mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-10-08 01:01:35 +02:00
Compare commits
18 Commits
ai-fix/fil
...
2fc1ea84be
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2fc1ea84be | ||
|
|
48ac78c59d | ||
|
|
9302fc9a51 | ||
|
|
29ce08c162 | ||
|
|
bb1d0c6b66 | ||
|
|
1b1436b61a | ||
|
|
08fe5e33be | ||
|
|
dac8efba60 | ||
|
|
87f69ce79b | ||
|
|
84dfd1b996 | ||
|
|
2b6e07040f | ||
|
|
680386525f | ||
|
|
20a2f997c9 | ||
|
|
15de5e3a39 | ||
|
|
232e697301 | ||
|
|
53ad396e5b | ||
|
|
bcdd972c2f | ||
|
|
65233d1291 |
2
.github/workflows/daily_README.yaml
vendored
2
.github/workflows/daily_README.yaml
vendored
@@ -228,7 +228,7 @@ jobs:
|
||||
echo "... done"
|
||||
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "GitHub bot : README updated"
|
||||
default_author: github_actions
|
||||
|
||||
2
.github/workflows/daily_ai_fix.yaml
vendored
2
.github/workflows/daily_ai_fix.yaml
vendored
@@ -125,7 +125,7 @@ jobs:
|
||||
|
||||
- name: Analyse and fix
|
||||
if: steps.batch.outputs.count != '0'
|
||||
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
|
||||
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
|
||||
with:
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# Skip the OIDC -> Claude App token exchange. The scheduled path
|
||||
|
||||
2
.github/workflows/helper_stats_graphs.yaml
vendored
2
.github/workflows/helper_stats_graphs.yaml
vendored
@@ -237,7 +237,7 @@ jobs:
|
||||
# Get stars evolution
|
||||
wget -S -O .github/starsevol.svg "https://api.star-history.com/svg?repos=alexbelgium/hassio-addons&type=Date" || true
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "GitHub bot : graphs updated"
|
||||
default_author: github_actions
|
||||
|
||||
2
.github/workflows/on_claude_mention.yml
vendored
2
.github/workflows/on_claude_mention.yml
vendored
@@ -64,7 +64,7 @@ jobs:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Run Claude Code
|
||||
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
|
||||
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
|
||||
with:
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# AI_PR_TOKEN, not GITHUB_TOKEN, so a PR Claude opens triggers CI.
|
||||
|
||||
2
.github/workflows/on_issue_approved.yaml
vendored
2
.github/workflows/on_issue_approved.yaml
vendored
@@ -135,7 +135,7 @@ jobs:
|
||||
|
||||
- name: Execute the plan
|
||||
if: steps.bundle.outputs.has_plan == 'true'
|
||||
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
|
||||
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
|
||||
with:
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# Skip the OIDC -> Claude App token exchange, which 401s whenever
|
||||
|
||||
2
.github/workflows/on_issues.yml
vendored
2
.github/workflows/on_issues.yml
vendored
@@ -59,7 +59,7 @@ jobs:
|
||||
# Remove issues list
|
||||
rm issueslist
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "Github bot : issues linked to readme"
|
||||
default_author: github_actions
|
||||
|
||||
2
.github/workflows/on_issues_ai_triage.yaml
vendored
2
.github/workflows/on_issues_ai_triage.yaml
vendored
@@ -166,7 +166,7 @@ jobs:
|
||||
id: classify
|
||||
if: github.event_name != 'issue_comment' || steps.claim.outputs.go == 'true'
|
||||
continue-on-error: true
|
||||
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
|
||||
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
|
||||
with:
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# Without this the action falls back to the OIDC -> Claude App token
|
||||
|
||||
2
.github/workflows/on_pr_coderabbit.yml
vendored
2
.github/workflows/on_pr_coderabbit.yml
vendored
@@ -79,7 +79,7 @@ jobs:
|
||||
|
||||
- name: Address CodeRabbit comments
|
||||
if: steps.claim.outputs.go == 'true'
|
||||
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
|
||||
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
|
||||
with:
|
||||
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||
# Skip the OIDC -> Claude App token exchange, which 401s whenever
|
||||
|
||||
4
.github/workflows/onpush_builder.yaml
vendored
4
.github/workflows/onpush_builder.yaml
vendored
@@ -95,7 +95,7 @@ jobs:
|
||||
- name: Commit sanitize changes
|
||||
id: sanitize_commit
|
||||
if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/master' }}
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
commit: -u
|
||||
message: "GitHub bot: sanitize (spaces + LF endings) & chmod [nobuild]"
|
||||
@@ -410,7 +410,7 @@ jobs:
|
||||
done
|
||||
|
||||
- name: Commit changelog changes
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
commit: -u
|
||||
message: "GitHub bot: changelog [nobuild]"
|
||||
|
||||
4
.github/workflows/weekly_crlftolf.yaml
vendored
4
.github/workflows/weekly_crlftolf.yaml
vendored
@@ -18,7 +18,7 @@ jobs:
|
||||
uses: erclu/check-crlf@v1
|
||||
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "Github bot : CRLF corrected"
|
||||
default_author: github_actions
|
||||
@@ -50,7 +50,7 @@ jobs:
|
||||
dos2unix -k "$f"
|
||||
done
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "Github bot : CRLF corrected"
|
||||
default_author: github_actions
|
||||
|
||||
2
.github/workflows/weekly_reduceimagesize.yml
vendored
2
.github/workflows/weekly_reduceimagesize.yml
vendored
@@ -31,7 +31,7 @@ jobs:
|
||||
|
||||
- name: Commit if needed
|
||||
if: steps.calibre.outputs.markdown != ''
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
message: "Github bot : image compressed"
|
||||
default_author: github_actions
|
||||
|
||||
2
.github/workflows/weekly_stats.yaml
vendored
2
.github/workflows/weekly_stats.yaml
vendored
@@ -109,7 +109,7 @@ jobs:
|
||||
#TOTAL3="$(awk '{SUM+=$2}END{print SUM}' Stats)"
|
||||
|
||||
- name: Commit if needed
|
||||
uses: EndBug/add-and-commit@v10
|
||||
uses: EndBug/add-and-commit@v11.0.0
|
||||
with:
|
||||
default_author: github_actions
|
||||
message : "Github bot : stats updated"
|
||||
|
||||
@@ -1,4 +1,25 @@
|
||||
## 07308545.1 (17-08-2026)
|
||||
- Minor bugs fixed
|
||||
|
||||
## 07308543.1 (17-08-2026)
|
||||
- Fix the "For your security, sign in again" prompt recurring on every restart again. The v1.37
|
||||
`safeStorage` patch (`86-claude_safestorage.sh` / `claude-safestorage-patch.js`) only knew how
|
||||
to inject its opt-in after a leading `"use strict"` directive in the app's main bundle, and
|
||||
refused to patch anything else. Confirmed live on the running add-on (Claude Desktop
|
||||
1.30096.1): the shipped main bundle (`.vite/build/index.pre.js`) no longer opens with a
|
||||
`"use strict"` directive at all — it now opens directly with a bare IIFE — so the patcher has
|
||||
been silently refusing to patch on every boot, `safeStorage.isEncryptionAvailable()` stayed
|
||||
`false`, and the app's own log kept showing `Encryption not available, returning empty env
|
||||
vars` exactly as before v1.37. `applyPatch()` now falls back to inserting the opt-in as the
|
||||
bundle's first real statement when no directive is present, skipping past any leading BOM,
|
||||
hashbang, or banner comment first so a directive hidden behind a comment is still found and
|
||||
protected rather than pushed out of position zero. Verified by copying the live production
|
||||
`app.asar` and running the patcher against it directly: the previously-refused bundle now
|
||||
patches successfully, the marker lands correctly, a second run reports "Already patched", and
|
||||
targeted unit tests cover the bare-IIFE, comment-hidden-directive, hashbang, and
|
||||
unterminated-comment cases.
