Repository navigation
v0.9.5
Two wizards for new Shellys (firmware through the device's own access point, and
"Set up a new Shelly" with profiles), an update arrow, an OpenAPI description of the
API — and two security fixes: the device log needs the login, and the raw RPC
endpoint no longer runs anything it is given.
Added
-
A device with a newer stable firmware shows ↑ after its status (like ↻ for "reboot
needed"), with the version in the tooltip; a summary chip Updates and a selection
Firmware update available. The device reports it itself, so it costs no extra request.
The MCP device list saysupdate_available. -
The REST API is described in OpenAPI 3.1 at
/api/v1/openapi.json(linked on the
About page): every operation with its parameters, bodies, answers and errors, for
Postman, Swagger UI or a code generator. A test keeps it equal to the routes. -
Update firmware through a device's own access point, a wizard with QR codes (Firmware
page): give the access point's name (or pick the device); the file goes to the phone, a QR code
joins the phone to the device's access point, another opens192.168.33.1, and ShellyLanMan waits
until the device is back and shows its version. It also serves a Shelly ShellyLanMan does not know.
Where the access point of a Gen2+ device is switched off, the wizard offers to switch it on; for Gen1 it says how to do it in the device's page. -
Set up a new Shelly: a wizard (button on the Devices page) with profiles (Settings →
Profiles). A profile says what a new device gets: a name made from a pattern, login, MQTT, time
server, cloud and the checklist's settings (eco, LED, access point, roaming, automatic firmware
update), and a reminder of your Wi-Fi's name (its password is never kept). The phone joins the new
device's own access point (QR code), opens its page (QR code) and you enter your Wi-Fi there; when the
device is on your network ShellyLanMan shows what the profile would do and, after your go, does it.
Passwords in a profile are stored encrypted and are never shown again.GET/POST /api/v1/profilesand more.
Changed
- The raw RPC endpoint behind the scheduler's test method button (
POST /api/v1/devices/{id}/rpc)
no longer runs anything it is given: methods that restart, update, delete, or replace code
or a settings block ask for confirmation (a dialog, orconfirm: truein the API); a
factory reset, a Wi-Fi reset and the delete-all methods are refused there.
Fixed
- A device's live log (
/ws/log/…) could be opened without the UI password; it is now
behind the login like the rest.