diff --git a/custom_components/gree_controller/manifest.json b/custom_components/gree_controller/manifest.json index c588fd9..bdd87d7 100644 --- a/custom_components/gree_controller/manifest.json +++ b/custom_components/gree_controller/manifest.json @@ -1,7 +1,7 @@ { "domain": "gree_controller", "name": "GREE Controller", - "version": "0.14.14", + "version": "0.14.15", "config_flow": true, "integration_type": "hub", "iot_class": "local_polling", diff --git a/gree-controller/CHANGELOG.md b/gree-controller/CHANGELOG.md index b16533f..1e5c41a 100644 --- a/gree-controller/CHANGELOG.md +++ b/gree-controller/CHANGELOG.md @@ -1,5 +1,14 @@ # Changelog +## 0.14.15 + +- Treats TCP `8787` as the fixed internal Home Assistant add-on application/ingress port and validates the Supervisor-reported ingress port at startup. +- Makes the add-on build fail when `run.sh`, `ingress_port` and watchdog port metadata diverge. +- Uses the Home Assistant Supervisor network API to resolve the primary host IPv4 for generated chart-only share links instead of depending on the browser/ingress hostname. +- Adds optional `public_chart_base_url` for reverse proxies, alternate hostnames or non-standard external routing while keeping the public surface limited to generated Custom Chart shares. +- Uses Home Assistant's `[PORT:8787]` watchdog placeholder so Supervisor resolves the effective watchdog port from the add-on port contract. +- Keeps standalone installations fully port-configurable through `GREE_CONTROLLER_BIND`. + ## 0.14.14 - Changes History → Custom Charts links to open a standalone chart-only page instead of the full dashboard. diff --git a/gree-controller/DOCS.md b/gree-controller/DOCS.md index 352cfbb..0dc0bec 100644 --- a/gree-controller/DOCS.md +++ b/gree-controller/DOCS.md @@ -56,6 +56,7 @@ Broadcast zwykle nie przechodzi przez router. Sterowanie unicast może działać | `zone_interval_seconds` | interwał sterowania strefami/termostatem | | `discovery_timeout_ms` | timeout discovery UDP | | `app_token` | token bezpośredniego Web UI/API; w trybie Supervisor pusty = direct access zablokowany | +| `public_chart_base_url` | opcjonalny bazowy URL publicznych linków Custom Chart; puste = automatyczne główne IPv4 hosta HA + `:8787` | | `log_level` | `error`, `warn`, `info`, `debug`, `trace` | ### Home Assistant API @@ -64,7 +65,7 @@ Dodatek korzysta automatycznie z wewnętrznego proxy Home Assistant Core (`http: ### Dostęp, dane i bezpieczeństwo -Usługa słucha na TCP `8787`; ingress Home Assistant przekazuje Web UI na ten port. Gdy wykryty jest `SUPERVISOR_TOKEN`, bezpośredni dashboard/API na `:8787` wymaga `app_token`; przy pustym `app_token` bezpośredni dashboard jest zablokowany. Z sieci bez poświadczeń dostępny jest tylko publiczny widok i endpoint danych pojedynczego Custom Chart (`/charts/custom/`, `/api/public/charts/custom/`). Token udostępnienia jest losowy, jego skrót jest zapisywany w SQLite, a sam URL nie zawiera nazw urządzeń ani listy metryk. Link kopiowany z History → Custom chart omija HA ingress i wskazuje bezpośrednio host/IP dodatku na jego porcie HTTP (domyślnie `8787`). `/api/health` bez tokenu jest akceptowane tylko od peera Supervisora na potrzeby watchdoga; bezpośrednie żądanie sieciowe wymaga `app_token`. Baza jest zapisywana w `/data/gree-controller.db`; konfiguracja używa `backup: cold`, więc dane są objęte backupem dodatku. +Usługa używa stałego wewnętrznego portu TCP `8787`; ingress Home Assistant przekazuje Web UI na ten port. Port nie jest opcją użytkownika w zakładce Network. Przy starcie add-on porównuje port raportowany przez Supervisor z kontraktem `8787` i odmawia startu, jeśli ręcznie zmodyfikowana paczka jest niespójna. Gdy wykryty jest `SUPERVISOR_TOKEN`, bezpośredni dashboard/API na `:8787` wymaga `app_token`; przy pustym `app_token` bezpośredni dashboard jest zablokowany. Z sieci bez poświadczeń dostępny jest tylko publiczny widok i endpoint danych pojedynczego Custom Chart (`/charts/custom/`, `/api/public/charts/custom/`). Token udostępnienia jest losowy, jego skrót jest zapisywany w SQLite, a sam URL nie zawiera nazw urządzeń ani listy metryk. Link kopiowany z History → Custom chart omija HA ingress; domyślnie add-on pobiera główne IPv4 hosta z Supervisor API i tworzy `http://:8787/charts/custom/...`. `public_chart_base_url` pozwala jawnie wskazać reverse proxy, inną nazwę hosta lub alternatywną trasę. `/api/health` bez tokenu jest akceptowane tylko od peera Supervisora na potrzeby watchdoga; bezpośrednie żądanie sieciowe wymaga `app_token`. Baza jest zapisywana w `/data/gree-controller.db`; konfiguracja używa `backup: cold`, więc dane są objęte backupem dodatku. Watchdog sprawdza `/api/health`. Do diagnostyki sieci najpierw sprawdź `ha network info`, poprawność `gree_interface`, broadcast konkretnej podsieci i reguły UDP/firewalla. @@ -121,6 +122,7 @@ Broadcast normally does not cross routers. Unicast control may work through rout | `zone_interval_seconds` | thermostat/zone control interval | | `discovery_timeout_ms` | UDP discovery timeout | | `app_token` | token for direct Web UI/API access; in Supervisor mode empty = direct access disabled | +| `public_chart_base_url` | optional base URL for public Custom Chart links; empty = primary HA host IPv4 + `:8787` automatically | | `log_level` | `error`, `warn`, `info`, `debug`, `trace` | ### Home