|
||||
- One-time step after upgrading, same as v1.37: the previously-stored session is already stale,
|
||||
so complete one sign-in from a computer; it then persists across restarts.
|
||||
## 07308545 (2026-08-15)
|
||||
- Update to latest version from aaddrick/claude-desktop-debian (changelog : https://github.com/aaddrick/claude-desktop-debian/releases)
|
||||
- Upstream tag : v3.2.2+claude1.30096.1
|
||||
|
||||
@@ -13,8 +13,10 @@ streamed desktop.
|
||||
offline until a fresh sign-in was done from a computer). v1.35 switched to
|
||||
`--password-store=basic` plus a cont-init script that re-syncs the persistent openbox
|
||||
`autostart` from the image on every boot — **but that flag alone does nothing**, and the bug
|
||||
survived it untouched. Actually fixed in v1.37, which adds the application-side opt-in the
|
||||
`basic` backend requires; see "Why v1.35 did not work" below.
|
||||
survived it untouched. v1.37 added the application-side opt-in the `basic` backend requires;
|
||||
see "Why v1.35 did not work" below. That patcher then regressed silently when upstream's
|
||||
bundle output changed shape — fixed again in 07308543.1; see "Why v1.37 stopped working"
|
||||
below.
|
||||
- **Planned only:** Problem A (in-desktop browser for OAuth) is intentionally not implemented.
|
||||
The image ships no browser; complete the login with the user-side workaround below.
|
||||
|
||||
@@ -170,10 +172,40 @@ The third row is the one that matters: it is the restart survival this add-on ne
|
||||
reaches upgrades, not just fresh installs.
|
||||
4. `gnome-keyring` stays out of the Dockerfile.
|
||||
|
||||
### Why v1.37 stopped working
|
||||
|
||||
`claude-safestorage-patch.js` only knew how to inject its opt-in *after* a leading
|
||||
`"use strict"` directive in the app's main bundle, and refused to patch (leaving the app
|
||||
unpatched and the session un-persisted) if that directive wasn't there. Confirmed live on the
|
||||
running add-on: Claude Desktop 1.30096.1's main bundle (`.vite/build/index.pre.js`) no longer
|
||||
opens with a `"use strict"` directive — it now opens directly with a bare IIFE
|
||||
(`(function(){try{var e=typeof window...`). Upstream's build output changed shape at some point
|
||||
after v1.37 shipped, the patcher's one injection point stopped existing, and it had been
|
||||
silently refusing to patch on every boot since — the app's `main.log` kept showing exactly the
|
||||
same `Encryption not available, returning empty env vars` warning documented above, and the
|
||||
session went back to not surviving restarts.
|
||||
|
||||
`applyPatch()` now falls back to inserting the opt-in as the bundle's first real statement when
|
||||
no `"use strict"` directive is found, rather than refusing outright. It skips past any leading
|
||||
BOM, hashbang, or banner comment first (`skipPrologue()`), so a directive hidden behind a
|
||||
comment is still found and protected instead of being pushed out of the first-statement
|
||||
position by a naive prepend — Vite/esbuild banners commonly put a license comment ahead of the
|
||||
directive. A bundle with no directive at all has nothing to protect, so prepending the opt-in
|
||||
there is unconditionally safe: the injected code is a complete `try{}catch(e){}` statement, and
|
||||
a statement can never merge with what follows it via ASI the way a bare expression could.
|
||||
|
||||
Verified by copying the live production `app.asar` and running the patcher against it directly
|
||||
(outside the container's boot sequence): the previously-refused bundle now patches
|
||||
successfully, the marker lands at the front of the main entry, a second run correctly reports
|
||||
"Already patched" (idempotent), and unit tests cover the bare-IIFE, comment-hidden-directive,
|
||||
hashbang, and unterminated-comment cases.
|
||||
|
||||
### One-time step after upgrading
|
||||
The previously-stored session is already stale. Complete **one** sign-in from a computer
|
||||
(mobile still can't finish the OAuth flow itself, per Problem A) — the session then persists
|
||||
normally and dispatch stays online regardless of which device connects first afterward.
|
||||
normally and dispatch stays online regardless of which device connects first afterward. This
|
||||
applies again after the 07308543.1 fix above, since the affected sessions were never persisted
|
||||
in the first place.
|
||||
|
||||
---
|
||||
|
||||
@@ -185,7 +217,10 @@ normally and dispatch stays online regardless of which device connects first aft
|
||||
- `claude_desktop/rootfs/etc/cont-init.d/86-claude_safestorage.sh` and
|
||||
`claude_desktop/rootfs/usr/local/bin/claude-safestorage-patch.js` — new in v1.37; the
|
||||
app-side `safeStorage` opt-in that makes `--password-store=basic` actually take effect.
|
||||
`claude-safestorage-patch.js` updated again in 07308543.1 to also patch bundles with no
|
||||
leading `"use strict"` directive, and to look past leading comments/hashbang when deciding
|
||||
whether one is present.
|
||||
- `claude_desktop/Dockerfile` — corrected stale comment (gnome-keyring is not installed).
|
||||
- `claude_desktop/CHANGELOG.md` / `config.yaml` — v1.35, then v1.37.
|
||||
- `claude_desktop/CHANGELOG.md` / `config.yaml` — v1.35, then v1.37, then 07308543.1.
|
||||
|
||||
Problem A (in-desktop browser for OAuth) remains planned-only; not touched by this change.
|
||||
|
||||
@@ -136,5 +136,5 @@ schema:
|
||||
slug: claude_desktop
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons
|
||||
version: "07308545"
|
||||
version: "07308545.1"
|
||||
video: true
|
||||
|
||||
@@ -128,24 +128,98 @@ function integrityOf(buf, blockSize) {
|
||||
return { algorithm: 'SHA256', hash: sha256(buf), blockSize, blocks };
|
||||
}
|
||||
|
||||
/* Insert the opt-in after the bundle's leading "use strict" directive. It must go *after* it: a
|
||||
* directive prologue only takes effect as the very first statement, so prepending would silently
|
||||
* drop the whole main process out of strict mode.
|
||||
// Any of the four ECMAScript LineTerminator code points — not just "\n". A //-comment or an ASI
|
||||
// boundary ends at the first of these, and using a bare "\n" search for that would let a CR- or
|
||||
// U+2028/U+2029-terminated line swallow real code as "still the comment/still on this line" and
|
||||
// misplace the insertion point deep inside the bundle instead of before it.
|
||||
const LINE_TERMINATOR = /[\n\r\u2028\u2029]/;
|
||||
|
||||
/* Skip a leading BOM and hashbang line. Only meaningful at byte 0 — called once, before any
|
||||
* directive scanning. */
|
||||
function skipBomAndHashbang(source) {
|
||||
let i = source.charCodeAt(0) === 0xfeff ? 1 : 0; // BOM
|
||||
if (source.startsWith('#!', i)) {
|
||||
const m = LINE_TERMINATOR.exec(source.slice(i));
|
||||
i += m ? m.index + 1 : source.length - i;
|
||||
}
|
||||
return i;
|
||||
}
|
||||
|
||||
/* Skip whitespace and comments starting at i. Returns the next index, or -1 for an unterminated
|
||||
* block comment (caller refuses rather than guesses). */
|
||||
function skipWhitespaceAndComments(source, i) {
|
||||
for (;;) {
|
||||
const rest = source.slice(i);
|
||||
const ws = /^\s+/.exec(rest);
|
||||
if (ws) {
|
||||
i += ws[0].length;
|
||||
continue;
|
||||
}
|
||||
if (rest.startsWith('//')) {
|
||||
const m = LINE_TERMINATOR.exec(rest);
|
||||
i += m ? m.index + 1 : rest.length;
|
||||
continue;
|
||||
}
|
||||
if (rest.startsWith('/*')) {
|
||||
const end = rest.indexOf('*/');
|
||||
if (end === -1) return -1;
|
||||
i += end + 2;
|
||||
continue;
|
||||
}
|
||||
return i;
|
||||
}
|
||||
}
|
||||
|
||||
// A single-line string literal: no raw line terminator in its content (a real one would need an
|
||||
// escaped line continuation, which this deliberately doesn't special-case — failing to match
|
||||
// just means the prologue scan below stops there, which is always safe, see applyPatch).
|
||||
const STRING_LITERAL = /^(['"])(?:\\.|(?!\1)[^\\\n\r\u2028\u2029])*\1/;
|
||||
|
||||
/* Scan the bundle's full leading directive prologue: every consecutive ExpressionStatement made
|
||||
* of nothing but a string literal, per how ECMAScript directives actually work. A directive
|
||||
* prologue can hold more than one entry, and "use strict" only has to appear *somewhere* in it,
|
||||
* not first — so this treats every leading directive as needing protection, not just one
|
||||
* specifically named "use strict". Returns the index right after the full prologue (which is
|
||||
* also correct as "no prologue, insert here" when there wasn't one), or -1 when a leading string
|
||||
* literal isn't cleanly terminated as its own statement — ambiguous whether it's a directive at
|
||||
* all, refused rather than guessed at. */
|
||||
function scanDirectivePrologue(source, start) {
|
||||
let i = start;
|
||||
for (;;) {
|
||||
const next = skipWhitespaceAndComments(source, i);
|
||||
if (next === -1) return -1;
|
||||
const rest = source.slice(next);
|
||||
const m = STRING_LITERAL.exec(rest);
|
||||
if (!m) return next; // not a directive; prologue (possibly empty) ends here
|
||||
const after = rest.slice(m[0].length);
|
||||
if (after[0] === ';') {
|
||||
i = next + m[0].length + 1;
|
||||
} else if (after === '' || LINE_TERMINATOR.test(after[0])) {
|
||||
i = next + m[0].length;
|
||||
} else {
|
||||
return -1; // "use strict" + x and friends: not unambiguously a directive
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* Insert the opt-in right after the bundle's full leading directive prologue (BOM/hashbang, then
|
||||
* any run of string-literal-only statements — "use strict" among them if present). It must go
|
||||
* *after* the whole prologue, not just after the first entry: a directive prologue only takes
|
||||
* effect when its members are the very first statements, so inserting between two of them, or
|
||||
* ahead of all of them, would silently drop the file out of strict mode just as surely as
|
||||
* inserting ahead of a lone "use strict" would.
|
||||
*
|
||||
* Returns null — meaning "refuse to patch" — for anything that is not unambiguously a directive.
|
||||
* `"use strict" + x` is an expression, not a directive, and injecting into it would produce a
|
||||
* syntax error, so the directive is only accepted when it is terminated by its own semicolon, a
|
||||
* line break, or end of input. */
|
||||
* When there is no prologue at all (observed from Claude Desktop 1.30096.1 onward, whose main
|
||||
* entry opens with a bare IIFE instead), there is nothing to preserve: PATCH lands at the same
|
||||
* position anyway, as the file's first real statement. A `try{}catch(e){}` statement can never
|
||||
* merge with whatever follows via ASI — unlike a bare expression, a statement is not a valid
|
||||
* left-hand side for anything a following token could continue — so this is unconditionally
|
||||
* safe once placed after any banner comment / hashbang / directive prologue. */
|
||||
function applyPatch(source) {
|
||||
const m = /^\s*(['"])use strict\1(;?)/.exec(source);
|
||||
if (!m) return null;
|
||||
const rest = source.slice(m[0].length);
|
||||
const terminated = m[2] === ';' || rest === '' || /^[\r\n]/.test(rest);
|
||||
if (!terminated) return null;
|
||||
// Supply the terminator when the directive relied on ASI; without it the injected code would
|
||||
// continue the string-literal expression instead of following it.
|
||||
const sep = m[2] === ';' ? '' : ';';
|
||||
return source.slice(0, m[0].length) + sep + PATCH + rest;
|
||||
const start = skipBomAndHashbang(source);
|
||||
const end = scanDirectivePrologue(source, start);
|
||||
if (end === -1) return null;
|
||||
return source.slice(0, end) + PATCH + source.slice(end);
|
||||
}
|
||||
|
||||
function writeAll(fd, buf) {
|
||||
@@ -203,7 +277,7 @@ function main() {
|
||||
|
||||
const patchedSource = applyPatch(original);
|
||||
if (patchedSource === null) {
|
||||
fail(`${mainRel} does not begin with a recognized "use strict" directive; refusing to patch`);
|
||||
fail(`${mainRel} opens with an ambiguous "use strict"-like string literal; refusing to patch`);
|
||||
}
|
||||
const patched = Buffer.from(patchedSource, 'utf8');
|
||||
|
||||
|
||||
@@ -1,4 +1,18 @@
|
||||
|
||||
## 1.5.1.2 (2026-08-19)
|
||||
- Fix direct access on port 8071, which was broken in 1.5.1.1: the root
|
||||
redirect pointed at the container-internal port 8072 instead of the
|
||||
published one, and the page it led to referenced assets under a path the
|
||||
add-on did not serve, so every asset returned 404. Requests are now passed
|
||||
through unchanged, with the bare root and the two previously documented
|
||||
`/filebrowser_quantum` URLs redirected to the app's configured base path.
