Skip to content

Releases: ttiimmaahh/omarivian

OmaRivian v0.4.3

Choose a tag to compare

@github-actions github-actions released this 04 Sep 21:54

OmaRivian v0.4.3

OmaRivian v0.4.3 fixes automatic session renewal and restores cached vehicle artwork after a shell restart during an API or authentication failure.

Fixes

  • Check access-token expiry before each scheduled or manual poll and renew tokens that are expired or within five minutes of expiry. Rivian can report an expired access token as INTERNAL_SERVER_ERROR, which previously bypassed authentication recovery and left the widget showing stale data.
  • Bootstrap renewal without sending stale app-session or CSRF headers. Save rotated credentials immediately, before further API requests, while preserving the distinct user-session token needed by Parallax telemetry.
  • Retain the existing one-renewal-per-poll limit and reactive authentication retry for revoked sessions or opaque access tokens. No separate daemon, saved password, or additional dependency is required.
  • Restore last-known vehicle data and local artwork from an error-state cache on startup. Cached data remains visibly stale, and unlinking still clears it.
  • Add regression coverage for repeated token rotation across independent polls, renewal failures, keyring persistence, and cold-start artwork recovery.

Validation

  • All 109 Python tests and the JavaScript model/panel cache tests pass.
  • Omarchy manifest validation and QML lint pass.
  • A live refresh successfully renewed an expired access token without relinking and recovered vehicle telemetry and artwork.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

Existing settings and linked account credentials are preserved. The next scheduled or manual refresh renews an expired access token when the saved refresh token is still valid. A revoked or expired refresh token still requires Link account.

Known limitations

  • OmaRivian remains early-development software using Rivian's private, unsupported owner API; upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.4.2

Choose a tag to compare

@github-actions github-actions released this 02 Sep 22:57

OmaRivian v0.4.2

OmaRivian v0.4.2 refreshes the panel screenshot. There are no code, behavior, or API changes from v0.4.1.

Highlights

  • Replaces the README and marketplace preview with a capture of the current panel. The previous image predated v0.3.0: it showed Re-link and Unlink buttons in place of the settings gear, and a "Charging" fact label where the charger cell now reports whether the cable is connected.
  • Captures the panel from synthetic state rather than redacting a real one, so the identity, location, VIN suffix, odometer, and telemetry on screen are demo values. The figures match the previous screenshot.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

Existing settings and linked account credentials are preserved. Upgrading from v0.4.1 changes nothing at runtime.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • On R2, chargerState is the only charge signal the API returns; chargerStatus and chargePortState come back empty, and no allowlisted Parallax topic covers charging.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.4.1

Choose a tag to compare

@github-actions github-actions released this 02 Sep 22:25

OmaRivian v0.4.1

OmaRivian v0.4.1 corrects the charger state mapping, which could report a parked, unplugged vehicle as actively charging.

Highlights

  • Maps Rivian's chargerState and chargerStatus enum values explicitly instead of matching substrings. The previous heuristic read the charging_ready state—which means the vehicle is ready to charge and is not connected—as an active charging session, showing "Charging" and "Plugged in" for a vehicle sitting unplugged.
  • Leaves the plug undecided for unrecognized charger values rather than inferring a connection that was never reported.
  • Clears the remaining charge time unless charging is actually active, so a countdown left over from a finished session no longer appears as a current estimate.
  • Renders known charger states as readable labels in the panel instead of title-casing the raw API token.
  • Adds a tools/dump-sample-data helper that saves raw vehicle, telemetry, and derived responses to a git-ignored sample-data/ directory for local debugging.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

Existing settings and linked account credentials are preserved.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • On R2, chargerState is the only charge signal the API returns; chargerStatus and chargePortState come back empty, and no allowlisted Parallax topic covers charging.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.4.0

Choose a tag to compare

@github-actions github-actions released this 27 Aug 17:48

OmaRivian v0.4.0

OmaRivian v0.4.0 restores reliable unattended account renewal, preserves live R2 telemetry across renewed sessions, and makes active vehicle status easier to scan.

