Commit e7d6c35
fix(themes): never treat an unproven credential as the engine's account
Two Codex P1s, both about credential-to-engine identity. The second
undermines the refusal added in efe9f1d, so that fix was incomplete.
An explicit engine URL is never provably paired with a credential. On HA
OS, _addon_credential_best_effort() hands back the DISCOVERED Puppet app's
credential without checking it identifies the engine that URL points at, so
a sidecar URL plus a running app produced a credential for the wrong
account -- and my earlier check, which only tested for a MISSING
addon_credential, passed it straight through. The engine-theme actions now
refuse whenever an engine URL is set explicitly, regardless of what
discovery turned up. That pairing was documented as a safe no-op, and it
was, while the guard only wrote back its own snapshot; it stopped being one
when these actions began reading and writing a profile on request.
The capture guard has the same uncertainty but must not simply go dark:
its client-credential fallback is what protects the common single-user
Docker setup, where ha-mcp and the engine really are the same user. It
stays active and now tracks whether its credential is provably the
engine's. When it is not, the report says so and tells the agent to verify
before restoring, rather than implying the engine's account was the one
observed.
Also fixes an import in the new resolver guard that reached beyond the
package (...config from src/ha_mcp/tools/), which turned the refusal into
an INTERNAL_ERROR. The identity tests caught it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Nm7tyA1nfxNCWFXaR3AxV1 parent 9e2350b commit e7d6c35
3 files changed
Lines changed: 68 additions & 5 deletions
File tree
- src/ha_mcp
- dashboard_screenshot
- tools
- tests/src/unit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
194 | 198 | | |
195 | 199 | | |
196 | 200 | | |
| |||
200 | 204 | | |
201 | 205 | | |
202 | 206 | | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
203 | 212 | | |
204 | 213 | | |
205 | 214 | | |
206 | 215 | | |
207 | 216 | | |
208 | | - | |
| 217 | + | |
209 | 218 | | |
210 | 219 | | |
211 | 220 | | |
| |||
353 | 362 | | |
354 | 363 | | |
355 | 364 | | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
356 | 373 | | |
357 | 374 | | |
358 | 375 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
| 49 | + | |
49 | 50 | | |
50 | 51 | | |
51 | 52 | | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
52 | 56 | | |
53 | | - | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
54 | 65 | | |
55 | 66 | | |
56 | 67 | | |
| |||
65 | 76 | | |
66 | 77 | | |
67 | 78 | | |
68 | | - | |
69 | | - | |
70 | | - | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
71 | 83 | | |
72 | 84 | | |
73 | 85 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
755 | 755 | | |
756 | 756 | | |
757 | 757 | | |
| 758 | + | |
| 759 | + | |
| 760 | + | |
| 761 | + | |
| 762 | + | |
| 763 | + | |
| 764 | + | |
| 765 | + | |
| 766 | + | |
| 767 | + | |
| 768 | + | |
| 769 | + | |
| 770 | + | |
| 771 | + | |
| 772 | + | |
| 773 | + | |
| 774 | + | |
| 775 | + | |
| 776 | + | |
| 777 | + | |
| 778 | + | |
| 779 | + | |
| 780 | + | |
| 781 | + | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
| 787 | + | |
| 788 | + | |
| 789 | + | |
| 790 | + | |
| 791 | + | |
0 commit comments