Repository navigation
Add getting the API key from the device, with a press on its button - #1199
Merged
Merged
Conversation
Devices from 2022 onward can hand out their API key locally: request a challenge, have someone press the button on top of the device while it shows it, and exchange the resolved challenge for the key. No LaMetric account or cloud involved. This uses the web interface of the device, which LaMetric does not document. Tested end to end on an sa8 TIME on firmware 3.2.6. An LM 37X8 TIME does not have it, and now says so. The error helper also understands the error shape of that web interface, so the reason of the device is passed on.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Changes
Devices from 2022 onward can hand out their API key locally, after someone presses the button on top of the device. No LaMetric account or cloud involved. This adds
LaMetricLocalAuthfor that:request_challenge()makes the device show CLICK ME, and returns anAuthChallenge.challenge(challenge_id=...)polls it.resolvedturns true once the button is pressed; the state goes toexpiredwhen the time runs out.api_key(challenge_id=...)exchanges the resolved challenge for a web admin key, and uses that to read the API key from the users of the device. A key generated in the LaMetric app is preferred over the one of the LaMetric account.This matters for Home Assistant: according to the LaMetric docs, a key generated in the app stays on the device and is not synced to the cloud, so the cloud based config flow cannot see it.
This uses the web interface of the device (port 443), which LaMetric does not document. The flow was described in #915; I tested it end to end on a real sa8 TIME on firmware 3.2.6, with a press on the button, and the key it returned is the one the device API accepts. An LM 37X8 TIME on firmware 2.3.9 has no web interface and answers with a 401;
request_challenge()turns that into a clear "does not support" error rather than an authentication error.Two differences from what #915 describes, seen on the real device:
api_key()falls back to that one.{"error": {"message": ...}}instead of{"errors": [...]}.error_message()now understands both, so the reason of the device is passed on, for example "Invalid challenge status in-progress".Nothing is retried: requesting a challenge twice would show it twice on the device. The test fixtures are the answers of the real sa8, with keys and IDs replaced.
Related Issues
Closes #915