Highlights

  • Recognizes Rivian's expired-session GraphQL response even when it arrives as HTTP 400, renews the session, persists rotated access and refresh tokens, and retries once.
  • Preserves the distinct U-Sess credential during access-token renewal so Parallax cabin, power-state, security, and opt-in location telemetry continue working.
  • Displays a prominent semantic vehicle activity state instead of surfacing an unhelpful Unknown power state.
  • Shows active charging in green with a gently pulsing status dot and an estimated time remaining to the configured charge limit.
  • Shows driving in blue and sleeping or standby states with a quieter neutral treatment.
  • Keeps the connection, activity, charger, and charge-limit information distinct instead of repeating the same state in multiple rows.

Security and privacy

  • HTTP 400 response bodies use the same response-size and deadline bounds as successful GraphQL responses.
  • Authentication is detected across all returned GraphQL errors, including mixed or malformed error arrays.
  • Upstream GraphQL error text is sanitized before it can reach local state or the QML interface.
  • Failed Parallax handshakes close the active TLS stream, and artwork-cache cleanup is bounded.
  • The plugin remains read-only, with no vehicle-control operations or generic query interface.
  • Location remains opt-in and is omitted from local state when disabled.
  • Credentials remain stored through Linux Secret Service; no session credentials are exposed to QML.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

Existing settings and linked-account credentials are preserved. If a previous OmaRivian version already replaced the distinct Parallax U-Sess credential during renewal, relink the account once after upgrading. Subsequent automatic renewals preserve that credential.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • Vehicle location and cabin telemetry depend on what Rivian reports; a sleeping or offline vehicle may temporarily show Not reported.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.3.1

Choose a tag to compare

@github-actions github-actions released this 26 Aug 22:18

OmaRivian v0.3.1

OmaRivian v0.3.1 hardens its local and network trust boundaries, improves session recovery, and makes unlink failures explicit.

Highlights

  • Forces all QML vehicle and status text to render as plain text, preventing API-supplied markup from reaching Qt's rich-text renderer.
  • Adds strict response-size and total-duration bounds for GraphQL and artwork downloads, including trickling responses.
  • Validates GraphQL response shapes and limits vehicle-list fanout before data reaches local state.
  • Bounds API-supplied strings so generated state remains within the helper's safe read limit.
  • Rejects symlinked, FIFO, and other non-regular private state or cache paths instead of following or blocking on them.
  • Adds timeouts for keyring access and command-lock acquisition.
  • Refreshes an expired Rivian session when selected-vehicle telemetry rejects authentication, while preserving legacy telemetry for generic Parallax failures.
  • Reports failed credential deletion and residual local files during unlink instead of silently claiming success.
  • Keeps only the current artwork for each vehicle to prevent stale cache accumulation.
  • Displays the installed OmaRivian version on the settings page.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

Existing settings and linked account credentials are preserved.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.3.0

Choose a tag to compare

@github-actions github-actions released this 26 Aug 16:14

OmaRivian v0.3.0

OmaRivian v0.3.0 makes everyday vehicle status easier to scan, adds a dedicated in-panel settings experience, and strengthens location privacy when preferences change.

Highlights

  • Adds a visible settings action beside Refresh in the panel header.
  • Presents Appearance, Privacy, and Account settings as a dedicated page inside the existing Omarchy popup.
  • Lets you show the battery percentage in the bar and enable vehicle location directly from the panel, with immediate persistence.
  • Moves account linking and unlinking out of the vehicle-detail feed while retaining unlink confirmation.
  • Returns from settings to vehicle details with Done or Escape; reopening the popup always starts on vehicle details.
  • Fits the complete vehicle-detail view without unnecessary scrolling when the display has room, while retaining safe scrolling on smaller displays.

Privacy and reliability

  • Location remains disabled by default.
  • Changing the location preference immediately refreshes local state; disabling it removes cached coordinates.
  • Stale or overlapping refreshes cannot restore an older location preference after a newer choice.
  • Helper commands that mutate credentials, preferences, or state are serialized through a private local lock.
  • Startup synchronization removes location data left by an out-of-band settings change, and unlinking clears retained vehicle data from the panel.
  • OmaRivian remains read-only and does not send vehicle-control commands.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

After updating, open the OmaRivian panel and use the settings gear in the header to manage display, privacy, and account options. Existing settings and linked account credentials are preserved.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • Vehicle location depends on what Rivian reports during a refresh; a sleeping or offline vehicle may show Not reported until it reconnects.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.2.0

Choose a tag to compare

@github-actions github-actions released this 26 Aug 12:25

OmaRivian v0.2.0

OmaRivian v0.2.0 hardens the plugin's read-only trust boundary, automatically renews expired Rivian sessions, and improves active R2 telemetry.

