Repository navigation
Releases: wimmme/shellylanman
Release list
v0.9.6
Create a profile from a Shelly you already set up, and a release check that fits the Home Assistant app.
Added
- Create profile… (Devices page, one device selected): reads the device and lists the settings a profile can
take over, with a tick; those that differ from a Shelly as it leaves the factory are ticked at first. Then the
profile editor opens with them filled in; the profile's name is required and the passwords are typed (a
device does not tell them).GET /api/v1/profiles/from-device.
Changed
- Check for new ShellyLanMan versions is now the first setting under Settings → General, where
the About page's "Release check off" link leads (it was at the bottom, between other settings). - README links to the Home Assistant Community thread.
- The profile's name is marked as required in the editor.
- In the Home Assistant app the release check looks at the app's releases (
shellylanman-ha), where Home Assistant gets
its updates from, and links there; "Skip this version" is not offered in the app (it would only hide ShellyLanMan's
own line).
v0.9.5
Two wizards for new Shellys (firmware through the device's own access point, and
"Set up a new Shelly" with profiles), an update arrow, an OpenAPI description of the
API — and two security fixes: the device log needs the login, and the raw RPC
endpoint no longer runs anything it is given.
Added
-
A device with a newer stable firmware shows ↑ after its status (like ↻ for "reboot
needed"), with the version in the tooltip; a summary chip Updates and a selection
Firmware update available. The device reports it itself, so it costs no extra request.
The MCP device list saysupdate_available. -
The REST API is described in OpenAPI 3.1 at
/api/v1/openapi.json(linked on the
About page): every operation with its parameters, bodies, answers and errors, for
Postman, Swagger UI or a code generator. A test keeps it equal to the routes. -
Update firmware through a device's own access point, a wizard with QR codes (Firmware
page): give the access point's name (or pick the device); the file goes to the phone, a QR code
joins the phone to the device's access point, another opens192.168.33.1, and ShellyLanMan waits
until the device is back and shows its version. It also serves a Shelly ShellyLanMan does not know.
Where the access point of a Gen2+ device is switched off, the wizard offers to switch it on; for Gen1 it says how to do it in the device's page. -
Set up a new Shelly: a wizard (button on the Devices page) with profiles (Settings →
Profiles). A profile says what a new device gets: a name made from a pattern, login, MQTT, time
server, cloud and the checklist's settings (eco, LED, access point, roaming, automatic firmware
update), and a reminder of your Wi-Fi's name (its password is never kept). The phone joins the new
device's own access point (QR code), opens its page (QR code) and you enter your Wi-Fi there; when the
device is on your network ShellyLanMan shows what the profile would do and, after your go, does it.
Passwords in a profile are stored encrypted and are never shown again.GET/POST /api/v1/profilesand more.
Changed
- The raw RPC endpoint behind the scheduler's test method button (
POST /api/v1/devices/{id}/rpc)
no longer runs anything it is given: methods that restart, update, delete, or replace code
or a settings block ask for confirmation (a dialog, orconfirm: truein the API); a
factory reset, a Wi-Fi reset and the delete-all methods are refused there.
Fixed
- A device's live log (
/ws/log/…) could be opened without the UI password; it is now
behind the login like the rest.
v0.9.4
A Log page: see ShellyLanMan's own log in the browser.
Added
- Log page, above Settings: ShellyLanMan's own log — the last 1000 lines of this run,
kept in memory, live while the page is open. Filter by level (information and up,
warnings and errors, errors only) and by text; pause, clear, copy.GET /api/v1/log.
v0.9.3
Ports: one setting, shown in ShellyLanMan — and the Home Assistant app no longer
clashes with other apps on the same host.
Changed
- The port has one setting:
SHELLYLANMAN_PORT(Docker:docker-compose.ymlor
docker run -e; the Home Assistant app: optionport). Settings → General → Ports
shows the ports in use and where to change them; the page no longer changes the port.
SHELLYLANMAN_LISTENis gone. docker-compose.ymllists every option, the optional ones in comments; the README's
Quick start is that file.- A port that is already taken stops ShellyLanMan with a message naming the port and
where to set another one. - Home Assistant app: the sidebar (ingress) uses a free port that Home Assistant
chooses, instead of 8099 — it clashed with another app on the same host.
