Commit efe9f1d
fix(themes): refuse engine-theme actions on an unidentifiable account
expected_current does not establish account identity. It compares values,
so when ha-mcp's own user and the sidecar's engine user happen to hold the
same theme the comparison passes and get_engine_theme reads, and
set_engine_theme overwrites, the WRONG profile -- leaving the engine
account untouched. My earlier answer that the compare-and-set covered this
was wrong.
An explicitly configured engine URL yields no addon_credential, so the only
fallback is ha-mcp's own credential, which under the dedicated-engine-
account setup this feature recommends is a different Home Assistant user.
Both engine-theme actions now refuse in that case with an error naming the
sidecar situation and pointing at the engine account's own Profile page,
rather than acting on a profile that may not be the engine's.
The restore examples in the tool docstring and beta.md omitted
expected_current, teaching the unguarded form to any agent following them
after a warning. Both now pass the warning's expected_current alongside the
value.
Raised by Codex.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Nm7tyA1nfxNCWFXaR3AxV1 parent f3b8c0b commit efe9f1d
3 files changed
Lines changed: 80 additions & 3 deletions
File tree
- docs
- src/ha_mcp/tools
- tests/src/unit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
190 | 190 | | |
191 | 191 | | |
192 | 192 | | |
193 | | - | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
194 | 196 | | |
195 | 197 | | |
196 | 198 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
53 | 80 | | |
54 | 81 | | |
55 | 82 | | |
| |||
271 | 298 | | |
272 | 299 | | |
273 | 300 | | |
274 | | - | |
275 | | - | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
276 | 306 | | |
277 | 307 | | |
278 | 308 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
630 | 630 | | |
631 | 631 | | |
632 | 632 | | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
| 666 | + | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
0 commit comments