|
||||
|
||||
## 1.5.1.1 (2026-08-16)
|
||||
- Expose the web UI on host port 8071, reachable at `<your-ip>:8071`
|
||||
(redirects to `/filebrowser_quantum/`). Direct access is served by a new,
|
||||
separate nginx vhost that proxies to the same backend Ingress already uses;
|
||||
Ingress itself, and the app's own base URL, are unchanged.
|
||||
|
||||
## 1.5.1 (2026-08-08)
|
||||
- Update to latest version from gtsteffaniak/filebrowser (changelog : https://github.com/gtsteffaniak/filebrowser/releases)
|
||||
|
||||
|
||||
@@ -46,7 +46,7 @@ comparison to installing any other Home Assistant add-on.
|
||||
|
||||
## Configuration
|
||||
|
||||
The web UI can be found at `<your-ip>:8071` or through the Home Assistant sidebar when using Ingress.
|
||||
The web UI can be found at `<your-ip>:8071` or through the Home Assistant sidebar when using Ingress. Direct access redirects to the add-on's configured base path, so the address bar will show a longer URL than the one you typed.
|
||||
|
||||
**Default credentials:**
|
||||
- Username: `admin`
|
||||
|
||||
@@ -97,6 +97,10 @@ options:
|
||||
default_user_scope: "/"
|
||||
panel_admin: false
|
||||
panel_icon: mdi:file-search
|
||||
ports:
|
||||
8072/tcp: 8071
|
||||
ports_description:
|
||||
8072/tcp: Web UI port
|
||||
privileged:
|
||||
- SYS_ADMIN
|
||||
- DAC_READ_SEARCH
|
||||
@@ -114,4 +118,4 @@ schema:
|
||||
slug: filebrowser_quantum
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons
|
||||
version: "1.5.1"
|
||||
version: "1.5.1.2"
|
||||
|
||||
@@ -43,6 +43,9 @@ declare ingress_interface
|
||||
declare ingress_port
|
||||
#declare keyfile
|
||||
|
||||
# The app's own baseURL is the Supervisor ingress-entry path, unchanged from
|
||||
# before: FileBrowser emits that prefix as absolute links in its HTML and JS,
|
||||
# so it is also the path direct ip:port access has to use (see direct.conf).
|
||||
FB_BASEURL=$(bashio::addon.ingress_entry)
|
||||
export FB_BASEURL
|
||||
|
||||
@@ -59,6 +62,15 @@ sed -i "s|%%protocol%%|${ADDON_PROTOCOL}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%port%%|${ingress_port}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%interface%%|${ingress_interface}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%subpath%%|${FB_BASEURL}/|g" /etc/nginx/servers/ingress.conf
|
||||
|
||||
# --- Direct ip:port access (separate vhost, ingress untouched) ---
|
||||
# Listens on 8072, published to the host as 8071 by config.yaml's `ports:`.
|
||||
# Requests are passed through unchanged; the bare root and the two legacy
|
||||
# /filebrowser_quantum paths are redirected to the app's baseURL, which is what
|
||||
# its own links already point at.
|
||||
sed -i "s|%%protocol%%|${ADDON_PROTOCOL}|g" /etc/nginx/servers/direct.conf
|
||||
sed -i "s|%%subpath%%|${FB_BASEURL}/|g" /etc/nginx/servers/direct.conf
|
||||
|
||||
mkdir -p /var/log/nginx && touch /var/log/nginx/error.log
|
||||
|
||||
############################
|
||||
|
||||
40
filebrowser_quantum/rootfs/etc/nginx/servers/direct.conf
Normal file
40
filebrowser_quantum/rootfs/etc/nginx/servers/direct.conf
Normal file
@@ -0,0 +1,40 @@
|
||||
server {
|
||||
listen 0.0.0.0:8072 default_server;
|
||||
|
||||
include /etc/nginx/includes/server_params.conf;
|
||||
include /etc/nginx/includes/proxy_params.conf;
|
||||
|
||||
client_max_body_size 0;
|
||||
|
||||
# nginx listens on 8072 inside the container but is published to the host
|
||||
# as 8071. An absolute redirect would be built from $server_port and send
|
||||
# the browser to :8072, which is not published and therefore unreachable.
|
||||
absolute_redirect off;
|
||||
|
||||
# FileBrowser serves under its baseURL (the Supervisor ingress entry) and
|
||||
# emits that prefix as absolute links in its HTML/JS, so the browser must
|
||||
# use that same path here. The bare root and the two legacy paths below
|
||||
# redirect to it; every other request is proxied through untouched, which
|
||||
# keeps asset, API and websocket URLs working without response rewriting.
|
||||
location = / {
|
||||
return 302 %%subpath%%;
|
||||
}
|
||||
|
||||
# 1.5.1.1 briefly documented /filebrowser_quantum/ as the direct URL. The
|
||||
# app never served that path itself, so send those bookmarks on instead of
|
||||
# letting them fall through to a 404.
|
||||
location = /filebrowser_quantum {
|
||||
return 302 %%subpath%%;
|
||||
}
|
||||
|
||||
location = /filebrowser_quantum/ {
|
||||
return 302 %%subpath%%;
|
||||
}
|
||||
|
||||
location / {
|
||||
proxy_connect_timeout 30m;
|
||||
proxy_send_timeout 30m;
|
||||
proxy_read_timeout 30m;
|
||||
proxy_pass %%protocol%%://backend;
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,7 @@
|
||||
|
||||
## 3.1.0.1 (2026-08-17)
|
||||
- Fix `password authentication failed for user` when `DB_PASSWORD` contains special characters. Passwords are now URI-encoded before being used in the psql connection string, and SQL-escaped before being used in `CREATE`/`ALTER USER` statements
|
||||
|
||||
## 3.1.0 (2026-08-01)
|
||||
- Update to latest version from immich-app/immich (changelog : https://github.com/immich-app/immich/releases)
|
||||
|
||||
|
||||
@@ -141,6 +141,6 @@ slug: immich
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons
|
||||
usb: true
|
||||
version: "3.1.0"
|
||||
version: "3.1.0.1"
|
||||
video: true
|
||||
webui: http://[HOST]:[PORT:8080]
|
||||
|
||||
@@ -98,10 +98,11 @@ setup_root_user() {
|
||||
fi
|
||||
|
||||
# Check if the root user exists.
|
||||
if ! psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}" -tAc "SELECT 1 FROM pg_roles WHERE rolname='root'" | grep -q 1; then
|
||||
if ! psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}" -tAc "SELECT 1 FROM pg_roles WHERE rolname='root'" | grep -q 1; then
|
||||
bashio::log.info "Root user does not exist. Creating root user with DB_ROOT_PASSWORD..."
