mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 14:25:08 +00:00
Optional web login, off by default: a device that sets no password behaves exactly as before. Set under General > Security; then every page and API route needs a session login or an API token (Authorization: Bearer). Loopback, the Wi-Fi setup flow in AP mode, static files, captive-portal probes and a reduced /api/v3/health stay open. Secrets live in the web_auth section of config_secrets.json and no API returns them. scripts/reset_web_password.py turns login off. Stacked on #674. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -2238,7 +2238,10 @@ def _read_mqtt_bridge_config() -> Dict[str, Any]:
|
||||
name shadows it.
|
||||
"""
|
||||
settings = dict(_MQTT_BRIDGE_DEFAULTS)
|
||||
# Write-only credentials: never in _MQTT_BRIDGE_DEFAULTS, which is what
|
||||
# the GET route echoes back.
|
||||
settings['mqtt_password'] = None
|
||||
settings['ledmatrix_api_token'] = None
|
||||
try:
|
||||
if _MQTT_BRIDGE_CONFIG.is_file():
|
||||
with open(_MQTT_BRIDGE_CONFIG, encoding='utf-8') as handle:
|
||||
@@ -2320,6 +2323,7 @@ from web_interface.blueprints.api_v3 import ( # noqa: E402,F401
|
||||
plugins,
|
||||
starlark,
|
||||
system,
|
||||
web_login,
|
||||
wifi,
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user