Added
- README: Shellys with a password — how ShellyLanMan logs in to protected Shellys.
localUrlinGET /api/v1/statusand/api/v1/about(Home Assistant app): where the
integration next to the app reaches it without token.
v0.9.2
More room on the screen: the sidebar can be full or minimal, as in Home Assistant.
Added
- Full or minimal sidebar on wide screens, as in Home Assistant: the button at the top
left switches between icons with labels and icons only (remembered per browser);
the logo moved to the right of the name. On a phone the ☰ drawer stays.
Fixed
- Settings → Security in Home Assistant's sidebar no longer says that switching the
password off needs the current one.
Changed
- README: screenshots with the new sidebar header.
v0.9.1
A forgotten UI password can be reset in the Home Assistant app too.
Fixed
- Home Assistant app: in Home Assistant's sidebar the UI password can be changed or
switched off without the current one (you are logged in to Home Assistant there,
and the app cannot be started withSHELLYLANMAN_RESET_PASSWORD).
Changed
- README and
docker-compose.yml: how to reset a forgotten password.
v0.9.0
Security: an optional password for the UI, two fixes found by code scanning, and
the repository checked by Dependabot and CodeQL.
Added
- Optional password for the UI (Settings → Security, off by default): one password,
no user name; a login page with Stay logged in (30 days since the last use);
slower after five wrong tries; not asked under Home Assistant's sidebar, where
Home Assistant's login applies. Programs use the MCP token for the API; the
Home Assistant integration next to the app keeps working without one (the app's
loopback listener serves its calls). Forgotten: start once with
SHELLYLANMAN_RESET_PASSWORD=1.
Changed
- Repository security: Dependabot (alerts, security and weekly version updates),
CodeQL code scanning and private vulnerability reporting are on. - Updated: Go modules, Node 26 for building the web UI.
- README: tests, CodeQL and PayPal badges.
Fixed
- Device login (digest): the realm, nonce and opaque a device sends are quoted
properly in the answer, so a device cannot add header fields of its own (CodeQL). - Backups: a device id
.or..can no longer point outside the backups folder
(CodeQL).
v0.8.0
BLU devices that a gateway only relays get a row of their own, and a wizard tells
you which model they are.
Added
- Rows for BLU devices that a gateway only relays (BLE.CloudRelay): readings,
buttons and sensors from their BTHome messages; read only — no backup, restore
or logs. The model is estimated from what the device sends ("?") until it is
identified; a name can be given under Notes. - Identify BLU devices: a wizard in which a gateway listens while you put a BLU
device in pairing mode, and shows the model of every device that answers. The
model is stored in ShellyLanMan's archive; nothing changes on the device or the
gateway. On the Devices page (Identify) and in the checklist's BLE dialog. - API:
relayin the device list,GET /api/v1/blu/gateways,
POST /api/v1/blu/identify(eventsblu.identify,blu.discovered), and an
optionalnamewhen saving the notes of a relayed BLU device.
Changed
- README: screenshots with a relayed BLU device and the Identify wizard.
v0.7.0
Your Shellys into Home Assistant in one go: the Home Assistant integration adds the
Shellys ShellyLanMan knows to Home Assistant's Shelly integration.
Added
- API for the Home Assistant integration (adding Shellys to Home Assistant's Shelly
integration):protectedin the device list, and
GET /api/v1/devices/{id}/credentialswith the credentials ShellyLanMan uses for a
device — only with the MCP token at access level configure, or on the Home
Assistant app's loopback listener; never on the open LAN port without that token.
v0.6.4
The script editor gives feedback at once and never opens blind.
Changed
- Script editor: the window opens at once and says it is reading the script, instead
of nothing happening for seconds on a device with weak Wi-Fi. A second click or
double-click does not open a second editor.
Fixed
- Script editor: when the device could not send the code (busy, HTTP error), an empty
editor opened, and Upload would have wiped the script on the device. It now shows
the error with Retry, and Upload / Upload and run stay off until the code was
read. The API and MCP report the error too (Script.GetCode).