|
||||
psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
CREATE ROLE root WITH LOGIN SUPERUSER CREATEDB CREATEROLE PASSWORD '${DB_ROOT_PASSWORD}';
|
||||
local root_password_sql="${DB_ROOT_PASSWORD//\'/\'\'}"
|
||||
psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
CREATE ROLE root WITH LOGIN SUPERUSER CREATEDB CREATEROLE PASSWORD '${root_password_sql}';
|
||||
EOF
|
||||
else
|
||||
bashio::log.info "Root user exists with a non-default password. No migration needed."
|
||||
@@ -113,10 +114,10 @@ setup_database() {
|
||||
bashio::log.info "Setting up external PostgreSQL database..."
|
||||
|
||||
# Create the database if it does not exist
|
||||
if ! psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}/postgres" -tAc \
|
||||
if ! psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}/postgres" -tAc \
|
||||
"SELECT 1 FROM pg_database WHERE datname='${DB_DATABASE_NAME}';" | grep -q 1; then
|
||||
bashio::log.info "Database does not exist. Creating it now..."
|
||||
psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
CREATE DATABASE ${DB_DATABASE_NAME};
|
||||
EOF
|
||||
else
|
||||
@@ -124,20 +125,21 @@ EOF
|
||||
fi
|
||||
|
||||
# Ensure the user exists and update its password
|
||||
psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
local db_password_sql="${DB_PASSWORD//\'/\'\'}"
|
||||
psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
DO \$\$
|
||||
BEGIN
|
||||
IF NOT EXISTS (SELECT FROM pg_roles WHERE rolname = '${DB_USERNAME}') THEN
|
||||
CREATE USER ${DB_USERNAME} WITH ENCRYPTED PASSWORD '${DB_PASSWORD}';
|
||||
CREATE USER ${DB_USERNAME} WITH ENCRYPTED PASSWORD '${db_password_sql}';
|
||||
ELSE
|
||||
ALTER USER ${DB_USERNAME} WITH ENCRYPTED PASSWORD '${DB_PASSWORD}';
|
||||
ALTER USER ${DB_USERNAME} WITH ENCRYPTED PASSWORD '${db_password_sql}';
|
||||
END IF;
|
||||
END
|
||||
\$\$;
|
||||
EOF
|
||||
|
||||
# Ensure the user has full privileges on the database
|
||||
psql "postgres://${DB_USERNAME}:${DB_PASSWORD}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
psql "postgres://${DB_USERNAME_URI}:${DB_PASSWORD_URI}@${DB_HOSTNAME}:${DB_PORT}" << EOF
|
||||
GRANT ALL PRIVILEGES ON DATABASE ${DB_DATABASE_NAME} TO ${DB_USERNAME};
|
||||
EOF
|
||||
|
||||
@@ -147,7 +149,7 @@ EOF
|
||||
# Function to check if the vectors (pgvecto.rs) extension is available on the server
|
||||
check_vector_extension() {
|
||||
echo "Checking if 'vectors' extension is available for database '${DB_DATABASE_NAME}'..."
|
||||
RESULT=$(psql "postgres://$DB_USERNAME:$DB_PASSWORD@$DB_HOSTNAME:$DB_PORT/${DB_DATABASE_NAME}" -tAc "SELECT 1 FROM pg_available_extensions WHERE name = 'vectors';")
|
||||
RESULT=$(psql "postgres://$DB_USERNAME_URI:$DB_PASSWORD_URI@$DB_HOSTNAME:$DB_PORT/${DB_DATABASE_NAME}" -tAc "SELECT 1 FROM pg_available_extensions WHERE name = 'vectors';")
|
||||
if [[ "$RESULT" == "1" ]]; then
|
||||
echo "✅ 'vectors' extension is available."
|
||||
return 0
|
||||
@@ -163,7 +165,7 @@ check_vector_extension() {
|
||||
# itself on first startup; checking pg_extension would false-warn on every fresh install.
|
||||
check_vchord_extension() {
|
||||
echo "Checking if 'vchord' extension is available for database '${DB_DATABASE_NAME}'..."
|
||||
RESULT=$(psql "postgres://$DB_USERNAME:$DB_PASSWORD@$DB_HOSTNAME:$DB_PORT/${DB_DATABASE_NAME}" -tAc "SELECT 1 FROM pg_available_extensions WHERE name = 'vchord';")
|
||||
RESULT=$(psql "postgres://$DB_USERNAME_URI:$DB_PASSWORD_URI@$DB_HOSTNAME:$DB_PORT/${DB_DATABASE_NAME}" -tAc "SELECT 1 FROM pg_available_extensions WHERE name = 'vchord';")
|
||||
if [[ "$RESULT" == "1" ]]; then
|
||||
echo "✅ 'vchord' extension is available."
|
||||
return 0
|
||||
@@ -187,6 +189,14 @@ export DB_PORT="$(bashio::config 'DB_PORT')"
|
||||
export JWT_SECRET="$(bashio::config 'JWT_SECRET')"
|
||||
export DB_HOSTNAME="$(bashio::config 'DB_HOSTNAME')"
|
||||
|
||||
# libpq percent-decodes the userinfo part of a postgres:// URI, so credentials
|
||||
# containing reserved characters (% @ / : ? #) are misread and every psql call
|
||||
# below fails with "password authentication failed". Encode them once here and
|
||||
# use the encoded copies in URIs only - the app itself still gets the raw value
|
||||
# through export_db_env. Same approach as the postgres_15/postgres_17 addons.
|
||||
export DB_USERNAME_URI="$(jq -rn --arg x "$DB_USERNAME" '$x|@uri')"
|
||||
export DB_PASSWORD_URI="$(jq -rn --arg x "$DB_PASSWORD" '$x|@uri')"
|
||||
|
||||
if bashio::config.true 'VIPS_NOVECTOR'; then
|
||||
export VIPS_NOVECTOR="1"
|
||||
fi
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
|
||||
## 1.26.3.1 (19-08-2026)
|
||||
|
||||
- Fix : tapping `Read` in the Home Assistant companion app opened the reader in an external browser, which carries no ingress session cookie, so Home Assistant answered `401 Unauthorized` before Komga was reached ([#2994](https://github.com/alexbelgium/hassio-addons/issues/2994)). Komga opens the reader with `window.open(url, '_blank')` ; nginx now injects a script that turns that popup into a navigation of the ingress panel itself. Only http(s) urls below Komga's own base path are affected, so the OAuth2 login popup and links out of Komga keep their own window
|
||||
|
||||
## 1.26.3 (2026-08-13)
|
||||
- Update to latest version from gotson/komga (changelog : https://github.com/gotson/komga/releases)
|
||||
## 1.26.1.4 (12-08-2026)
|
||||
|
||||
@@ -101,4 +101,4 @@ schema:
|
||||
slug: komga
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons/tree/master/komga
|
||||
version: "1.26.3"
|
||||
version: "1.26.3.1"
