Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔥 Remove STDIN service #349

Merged
merged 1 commit into from
Dec 15, 2021
Merged

🔥 Remove STDIN service #349

merged 1 commit into from
Dec 15, 2021

Conversation

frenck
Copy link
Member

@frenck frenck commented Dec 15, 2021

Proposed Changes

This removed the stdin service from this add-on.
It makes it too easy to run an arbitrary command from a simple service call from within Home Assistant; which potentially can lead to security issues. The service by itself requires one to be authenticated and therefore is not less secure compared to e.g., the terminal itself (which gives you the exact same power).

Rather social engineering can be a factor, although requires a lot of steps. To prevent such discussions this service is removed.

As a replacement, you can use the ssh command directly to achieve the same result; which is generally available and not specific to this add-on.

@frenck frenck added the breaking-change A breaking change for existing users. label Dec 15, 2021
@frenck frenck merged commit d8dd62a into main Dec 15, 2021
@frenck frenck deleted the frenck-2021-3233 branch December 15, 2021 13:03
@github-actions github-actions bot locked and limited conversation to collaborators Dec 17, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
breaking-change A breaking change for existing users.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant