Skip to content

Releases: wimmme/shellylanman

v0.9.6

Choose a tag to compare

@github-actions github-actions released this 08 Oct 12:19

Create a profile from a Shelly you already set up, and a release check that fits the Home Assistant app.

Added

  • Create profile… (Devices page, one device selected): reads the device and lists the settings a profile can
    take over, with a tick; those that differ from a Shelly as it leaves the factory are ticked at first. Then the
    profile editor opens with them filled in; the profile's name is required and the passwords are typed (a
    device does not tell them). GET /api/v1/profiles/from-device.

Changed

  • Check for new ShellyLanMan versions is now the first setting under Settings → General, where
    the About page's "Release check off" link leads (it was at the bottom, between other settings).
  • README links to the Home Assistant Community thread.
  • The profile's name is marked as required in the editor.
  • In the Home Assistant app the release check looks at the app's releases (shellylanman-ha), where Home Assistant gets
    its updates from, and links there; "Skip this version" is not offered in the app (it would only hide ShellyLanMan's
    own line).

v0.9.5

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:46

Two wizards for new Shellys (firmware through the device's own access point, and
"Set up a new Shelly" with profiles), an update arrow, an OpenAPI description of the
API — and two security fixes: the device log needs the login, and the raw RPC
endpoint no longer runs anything it is given.

Added

  • A device with a newer stable firmware shows ↑ after its status (like ↻ for "reboot
    needed"), with the version in the tooltip; a summary chip Updates and a selection
    Firmware update available. The device reports it itself, so it costs no extra request.
    The MCP device list says update_available.

  • The REST API is described in OpenAPI 3.1 at /api/v1/openapi.json (linked on the
    About page): every operation with its parameters, bodies, answers and errors, for
    Postman, Swagger UI or a code generator. A test keeps it equal to the routes.

  • Update firmware through a device's own access point, a wizard with QR codes (Firmware
    page): give the access point's name (or pick the device); the file goes to the phone, a QR code
    joins the phone to the device's access point, another opens 192.168.33.1, and ShellyLanMan waits
    until the device is back and shows its version. It also serves a Shelly ShellyLanMan does not know.
    Where the access point of a Gen2+ device is switched off, the wizard offers to switch it on; for Gen1 it says how to do it in the device's page.

  • Set up a new Shelly: a wizard (button on the Devices page) with profiles (Settings →
    Profiles). A profile says what a new device gets: a name made from a pattern, login, MQTT, time
    server, cloud and the checklist's settings (eco, LED, access point, roaming, automatic firmware
    update), and a reminder of your Wi-Fi's name (its password is never kept). The phone joins the new
    device's own access point (QR code), opens its page (QR code) and you enter your Wi-Fi there; when the
    device is on your network ShellyLanMan shows what the profile would do and, after your go, does it.
    Passwords in a profile are stored encrypted and are never shown again. GET/POST /api/v1/profiles and more.

Changed

  • The raw RPC endpoint behind the scheduler's test method button (POST /api/v1/devices/{id}/rpc)
    no longer runs anything it is given: methods that restart, update, delete, or replace code
    or a settings block ask for confirmation (a dialog, or confirm: true in the API); a
    factory reset, a Wi-Fi reset and the delete-all methods are refused there.

Fixed

  • A device's live log (/ws/log/…) could be opened without the UI password; it is now
    behind the login like the rest.

v0.9.4

Choose a tag to compare

@github-actions github-actions released this 06 Oct 21:00

A Log page: see ShellyLanMan's own log in the browser.

Added

  • Log page, above Settings: ShellyLanMan's own log — the last 1000 lines of this run,
    kept in memory, live while the page is open. Filter by level (information and up,
    warnings and errors, errors only) and by text; pause, clear, copy. GET /api/v1/log.

v0.9.3

Choose a tag to compare

@github-actions github-actions released this 06 Oct 11:47

Ports: one setting, shown in ShellyLanMan — and the Home Assistant app no longer
clashes with other apps on the same host.

Changed

  • The port has one setting: SHELLYLANMAN_PORT (Docker: docker-compose.yml or
    docker run -e; the Home Assistant app: option port). Settings → General → Ports
    shows the ports in use and where to change them; the page no longer changes the port.
    SHELLYLANMAN_LISTEN is gone.
  • docker-compose.yml lists every option, the optional ones in comments; the README's
    Quick start is that file.
  • A port that is already taken stops ShellyLanMan with a message naming the port and
    where to set another one.
  • Home Assistant app: the sidebar (ingress) uses a free port that Home Assistant
    chooses, instead of 8099 — it clashed with another app on the same host.

