Files
LEDMatrix/src/core_config_keys.py
T
ChuckandClaude Opus 5.5 e3c85cece6 feat(web): optional web login and API tokens, off by default (stacked on #674) (#683)
Optional web login, off by default: a device that sets no password behaves
exactly as before. Set under General > Security; then every page and API
route needs a session login or an API token (Authorization: Bearer).
Loopback, the Wi-Fi setup flow in AP mode, static files, captive-portal
probes and a reduced /api/v3/health stay open. Secrets live in the web_auth
section of config_secrets.json and no API returns them.
scripts/reset_web_password.py turns login off. Stacked on #674.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 09:09:40 -04:00

57 lines
2.1 KiB
Python

"""Top-level config.json keys that belong to the LEDMatrix core, not to plugins.
config.json mixes two kinds of top-level section: core settings (``display``,
``schedule``, ``auto_update``, ...) and one section per plugin, keyed by plugin
id. Anything that needs to tell them apart -- plugin-state reconciliation above
all -- must use this list, not a private copy of it.
A private copy is what went wrong: #581 added a top-level ``auto_update``
section, reconciliation's own list did not know about it, and every device with
the new setting was told "In config but not installed: auto_update. Reinstall
via the Plugin Store, or remove these entries from config.json" -- advice that
deletes a real core setting.
When you add a top-level core setting, add its key here. The tests in
``test/test_core_config_keys.py`` fail if a top-level key in
``config/config.template.json``, or one written by the general-settings save
endpoint, is missing from this list.
"""
CORE_CONFIG_KEYS = frozenset({
# config/config.template.json
'web_display_autostart',
'auto_update',
'schedule',
'dim_schedule',
'timezone',
'target_fps',
'location',
'display',
'sync',
'plugin_system',
# Older or optional core sections still found in existing config files.
'logging',
'network',
'system',
'vegas_scroll_speed',
'vegas_separator_width',
'vegas_target_fps',
'vegas_buffer_ahead',
'vegas_plugin_order',
'vegas_excluded_plugins',
'vegas_scroll_enabled',
})
#: Top-level keys of ``config_secrets.json`` that belong to the core rather than
#: to a plugin: the GitHub token the Plugin Store reads, the historical
#: ``youtube`` section, and ``web_auth`` (the optional web login's password
#: hash and API-token hashes, web_interface/auth.py) -- which orphan-plugin
#: cleanup would otherwise delete, logging everyone out. Plugin secrets are
#: namespaced by plugin id, so anything deciding whether a secrets section is a
#: plugin's needs this as well as ``CORE_CONFIG_KEYS``.
CORE_SECRETS_KEYS = frozenset({
'github',
'youtube',
'web_auth',
})