|
||||
|
||||
@@ -60,6 +60,25 @@ server {
|
||||
# Only the json/xml document types are added here, so book pages are
|
||||
# never scanned.
|
||||
sub_filter "http://127.0.0.1:25600/komga" "%%ingress_entry%%/komga";
|
||||
|
||||
# Komga opens the reader with window.open(url, '_blank'). In the Home
|
||||
# Assistant companion apps the ingress panel is a webview, which hands
|
||||
# such a popup to an external browser : that browser carries no ingress
|
||||
# session cookie, so Home Assistant answers 401 before Komga is even
|
||||
# reached. Turn that popup into a navigation of the panel itself, but
|
||||
# only for the call shape Komga uses (name _blank, no feature string)
|
||||
# and only for http(s) urls below window.resourceBaseUrl. That leaves
|
||||
# the OAuth2 login popup (window.open(url, 'oauth2Login', '<features>'),
|
||||
# which needs its own window), blob urls and links out of Komga alone,
|
||||
# and if Komga ever stopped setting resourceBaseUrl the popup is left
|
||||
# untouched rather than widened to the whole Home Assistant origin,
|
||||
# which ingress shares. Anchored on the single page app mount point :
|
||||
# both Komga ui shells carry it once, and only a book served as
|
||||
# text/html rather than the xhtml the epub spec mandates could collide
|
||||
# with it -- the same exposure the /komga filter above already has, and
|
||||
# Komga sends script-src 'none' on that endpoint.
|
||||
sub_filter "<div id=\"app\">" "<script>(function(){var o=window.open;window.open=function(u,n,f){try{var b=window.resourceBaseUrl;if(u&&n==='_blank'&&!f&&b){if(b.slice(-1)!=='/')b+='/';var t=new URL(u,location.href);if((t.protocol==='http:'||t.protocol==='https:')&&t.origin===location.origin&&t.pathname.indexOf(b)===0){location.assign(t.href);return window}}}catch(e){}return o.apply(window,arguments)}})();</script><div id=\"app\">";
|
||||
|
||||
sub_filter_types application/json application/webpub+json
|
||||
application/divina+json application/opds+json
|
||||
application/atom+xml;
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
|
||||
## v0.9.3.1 (2026-08-18)
|
||||
- Fix startup crash: `collector-once` failed with `s6-svwait: fatal: unable to subscribe to events for /run/service/scrutiny` because the add-on entrypoint never started real s6 supervision. Keep the upstream image's own `/init` as PID 1, same as `scrutiny_original` (#2991) and `scrutiny`/`scrutiny_fa` (#2878).
|
||||
|
||||
## v0.9.3 (2026-08-13)
|
||||
- Update to latest version from analogj/scrutiny (changelog : https://github.com/analogj/scrutiny/releases)
|
||||
|
||||
|
||||
@@ -33,7 +33,8 @@ ENV S6_CMD_WAIT_FOR_SERVICES=1 \
|
||||
|
||||
# Add rootfs
|
||||
COPY rootfs/ /
|
||||
RUN find . -type f \( -name "*.sh" -o -name "run" -o -name "finish" \) -print -exec chmod +x {} \;
|
||||
RUN find . -type f \( -name "*.sh" -o -name "run" -o -name "finish" \) -print -exec chmod +x {} \; && \
|
||||
if [ -d /command ]; then ln -sf /command/* /usr/bin/; fi
|
||||
|
||||
# Uses /bin for compatibility purposes
|
||||
# hadolint ignore=DL4005
|
||||
@@ -61,19 +62,35 @@ RUN chmod 744 /ha_autoapps.sh && /ha_autoapps.sh "$PACKAGES" && rm /ha_autoapps.
|
||||
# 4 Entrypoint #
|
||||
################
|
||||
|
||||
# Add entrypoint
|
||||
# Keep the repository initialization hook, but return after it has prepared the
|
||||
# cont-init scripts. Upstream s6 remains responsible for supervising services.
|
||||
ENV S6_STAGE2_HOOK=/ha_entrypoint.sh
|
||||
COPY ha_entrypoint.sh /ha_entrypoint.sh
|
||||
RUN chmod 777 /ha_entrypoint.sh
|
||||
RUN chmod 0755 /ha_entrypoint.sh && \
|
||||
awk '!inserted && $0 == "if $PID1; then" { \
|
||||
print "if ! $PID1; then"; \
|
||||
print " echo \"Initialization hook complete\""; \
|
||||
print " exit 0"; \
|
||||
print "fi"; \
|
||||
inserted=1 \
|
||||
} { print }' /ha_entrypoint.sh > /ha_entrypoint.sh.tmp && \
|
||||
mv /ha_entrypoint.sh.tmp /ha_entrypoint.sh && \
|
||||
chmod 0755 /ha_entrypoint.sh
|
||||
|
||||
# Install bashio
|
||||
COPY bashio-standalone.sh /usr/local/lib/bashio-standalone.sh
|
||||
RUN chmod 0755 /usr/local/lib/bashio-standalone.sh
|
||||
|
||||
RUN test -x /init && \
|
||||
test -x /ha_entrypoint.sh && \
|
||||
bash -n /ha_entrypoint.sh && \
|
||||
grep -q 'Initialization hook complete' /ha_entrypoint.sh
|
||||
|
||||
RUN sed -i "1a if ! bashio::require.unprotected; then bashio::addon.stop; fi" /etc/cont-init.d/90-run.sh
|
||||
|
||||
ENTRYPOINT [ "/usr/bin/env" ]
|
||||
CMD [ "/ha_entrypoint.sh" ]
|
||||
# Scrutiny's image already includes s6-overlay and defines all services under
|
||||
# /etc/services.d. Keep /init as PID 1 so service readiness and s6-svc calls work.
|
||||
ENTRYPOINT [ "/init" ]
|
||||
|
||||
############
|
||||
# 5 Labels #
|
||||
|
||||
@@ -45,4 +45,4 @@ schema:
|
||||
slug: scrutiny_fa_original
|
||||
udev: true
|
||||
url: https://github.com/analogj/scrutiny
|
||||
version: "v0.9.3"
|
||||
version: "v0.9.3.1"
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
|
||||
## v0.9.3.1 (2026-08-18)
|
||||
- Fix startup crash: `collector-once` failed with `s6-svwait: fatal: unable to subscribe to events for /run/service/scrutiny` because the add-on entrypoint never started real s6 supervision. Keep the upstream image's own `/init` as PID 1 (same fix already shipped for `scrutiny`/`scrutiny_fa` in #2878). Closes #2989.