Highlights

  • Automatically exchanges expired Rivian refresh tokens, persists rotated credentials immediately, and retries the vehicle-list request once.
  • Uses live R2 Parallax cabin temperature, HVAC target, and heating state when legacy telemetry is missing.
  • Presents Rivian's active go power state as Driving and suppresses stale charging details while the vehicle is driving.
  • Adds clearer climate summaries such as 76°F · Heating to 75°F.
  • Includes an importable, secret-free Postman workspace for the plugin's authentication and read-only owner-API operations.

Security and privacy

  • Authenticated GraphQL responses are capped at 2 MiB.
  • Authenticated GraphQL requests reject redirects and verify the final response origin before reading the body.
  • Local state and preference reads are capped at 1 MiB, and Secret Service output is capped at 64 KiB.
  • Vehicle artwork remains restricted to Rivian-controlled HTTPS hosts and bounded downloads.
  • No vehicle-control commands or generic GraphQL query interface are included.
  • Full VINs are not written to local state, and location remains opt-in.

Upgrade

Existing Git-managed installations can update through Omarchy:

omarchy plugin update io.github.ttiimmaahh.omarivian

If the account session has expired, the next scheduled or manual refresh renews it automatically when a usable refresh token is present. Relink the account if Secret Service no longer contains a session or Rivian rejects the refresh token.

Postman workspace

Import these files from the repository:

  • postman/OmaRivian.postman_collection.json
  • postman/OmaRivian.postman_environment.example.json

Rivian does not publish a standard OAuth 2.0 authorization service for this private owner API. The collection therefore models the observed GraphQL CSRF, login/MFA, and refresh-token flow without embedding credentials.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream schema or authentication changes can interrupt functionality.
  • R2 climate field mappings are conservatively based on the published community topic reference and sanitized telemetry correlated with the Rivian app.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path remains fixture- and test-covered but has not been physically validated by the maintainer.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for installation, configuration, privacy details, unlinking, and removal.

OmaRivian v0.1.0

Choose a tag to compare

@github-actions github-actions released this 26 Aug 00:45

OmaRivian v0.1.0

OmaRivian's first public release brings read-only Rivian vehicle status to the Omarchy Quattro bar.

Highlights

  • Theme-native bar widget and responsive details panel.
  • Battery level, estimated range, charging state, locks, closures, cabin climate, software version, odometer, and last-contact status.
  • Rivian-provided vehicle artwork matching the configured model and appearance.
  • Multiple-vehicle switching with targeted refreshes.
  • Legacy-first R1 telemetry with read-only R2 Parallax fallback for fields unavailable through the legacy vehicle-state response.
  • Optional location display and map action, disabled by default.
  • Honest loading, stale, sleeping, offline, and error states.

Security and privacy

  • No vehicle-control commands are implemented.
  • Authentication secrets are entered in a terminal and session tokens are stored through Linux Secret Service.
  • Full VINs are not written to the local state cache.
  • Location is neither requested nor retained unless explicitly enabled.
  • Vehicle artwork is restricted to Rivian-controlled HTTPS hosts and cached with private file permissions.

Requirements

  • Omarchy 4 with the Quattro shell.
  • Python 3.10 or newer; no third-party Python packages are required.
  • secret-tool from libsecret and an unlocked Secret Service provider.
  • A Rivian owner account with at least one vehicle.

Install

omarchy plugin add https://github.com/ttiimmaahh/omarivian.git --enable

Open the widget and select Link account, or run ./tools/omarivian link from the installed plugin directory.

Known limitations

  • Rivian's owner API is private and unsupported, so upstream changes can interrupt functionality.
  • R2 telemetry is validated against the maintainer's vehicle. The retained R1 path is covered by fixtures and tests but has not been physically validated by the maintainer.
  • Normal Omarchy installation and updates follow the repository's default branch rather than pinning this release tag.

See the README for configuration, privacy details, unlinking, and removal.