|
|
|
@@ -1,15 +1,15 @@
|
|
|
|
|
# Installation og drift
|
|
|
|
|
# Installation and operation
|
|
|
|
|
|
|
|
|
|
1. Gå til **Indstillinger → Apps → Installér app → ⋮ → Repositorier**, og tilføj
|
|
|
|
|
præcis
|
|
|
|
|
1. Go to **Settings → Apps → Install app → ⋮ → Repositories** and add this
|
|
|
|
|
exact URL:
|
|
|
|
|
`https://git.radixadm.dk/dennis/homeassistant-stelloauth-addon.git`.
|
|
|
|
|
|
|
|
|
|
2. Installér **Stelloauth**, aktivér **Start ved opstart** og **Watchdog**, og
|
|
|
|
|
start derefter appen. Installationen bygger et lokalt image fra kilde til
|
|
|
|
|
den valgte `amd64`- eller `aarch64`-arkitektur. Repositoryet publicerer ikke
|
|
|
|
|
et prebuilt image.
|
|
|
|
|
2. Install **Stelloauth**, enable **Start on boot** and **Watchdog**, then start
|
|
|
|
|
the app. Home Assistant builds a local image from source for the selected
|
|
|
|
|
`amd64` or `aarch64` architecture. This repository does not publish a
|
|
|
|
|
prebuilt image.
|
|
|
|
|
|
|
|
|
|
3. Vent, til loggen i denne rækkefølge viser de fem faste readiness-beskeder:
|
|
|
|
|
3. Wait for the app log to show these five readiness messages in order:
|
|
|
|
|
|
|
|
|
|
```text
|
|
|
|
|
Cleaning CloakBrowser profiles
|
|
|
|
@@ -19,72 +19,75 @@
|
|
|
|
|
Stelloauth listening on 0.0.0.0:8080
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
4. Behold host-porten deaktiveret i normal drift. Ved kortvarig fejlfinding kan
|
|
|
|
|
`8080/tcp` tilknyttes host-port `8080`. Kontrollér derefter
|
|
|
|
|
`http://192.168.1.20:8080/` eller worker-endpointet
|
|
|
|
|
`http://192.168.1.20:8080/worker`, og **deaktivér porttilknytningen igen**,
|
|
|
|
|
når kontrollen er færdig. Worker-endpointet modtager MyOpel-oplysninger og
|
|
|
|
|
har ingen egen autentificering.
|
|
|
|
|
4. Keep the host port disabled during normal operation. For brief
|
|
|
|
|
troubleshooting, map `8080/tcp` to host port `8080`. Then check
|
|
|
|
|
`http://192.168.1.20:8080/` or the worker endpoint at
|
|
|
|
|
`http://192.168.1.20:8080/worker`. **Disable the port mapping again** when
|
|
|
|
|
you finish. The worker endpoint receives MyOpel details and has no separate
|
|
|
|
|
authentication.
|
|
|
|
|
|
|
|
|
|
5. Åbn konfigurationen af **Stellantis Vehicles**. Angiv præcis
|
|
|
|
|
`http://0031621f-stelloauth:8080/worker` som **Login service URL**.
|
|
|
|
|
Integrationen tilføjer ikke `/worker`; hele stien skal derfor stå i feltet.
|
|
|
|
|
5. Open the **Stellantis Vehicles** integration's configuration and set
|
|
|
|
|
**Login service URL** to exactly
|
|
|
|
|
`http://0031621f-stelloauth:8080/worker`. The integration does not append
|
|
|
|
|
`/worker`, so include the full path.
|
|
|
|
|
|
|
|
|
|
6. Vælg **Brand: Opel** og **Country: DK**, og gennemfør derefter integrationens
|
|
|
|
|
OAuth-opsætning med dine MyOpel-oplysninger.
|
|
|
|
|
6. Select **Brand: Opel** and **Country: DK**, then complete the integration's
|
|
|
|
|
OAuth setup with your MyOpel details.
|
|
|
|
|
|
|
|
|
|
7. Appens tre muligheder er:
|
|
|
|
|
7. The app provides three options:
|
|
|
|
|
|
|
|
|
|
- `queue_timeout`: hvor længe et loginforsøg må vente på den ene session.
|
|
|
|
|
- `rate_limit_count`: højeste antal loginforsøg i hver periode.
|
|
|
|
|
- `rate_limit_duration`: længden af rate limit-perioden.
|
|
|
|
|
- `queue_timeout`: how long a login attempt may wait for the single session.
|
|
|
|
|
- `rate_limit_count`: the maximum number of login attempts allowed in each
|
|
|
|
|
period.
|
|
|
|
|
- `rate_limit_duration`: the length of the login rate-limit period.
|
|
|
|
|
|
|
|
|
|
`CLOAK_MAX_SESSIONS` er fastlåst til én session, fordi CloakBrowsers gratis
|
|
|
|
|
niveau tillader ét samtidigt login. Samtidige forsøg bliver derfor køet.
|
|
|
|
|
`CLOAK_MAX_SESSIONS` is fixed at one because CloakBrowser's free tier allows
|
|
|
|
|
one concurrent login. Additional attempts wait in the queue.
|
|
|
|
|
|
|
|
|
|
8. Hvert OAuth-forsøg får en midlertidig profil under `/tmp/cloakserve`.
|
|
|
|
|
CloakBrowser rydder inaktive browserprocesser efter 30 sekunder, og
|
|
|
|
|
process manageren rydder gamle profiler ved opstart. Credentials, cookies,
|
|
|
|
|
tokens og OAuth-koder gemmes ikke i `/data`. CDP lytter kun på loopback
|
|
|
|
|
`127.0.0.1:9222`, og logs bruger faste, redigerede hændelser uden email,
|
|
|
|
|
passwords, URLs, koder eller tokens.
|
|
|
|
|
8. Each OAuth attempt gets a temporary profile under `/tmp/cloakserve`.
|
|
|
|
|
CloakBrowser removes inactive browser processes after 30 seconds, and the
|
|
|
|
|
process manager removes old profiles at startup. Credentials, cookies,
|
|
|
|
|
tokens, and OAuth codes are not stored in `/data`. CDP listens only on the
|
|
|
|
|
loopback address `127.0.0.1:9222`. Logs use fixed, redacted messages and do
|
|
|
|
|
not include email addresses, passwords, URLs, codes, or tokens.
|
|
|
|
|
|
|
|
|
|
9. De målte resultater fra den reelle `linux/amd64`-kørsel under Rosetta var:
|
|
|
|
|
9. Measurements from a real `linux/amd64` run under Rosetta:
|
|
|
|
|
|
|
|
|
|
- Image: 2,571,693,650 bytes (2.571 GB decimal / 2452.56 MiB).
|
|
|
|
|
- Dokumenteret Task 4-måling: 121,5 MiB.
|
|
|
|
|
- Stop: cirka 9.3 sekunder.
|
|
|
|
|
- `amd64` runtime bestod under Rosetta; `aarch64` build bestod.
|
|
|
|
|
- Mål-HAOS havde ved inspektionen approximately 4 GB free. Den knappe
|
|
|
|
|
plads sammenholdt med image- og build-lag kan forhindre installationen;
|
|
|
|
|
frigør plads først. Der er ikke verificeret en vellykket HAOS-installation.
|
|
|
|
|
- Image: 2,571,693,650 bytes (2.571 GB decimal / 2,452.56 MiB).
|
|
|
|
|
- Documented Task 4 measurement: 121.5 MiB.
|
|
|
|
|
- Stop time: about 9.3 seconds.
|
|
|
|
|
- The `amd64` runtime passed under Rosetta; the `aarch64` build passed.
|
|
|
|
|
|
|
|
|
|
Der er ikke gennemført et live MyOpel-login.
|
|
|
|
|
Login-flow RAM: not measured without real MyOpel credentials.
|
|
|
|
|
A successful live MyOpel login has not been verified. Login-flow memory
|
|
|
|
|
usage was not measured without real MyOpel credentials.
|
|
|
|
|
|
|
|
|
|
10. Fejlfinding og fjernelse:
|
|
|
|
|
10. Troubleshooting and removal:
|
|
|
|
|
|
|
|
|
|
- Mangler en readiness-besked, så se efter timeout: CloakBrowser har 60
|
|
|
|
|
sekunder og Stelloauth 30 sekunder. Ret årsagen og genstart appen.
|
|
|
|
|
- Et ugyldigt eller ikke-tilladt authorize-URL giver HTTP `400`.
|
|
|
|
|
- For mange loginforsøg giver HTTP `429`; vent den konfigurerede periode.
|
|
|
|
|
- Hvis repository-URL eller hostname ændres, ændres Supervisor-repository-ID
|
|
|
|
|
og dermed `0031621f-stelloauth`. Beregn og brug den nye interne URL.
|
|
|
|
|
- Ved disk pressure: kontrollér fri plads og fjern unødvendige images eller
|
|
|
|
|
backups via de normale Supervisor-funktioner før et nyt build.
|
|
|
|
|
- Hvis den interne URL ikke kan nås, brug kun den midlertidige portkontrol
|
|
|
|
|
fra trin 4 og deaktivér porttilknytningen bagefter.
|
|
|
|
|
- Fjernelse sker i **Indstillinger → Apps → Stelloauth → Afinstallér**.
|
|
|
|
|
Supervisor stopper containeren og fjerner appens lokale data. Fjern også
|
|
|
|
|
repositoryet via **Indstillinger → Apps → Installér app → ⋮ →
|
|
|
|
|
Repositorier**, hvis det ikke længere bruges.
|
|
|
|
|
- If a readiness message is missing, check for a timeout. CloakBrowser has
|
|
|
|
|
60 seconds and Stelloauth has 30 seconds. Fix the cause, then restart the
|
|
|
|
|
app.
|
|
|
|
|
- An invalid or disallowed authorize URL returns HTTP `400`.
|
|
|
|
|
- Too many login attempts return HTTP `429`; wait for the configured
|
|
|
|
|
rate-limit period.
|
|
|
|
|
- If the repository URL or hostname changes, the Supervisor repository ID
|
|
|
|
|
and `0031621f-stelloauth` hostname also change. Calculate and use the new
|
|
|
|
|
internal URL.
|
|
|
|
|
- If disk space is low, check available space and remove unneeded images or
|
|
|
|
|
backups through Supervisor before building again.
|
|
|
|
|
- If the internal URL cannot be reached, use the temporary port check from
|
|
|
|
|
step 4, then disable the port mapping again.
|
|
|
|
|
- To remove the app, go to **Settings → Apps → Stelloauth → Uninstall**.
|
|
|
|
|
Supervisor stops the container and removes the app's local data. If you
|
|
|
|
|
no longer need the repository, remove it from **Settings → Apps → Install
|
|
|
|
|
app → ⋮ → Repositories** as well.
|
|
|
|
|
|
|
|
|
|
## Kilder og licenser
|
|
|
|
|
## Sources and licenses
|
|
|
|
|
|
|
|
|
|
App-version `0.1.0` bygger Stelloauth `v0.6.0` fra commit
|
|
|
|
|
`367d4f8c02a3b072c59142c49dffc129edc8548b` og bruger det officielle
|
|
|
|
|
CloakBrowser `0.5.10`-image ved OCI index digest
|
|
|
|
|
App version `0.1.0` builds Stelloauth `v0.6.0` from commit
|
|
|
|
|
`367d4f8c02a3b072c59142c49dffc129edc8548b` and uses the official CloakBrowser
|
|
|
|
|
`0.5.10` image at OCI index digest
|
|
|
|
|
`sha256:2ed5b2d047cbdde22cde7ef1a796526c716aadaa5bccbe1db5ade49282b64a76`.
|
|
|
|
|
Repositoryets egne filer og patches er MIT-licenserede. CloakBrowsers
|
|
|
|
|
proprietære binær er fortsat under den separate **CloakBrowser Binary License**;
|
|
|
|
|
den er ikke MIT-licenseret eller redistribueret af dette repository.
|
|
|
|
|
The repository's original files and patches are licensed under the MIT License.
|
|
|
|
|
The proprietary CloakBrowser binary remains subject to the separate
|
|
|
|
|
**CloakBrowser Binary License**. It is not licensed under MIT or redistributed
|
|
|
|
|
by this repository.
|
|
|
|
|