|
||||
|
||||
## v0.9.3 (2026-08-13)
|
||||
- Update to latest version from analogj/scrutiny (changelog : https://github.com/analogj/scrutiny/releases)
|
||||
|
||||
|
||||
@@ -33,7 +33,8 @@ ENV S6_CMD_WAIT_FOR_SERVICES=1 \
|
||||
|
||||
# Add rootfs
|
||||
COPY rootfs/ /
|
||||
RUN find . -type f \( -name "*.sh" -o -name "run" -o -name "finish" \) -print -exec chmod +x {} \;
|
||||
RUN find . -type f \( -name "*.sh" -o -name "run" -o -name "finish" \) -print -exec chmod +x {} \; && \
|
||||
if [ -d /command ]; then ln -sf /command/* /usr/bin/; fi
|
||||
|
||||
# Uses /bin for compatibility purposes
|
||||
# hadolint ignore=DL4005
|
||||
@@ -61,17 +62,33 @@ RUN chmod 744 /ha_autoapps.sh && /ha_autoapps.sh "$PACKAGES" && rm /ha_autoapps.
|
||||
# 4 Entrypoint #
|
||||
################
|
||||
|
||||
# Add entrypoint
|
||||
# Keep the repository initialization hook, but return after it has prepared the
|
||||
# cont-init scripts. Upstream s6 remains responsible for supervising services.
|
||||
ENV S6_STAGE2_HOOK=/ha_entrypoint.sh
|
||||
COPY ha_entrypoint.sh /ha_entrypoint.sh
|
||||
RUN chmod 777 /ha_entrypoint.sh
|
||||
RUN chmod 0755 /ha_entrypoint.sh && \
|
||||
awk '!inserted && $0 == "if $PID1; then" { \
|
||||
print "if ! $PID1; then"; \
|
||||
print " echo \"Initialization hook complete\""; \
|
||||
print " exit 0"; \
|
||||
print "fi"; \
|
||||
inserted=1 \
|
||||
} { print }' /ha_entrypoint.sh > /ha_entrypoint.sh.tmp && \
|
||||
mv /ha_entrypoint.sh.tmp /ha_entrypoint.sh && \
|
||||
chmod 0755 /ha_entrypoint.sh
|
||||
|
||||
# Install bashio
|
||||
COPY bashio-standalone.sh /usr/local/lib/bashio-standalone.sh
|
||||
RUN chmod 0755 /usr/local/lib/bashio-standalone.sh
|
||||
|
||||
ENTRYPOINT [ "/usr/bin/env" ]
|
||||
CMD [ "/ha_entrypoint.sh" ]
|
||||
RUN test -x /init && \
|
||||
test -x /ha_entrypoint.sh && \
|
||||
bash -n /ha_entrypoint.sh && \
|
||||
grep -q 'Initialization hook complete' /ha_entrypoint.sh
|
||||
|
||||
# Scrutiny's image already includes s6-overlay and defines all services under
|
||||
# /etc/services.d. Keep /init as PID 1 so service readiness and s6-svc calls work.
|
||||
ENTRYPOINT [ "/init" ]
|
||||
|
||||
############
|
||||
# 5 Labels #
|
||||
|
||||
@@ -113,4 +113,4 @@ schema:
|
||||
slug: scrutiny_original
|
||||
udev: true
|
||||
url: https://github.com/analogj/scrutiny
|
||||
version: "v0.9.3"
|
||||
version: "v0.9.3.1"
|
||||
|
||||
@@ -1,4 +1,15 @@
|
||||
|
||||
## 3.4.1.3 (2026-08-18)
|
||||
|
||||
- Fixed the `404: Not Found` on **Discover** persisting for browsers that had already opened Seerr through ingress, even after 3.4.1.1 and 3.4.1.2 were installed (#2975). Seerr serves its JavaScript bundle with `Cache-Control: public, max-age=31536000, immutable`, and the add-on's nginx rewrites that bundle to carry the ingress prefix - which strips the `ETag` and `Last-Modified` a browser would revalidate with. Since every add-on version served the same upstream build, the chunk URLs never changed either, so a browser kept replaying the broken 3.4.1/3.4.1.1 JavaScript from its own cache for up to a year and no fix could reach it. That is why the report persisted on the origin the reporter uses daily (`https://<domain>/`) while a browser that had never cached it (`http://<ip>:8123/`) already showed the fixed behaviour. The asset paths now carry the add-on version, so each release has its own URLs and the first page load after an update fetches the current bundle. Only ingress was affected; the directly published port 5055 always worked.
|
||||
|
||||
## 3.4.1.2 (2026-08-18)
|
||||
|
||||
- Fixed **Discover** in the sidebar still failing through ingress after 3.4.1.1 (#2975). The trailing slash added in 3.4.1.1 was also applied to the copy of the link inside Seerr's JavaScript bundle, and Next.js' client-side router strips a trailing slash before navigating: it then sent the click to a URL Home Assistant does not route, so it either landed on the same `404: Not Found` or threw `Invariant: attempted to hard navigate to the same URL` and did nothing at all. The bundle is no longer rewritten, so **Discover** routes inside the app exactly like **Requests**, **Issues** and **Settings** already did. The server-rendered link keeps its trailing slash. Only ingress was affected; the directly published port 5055 always worked.
|
||||
|
||||
## 3.4.1.1 (2026-08-16)
|
||||
|
||||
- Fixed `404: Not Found` when clicking **Discover** in the sidebar through ingress (#2975). Seerr's Discover link points at `/`, which nginx rewrote to the ingress entry without a trailing slash; Home Assistant only routes ingress on `/api/hassio_ingress/<token>/…`, so the request was rejected by Home Assistant before reaching the add-on. Only ingress was affected; the directly published port 5055 always worked.
|
||||
|
||||
## 3.4.1 (2026-08-01)
|
||||
- Update to latest version from seerr-team/seerr (changelog : https://github.com/seerr-team/seerr/releases)
|
||||
## 3.3.0.1 (2026-07-28)
|
||||
|
||||
@@ -96,4 +96,4 @@ schema:
|
||||
slug: seerr
|
||||
udev: true
|
||||
url: https://github.com/alexbelgium/hassio-addons/tree/master/seerr
|
||||
version: "3.4.1"
|
||||
version: "3.4.1.3"
|
||||
|
||||
@@ -12,10 +12,27 @@ ingress_port=$(bashio::addon.ingress_port)
|
||||
ingress_interface=$(bashio::addon.ip_address)
|
||||
ingress_entry=$(bashio::addon.ingress_entry)
