Repository navigation
v0.9.0
Security: an optional password for the UI, two fixes found by code scanning, and
the repository checked by Dependabot and CodeQL.
Added
- Optional password for the UI (Settings → Security, off by default): one password,
no user name; a login page with Stay logged in (30 days since the last use);
slower after five wrong tries; not asked under Home Assistant's sidebar, where
Home Assistant's login applies. Programs use the MCP token for the API; the
Home Assistant integration next to the app keeps working without one (the app's
loopback listener serves its calls). Forgotten: start once with
SHELLYLANMAN_RESET_PASSWORD=1.
Changed
- Repository security: Dependabot (alerts, security and weekly version updates),
CodeQL code scanning and private vulnerability reporting are on. - Updated: Go modules, Node 26 for building the web UI.
- README: tests, CodeQL and PayPal badges.
Fixed
- Device login (digest): the realm, nonce and opaque a device sends are quoted
properly in the answer, so a device cannot add header fields of its own (CodeQL). - Backups: a device id
.or..can no longer point outside the backups folder
(CodeQL).