Skip to content

v0.9.5

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:46
· 5 commits to main since this release

Two wizards for new Shellys (firmware through the device's own access point, and
"Set up a new Shelly" with profiles), an update arrow, an OpenAPI description of the
API — and two security fixes: the device log needs the login, and the raw RPC
endpoint no longer runs anything it is given.

Added

  • A device with a newer stable firmware shows ↑ after its status (like ↻ for "reboot
    needed"), with the version in the tooltip; a summary chip Updates and a selection
    Firmware update available. The device reports it itself, so it costs no extra request.
    The MCP device list says update_available.

  • The REST API is described in OpenAPI 3.1 at /api/v1/openapi.json (linked on the
    About page): every operation with its parameters, bodies, answers and errors, for
    Postman, Swagger UI or a code generator. A test keeps it equal to the routes.

  • Update firmware through a device's own access point, a wizard with QR codes (Firmware
    page): give the access point's name (or pick the device); the file goes to the phone, a QR code
    joins the phone to the device's access point, another opens 192.168.33.1, and ShellyLanMan waits
    until the device is back and shows its version. It also serves a Shelly ShellyLanMan does not know.
    Where the access point of a Gen2+ device is switched off, the wizard offers to switch it on; for Gen1 it says how to do it in the device's page.

  • Set up a new Shelly: a wizard (button on the Devices page) with profiles (Settings →
    Profiles). A profile says what a new device gets: a name made from a pattern, login, MQTT, time
    server, cloud and the checklist's settings (eco, LED, access point, roaming, automatic firmware
    update), and a reminder of your Wi-Fi's name (its password is never kept). The phone joins the new
    device's own access point (QR code), opens its page (QR code) and you enter your Wi-Fi there; when the
    device is on your network ShellyLanMan shows what the profile would do and, after your go, does it.
    Passwords in a profile are stored encrypted and are never shown again. GET/POST /api/v1/profiles and more.

Changed

  • The raw RPC endpoint behind the scheduler's test method button (POST /api/v1/devices/{id}/rpc)
    no longer runs anything it is given: methods that restart, update, delete, or replace code
    or a settings block ask for confirmation (a dialog, or confirm: true in the API); a
    factory reset, a Wi-Fi reset and the delete-all methods are refused there.

Fixed

  • A device's live log (/ws/log/…) could be opened without the UI password; it is now
    behind the login like the rest.