|
||||
|
||||
# Cache-busting marker for the rewritten JavaScript bundle.
|
||||
#
|
||||
# Seerr serves /_next/static/ as "public, max-age=31536000, immutable", and
|
||||
# nginx's sub_filter strips ETag and Last-Modified off every response it
|
||||
# rewrites, while the HTML naming those chunks is served "no-store" and keeps
|
||||
# naming the same URLs. A browser therefore pins the bundle this add-on rewrote
|
||||
# on its first visit for a year, with no request left that could deliver a
|
||||
# later change to the sub_filter rules below - which is how #2975 outlived two
|
||||
# fixes. Folding the version into the asset path gives every release its own
|
||||
# URLs. njs/ingress.js strips the marker again before proxying.
|
||||
#
|
||||
# BUILD_VERSION is the add-on version baked in at build time (it is also what
|
||||
# bashio::addon.version returns). Only [A-Za-z0-9-] survives: the marker ends up
|
||||
# inside a regex literal in Seerr's own bundle, where a dot would be a wildcard.
|
||||
asset_tag="ha-$(printf '%s' "${BUILD_VERSION:-0}" | tr -c 'A-Za-z0-9' '-')"
|
||||
|
||||
# Update ingress.conf with actual values
|
||||
sed -i "s|%%port%%|${ingress_port}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%interface%%|${ingress_interface}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%ingress_entry%%|${ingress_entry}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%ingress_entry_escaped%%|${ingress_entry//\//\\\\\/}|g" /etc/nginx/servers/ingress.conf
|
||||
sed -i "s|%%asset_tag%%|${asset_tag}|g" /etc/nginx/servers/ingress.conf
|
||||
|
||||
bashio::log.info "Nginx ingress configured on ${ingress_interface}:${ingress_port}"
|
||||
bashio::log.info "Nginx ingress configured on ${ingress_interface}:${ingress_port} (asset tag ${asset_tag})"
|
||||
|
||||
@@ -47,11 +47,27 @@ function encodePart(part) {
|
||||
}
|
||||
|
||||
/*
|
||||
* Returns the request URI with the path untouched byte-for-byte and only the
|
||||
* query string repaired. Used as the proxy_pass target.
|
||||
* The cache-busting marker servers/ingress.conf inserts in front of every
|
||||
* rewritten "/_next" path, e.g. "/ha-3-4-1-3/_next/static/chunks/x.js". It
|
||||
* gives each add-on release its own asset URLs - Seerr serves /_next/static/ as
|
||||
* immutable for a year and sub_filter strips the validators, so identical URLs
|
||||
* would pin the rewritten bundle in the browser forever. Seerr knows nothing
|
||||
* about the marker, so it is removed again here, on the way in.
|
||||
*
|
||||
* Any marker is accepted, not just the one this container serves: a tab opened
|
||||
* before an add-on update keeps requesting its dynamic chunks under the marker
|
||||
* it was handed, and those have to keep working until it is reloaded. The
|
||||
* lookahead keeps a real Seerr path that merely starts with "ha-" untouched.
|
||||
*/
|
||||
var ASSET_TAG = /^\/ha-[0-9A-Za-z-]+(?=\/_next(\/|$))/;
|
||||
|
||||
/*
|
||||
* Returns the request URI with the path untouched byte-for-byte apart from the
|
||||
* cache-busting marker, and only the query string repaired. Used as the
|
||||
* proxy_pass target.
|
||||
*/
|
||||
function uri(r) {
|
||||
var raw = r.variables.request_uri;
|
||||
var raw = r.variables.request_uri.replace(ASSET_TAG, "");
|
||||
var split = raw.indexOf("?");
|
||||
|
||||
if (split < 0) {
|
||||
|
||||
@@ -43,14 +43,48 @@ server {
|
||||
|
||||
sub_filter_once off;
|
||||
|
||||
# Do not rewrite every response type blindly.
|
||||
sub_filter_types text/html application/javascript text/javascript application/json;
|
||||
# Do not rewrite every response type blindly. text/html is implicit and
|
||||
# must not be listed - nginx pre-seeds it and warns "duplicate MIME type"
|
||||
# on every config load if it appears here as well.
|
||||
sub_filter_types application/javascript text/javascript application/json;
|
||||
|
||||
sub_filter 'href="/"' 'href="$app"';
|
||||
# Seerr's "Discover" sidebar entry, the header logo and the 404 and
|
||||
# error pages are all <Link href="/">. The server-rendered anchor has to
|
||||
# carry the ingress prefix *with* a trailing slash: Home Assistant routes
|
||||
# ingress on "/api/hassio_ingress/{token}/{path:.*}", so a slash-less
|
||||
# entry matches no route and Home Assistant answers its own plain-text
|
||||
# "404: Not Found" before the request ever reaches this add-on (#2975).
|
||||
sub_filter 'href="/"' 'href="$app/"';
|
||||
sub_filter 'href="/login"' 'href="$app/login"';
|
||||
sub_filter 'href:"/"' 'href:"$app"';
|
||||
sub_filter '\/_next' '%%ingress_entry_escaped%%\/_next';
|
||||
sub_filter '/_next' '$app/_next';
|
||||
|
||||
# A matching rule for 'href:"/"' - the form those same links take once
|
||||
# compiled into the JS bundle - used to sit here. It is gone on purpose
|
||||
# and must not come back: it fed the ingress prefix into Next.js' own
|
||||
# route table, and next/link resolves a pushed href through
|
||||
# normalizePathTrailingSlash(), which drops a trailing slash while
|
||||
# `trailingSlash` is false (Seerr sets no override). Next therefore hard
|
||||
# navigated to the slash-less URL and recreated the same 404; on the root
|
||||
# page it instead threw "Invariant: attempted to hard navigate to the
|
||||
# same URL" and the click did nothing. That is the state PR #2976 left
|
||||
# #2975 in. Left alone the href stays "/", which removeTrailingSlash()
|
||||
# preserves, so the router matches its own "/" route and transitions
|
||||
# in-app - the path every other sidebar entry ("/requests", "/issues",
|
||||
# "/users", "/settings") already takes. Prefixing belongs in the rendered
|
||||
# anchor, never in the router's route table.
|
||||
#
|
||||
# Note that none of these rules are response-type scoped - sub_filter_types
|
||||
# includes JavaScript - so the anchor rule above avoids the bundle only
|
||||
# because the compiled output spells the prop 'href:"/"' and not
|
||||
# 'href="/"'. These are textual substitutions over someone else's minified
|
||||
# output: recheck them whenever Seerr or Next.js is upgraded.
|
||||
# "%%asset_tag%%" is a cache-busting marker carrying the add-on version,
|
||||
# substituted by 32-nginx_ingress.sh - which explains why it is needed.
|
||||
# In short: without it a browser replays the bundle this file produced at
|
||||
# the version it first loaded, for a year, and no later change to any
|
||||
# rule here can reach it. njs/ingress.js strips the marker back off
|
||||
# before proxying; the two belong together, do not change one alone.
|
||||
sub_filter '\/_next' '%%ingress_entry_escaped%%\/%%asset_tag%%\/_next';
|
||||
sub_filter '/_next' '$app/%%asset_tag%%/_next';
|
||||
sub_filter '/api/v1' '$app/api/v1';
|
||||
sub_filter '/login/plex/loading' '$app/login/plex/loading';
|
||||
sub_filter '/images/' '$app/images/';
|
||||
|
||||
Reference in New Issue
Block a user