Added

  • README: Shellys with a password — how ShellyLanMan logs in to protected Shellys.
  • localUrl in GET /api/v1/status and /api/v1/about (Home Assistant app): where the
    integration next to the app reaches it without token.

v0.9.2

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:03

More room on the screen: the sidebar can be full or minimal, as in Home Assistant.

Added

  • Full or minimal sidebar on wide screens, as in Home Assistant: the button at the top
    left switches between icons with labels and icons only (remembered per browser);
    the logo moved to the right of the name. On a phone the ☰ drawer stays.

Fixed

  • Settings → Security in Home Assistant's sidebar no longer says that switching the
    password off needs the current one.

Changed

  • README: screenshots with the new sidebar header.

v0.9.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 11:40

A forgotten UI password can be reset in the Home Assistant app too.

Fixed

  • Home Assistant app: in Home Assistant's sidebar the UI password can be changed or
    switched off without the current one (you are logged in to Home Assistant there,
    and the app cannot be started with SHELLYLANMAN_RESET_PASSWORD).

Changed

  • README and docker-compose.yml: how to reset a forgotten password.

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 10:38

Security: an optional password for the UI, two fixes found by code scanning, and
the repository checked by Dependabot and CodeQL.

Added

  • Optional password for the UI (Settings → Security, off by default): one password,
    no user name; a login page with Stay logged in (30 days since the last use);
    slower after five wrong tries; not asked under Home Assistant's sidebar, where
    Home Assistant's login applies. Programs use the MCP token for the API; the
    Home Assistant integration next to the app keeps working without one (the app's
    loopback listener serves its calls). Forgotten: start once with
    SHELLYLANMAN_RESET_PASSWORD=1.

Changed

  • Repository security: Dependabot (alerts, security and weekly version updates),
    CodeQL code scanning and private vulnerability reporting are on.
  • Updated: Go modules, Node 26 for building the web UI.
  • README: tests, CodeQL and PayPal badges.

Fixed

  • Device login (digest): the realm, nonce and opaque a device sends are quoted
    properly in the answer, so a device cannot add header fields of its own (CodeQL).
  • Backups: a device id . or .. can no longer point outside the backups folder
    (CodeQL).

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 00:00

BLU devices that a gateway only relays get a row of their own, and a wizard tells
you which model they are.

Added

  • Rows for BLU devices that a gateway only relays (BLE.CloudRelay): readings,
    buttons and sensors from their BTHome messages; read only — no backup, restore
    or logs. The model is estimated from what the device sends ("?") until it is
    identified; a name can be given under Notes.
  • Identify BLU devices: a wizard in which a gateway listens while you put a BLU
    device in pairing mode, and shows the model of every device that answers. The
    model is stored in ShellyLanMan's archive; nothing changes on the device or the
    gateway. On the Devices page (Identify) and in the checklist's BLE dialog.
  • API: relay in the device list, GET /api/v1/blu/gateways,
    POST /api/v1/blu/identify (events blu.identify, blu.discovered), and an
    optional name when saving the notes of a relayed BLU device.

Changed

  • README: screenshots with a relayed BLU device and the Identify wizard.

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 01:51

Your Shellys into Home Assistant in one go: the Home Assistant integration adds the
Shellys ShellyLanMan knows to Home Assistant's Shelly integration.

Added

  • API for the Home Assistant integration (adding Shellys to Home Assistant's Shelly
    integration): protected in the device list, and
    GET /api/v1/devices/{id}/credentials with the credentials ShellyLanMan uses for a
    device — only with the MCP token at access level configure, or on the Home
    Assistant app's loopback listener; never on the open LAN port without that token.

v0.6.4

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:31

The script editor gives feedback at once and never opens blind.

Changed

  • Script editor: the window opens at once and says it is reading the script, instead
    of nothing happening for seconds on a device with weak Wi-Fi. A second click or
    double-click does not open a second editor.

Fixed

  • Script editor: when the device could not send the code (busy, HTTP error), an empty
    editor opened, and Upload would have wiped the script on the device. It now shows
    the error with Retry, and Upload / Upload and run stay off until the code was
    read. The API and MCP report the error too (Script.GetCode).