Assistant API @@ -129,6 +131,6 @@ The add-on automatically uses the internal Home Assistant Core proxy (`http://su ### Access, data and security -The service listens on TCP `8787`; Home Assistant ingress proxies the Web UI to that port. When `SUPERVISOR_TOKEN` is detected, direct dashboard/API access on `:8787` requires `app_token`; with an empty `app_token`, direct dashboard access is disabled. From the network, the only unauthenticated application data is the single public Custom Chart view/data endpoint (`/charts/custom/`, `/api/public/charts/custom/`). The share token is random, only its hash is stored in SQLite, and the URL does not expose device names or metric selectors. Links copied from History → Custom chart bypass HA ingress and point directly to the add-on host/IP on its HTTP port (default `8787`). `/api/health` is accepted without a token only from the Supervisor peer for the add-on watchdog; direct network requests require `app_token`. The database is stored in `/data/gree-controller.db`; `backup: cold` keeps it in the add-on backup. +The service uses fixed internal TCP port `8787`; Home Assistant ingress proxies the Web UI to that port. The port is not a user-facing Network option. On startup the add-on compares the Supervisor-reported ingress port with the `8787` contract and refuses to start if a manually modified package is inconsistent. When `SUPERVISOR_TOKEN` is detected, direct dashboard/API access on `:8787` requires `app_token`; with an empty `app_token`, direct dashboard access is disabled. From the network, the only unauthenticated application data is the single public Custom Chart view/data endpoint (`/charts/custom/`, `/api/public/charts/custom/`). The share token is random, only its hash is stored in SQLite, and the URL does not expose device names or metric selectors. Links copied from History → Custom chart bypass HA ingress; by default the add-on obtains the primary host IPv4 from the Supervisor API and builds `http://:8787/charts/custom/...`. `public_chart_base_url` can explicitly select a reverse proxy, alternate hostname or routing path. `/api/health` is accepted without a token only from the Supervisor peer for the add-on watchdog; direct network requests require `app_token`. The database is stored in `/data/gree-controller.db`; `backup: cold` keeps it in the add-on backup. The watchdog checks `/api/health`. For network troubleshooting, verify `ha network info`, `gree_interface`, the selected subnet broadcast, and UDP/firewall rules first. diff --git a/gree-controller/config.yaml b/gree-controller/config.yaml index cb3d855..5488a00 100644 --- a/gree-controller/config.yaml +++ b/gree-controller/config.yaml @@ -1,5 +1,5 @@ name: "GREE Controller" -version: "0.14.14" +version: "0.14.15" slug: "gree_controller" description: "Local GREE HVAC controller with Web UI and Home Assistant integration" url: "https://git.linuxiarz.pl/gru/gree-controller-ha-addon/" @@ -12,13 +12,14 @@ boot: auto init: false host_network: true homeassistant_api: true +hassio_api: true ingress: true ingress_port: 8787 ingress_stream: true panel_icon: mdi:air-conditioner panel_title: GREE Controller panel_admin: true -watchdog: "http://[HOST]:8787/api/health" +watchdog: "http://[HOST]:[PORT:8787]/api/health" backup: cold options: gree_interface: "" @@ -29,6 +30,7 @@ options: zone_interval_seconds: 5 discovery_timeout_ms: 3000 app_token: "" + public_chart_base_url: "" log_level: info schema: gree_interface: str @@ -39,4 +41,5 @@ schema: zone_interval_seconds: "int(2,3600)" discovery_timeout_ms: "int(500,30000)" app_token: password + public_chart_base_url: str log_level: "list(error|warn|info|debug|trace)" diff --git a/gree-controller/translations/en.yaml b/gree-controller/translations/en.yaml index 37c0105..29a170f 100644 --- a/gree-controller/translations/en.yaml +++ b/gree-controller/translations/en.yaml @@ -23,6 +23,9 @@ configuration: app_token: name: Application token description: Token required for direct dashboard/API access on port 8787. With SUPERVISOR_TOKEN active, an empty token disables direct access; only generated Custom Chart share links remain public. + public_chart_base_url: + name: Public chart base URL + description: Optional override for generated Custom Chart links, for example http://192.168.1.20:8787 or a reverse-proxy URL. Leave empty to use the primary Home Assistant host IPv4 and the fixed add-on port 8787 automatically. log_level: name: Log level description: Controller log verbosity. diff --git a/gree-controller/translations/pl.yaml b/gree-controller/translations/pl.yaml index 5e972cd..a067437 100644 --- a/gree-controller/translations/pl.yaml +++ b/gree-controller/translations/pl.yaml @@ -23,6 +23,9 @@ configuration: app_token: name: Token aplikacji description: Token wymagany do bezpośredniego dostępu do dashboardu/API na porcie 8787. Przy aktywnym SUPERVISOR_TOKEN pusty token blokuje direct access; publiczne pozostają wyłącznie wygenerowane linki Custom Chart. + public_chart_base_url: + name: Bazowy URL publicznych wykresów + description: Opcjonalne nadpisanie adresu generowanych linków Custom Chart, np. http://192.168.1.20:8787 albo adres reverse proxy. Pozostaw puste, aby automatycznie użyć głównego IPv4 hosta Home Assistant i stałego portu add-onu 8787. log_level: name: Poziom logowania description: Szczegółowość logów kontrolera.