine), but also leaks camera images to the public if the home assistant server is port forwarded to the internet, as /local/* can be viewed without authentication.

@jackrosenthal
Copy link
Author

It looks like users can mitigate this privacy risk by setting IMG_DIR in the configuration to something outside of config/www.

@mrlt8 mrlt8 added the enhancement New feature or request label Jan 7, 2023
@mrlt8
Copy link
Owner

mrlt8 commented Jan 7, 2023

Good point. The snapshots in /config/www actually predate the the existence of the web UI and can probably be removed now that we have the web UI.

mrlt8 added a commit that referenced this issue Apr 7, 2023
mrlt8 added a commit that referenced this issue Apr 7, 2023
* HA MQTT auto discovery #751

* remove debug

* Update stream.py

* Change default IMG_DIR to media #660

* Fix API snapshots

* Command to change FPS #609 #749  #755

* Update docs
@mrlt8 mrlt8 closed this as completed Apr 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants