diff --git a/birdnet-go-dev/CHANGELOG.md b/birdnet-go-dev/CHANGELOG.md index 15760dbbab..c814a41799 100644 --- a/birdnet-go-dev/CHANGELOG.md +++ b/birdnet-go-dev/CHANGELOG.md @@ -1,3 +1,6 @@ +## 20260929.1 (30-09-2026) +- New `INGRESS_SKIP_AUTH` option (default `false`): when `true`, BirdNET-Go no longer asks for its own login when opened through the Home Assistant sidebar (ingress), since Home Assistant has already signed you in. Direct access on port 8080 still requires the login. +- Security: the ingress web server now only accepts connections from the Home Assistant Supervisor, as Home Assistant requires. ## 20260929 (29-09-2026) - Synced with upstream; merged open PRs (conflicts in #62, #63, #79 resolved) ## 20260920.2 (19-09-2026) diff --git a/birdnet-go-dev/README.md b/birdnet-go-dev/README.md index f00f20920d..4ad3151537 100644 --- a/birdnet-go-dev/README.md +++ b/birdnet-go-dev/README.md @@ -57,6 +57,7 @@ env_vars: [] # extra environment variables to pass to the container TZ: Etc/UTC # timezone, see https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List mqtt_auto_config: false # set true to auto-wire the Home Assistant MQTT addon into config.yaml mariadb_auto_config: false # set true to auto-wire the Home Assistant MariaDB addon into config.yaml (also disables SQLite) +INGRESS_SKIP_AUTH: false # set true to skip the BirdNET-Go login when opened through the Home Assistant sidebar (ingress) ``` - Config.yaml @@ -97,6 +98,14 @@ In practice it only bites when a single audio source has two or more bird models Requires [alexbelgium/birdnet-go#63](https://github.com/alexbelgium/birdnet-go/pull/63). +#### Skip login through ingress + +With `INGRESS_SKIP_AUTH: true`, BirdNET-Go does not show its own login page when you open it from the Home Assistant sidebar (ingress), because Home Assistant has already signed you in. Access on port 8080, and API access, still require the BirdNET-Go login as before. + +**Off by default.** Every Home Assistant user who can open the add-on panel, including non-administrators, then gets full access to BirdNET-Go, settings included. Changing the option requires an add-on restart. + +Requires [alexbelgium/birdnet-go#80](https://github.com/alexbelgium/birdnet-go/pull/80). + ### MQTT and MariaDB auto-configuration (opt-in) If the Home Assistant **MQTT** addon is installed and running and you set `mqtt_auto_config: true` in the addon options, the addon writes the HA Mosquitto credentials directly into BirdNET-Go's `config.yaml` on every startup: `realtime.mqtt.enabled`, `broker`, `username`, and `password` are populated, and the topic defaults to `birdnet`. In addition, it enables BirdNET-Go's **native Home Assistant MQTT auto-discovery** (`realtime.mqtt.homeassistant.enabled`), so the detection sensors show up in Home Assistant automatically — **no manual MQTT sensor YAML required** (the hand-written sensors in [HAINTEGRATION.md](./HAINTEGRATION.md) remain available if you prefer to build your own). Messages are also retained (`realtime.mqtt.retain: true`) so sensor states survive Home Assistant restarts. When the option is `false` (the default), the addon still logs the broker details and reminds you about the option whenever Mosquitto is detected — nothing is written. diff --git a/birdnet-go-dev/config.yaml b/birdnet-go-dev/config.yaml index f03c4a8638..6971f81d13 100644 --- a/birdnet-go-dev/config.yaml +++ b/birdnet-go-dev/config.yaml @@ -92,6 +92,7 @@ options: homeassistant_microphone: false mqtt_auto_config: false mariadb_auto_config: false + INGRESS_SKIP_AUTH: false panel_admin: false panel_icon: mdi:bird ports: @@ -110,6 +111,7 @@ schema: value: str? BIRDSONGS_FOLDER: str? LOG_MAX_SIZE_MB: int(1,1000)? + INGRESS_SKIP_AUTH: bool? LOG_MAX_AGE_DAYS: int(1,365)? TZ: str? cifsdomain: str? @@ -127,5 +129,5 @@ slug: birdnet-go-dev udev: true url: https://github.com/alexbelgium/hassio-addons usb: true -version: "20260929" +version: "20260929.1" video: true diff --git a/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf b/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf index 21fc2c9319..43eff1bdac 100644 --- a/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf +++ b/birdnet-go-dev/rootfs/etc/nginx/servers/ingress.conf @@ -4,6 +4,10 @@ server { include /etc/nginx/includes/proxy_params.conf; location / { + # Only the Supervisor's ingress proxy may use this server. + allow 172.30.32.2; + deny all; + proxy_pass http://localhost:8080/; rewrite ^%%ingress_entry%%/?(.*)$ /$1 break;