994ed9d77a
Adds GET /api/v1/stats/summary, gated by HOMEPAGE_API_KEY env var and X-API-Key header (hmac.compare_digest, matches the liveview pattern). Payload: nodes / online / offline / unknown pending_devices (status='pending') zigbee_devices (Node.ieee_address IS NOT NULL) last_scan_at (max ScanRun.finished_at) Disabled by default — endpoint returns 403 unless HOMEPAGE_API_KEY is set. README documents activation and ships a ready-to-paste gethomepage `customapi` widget snippet. Tests cover: disabled-by-default, missing header, wrong key, empty DB, and full aggregation across nodes/pending/zigbee/scan-runs.
37 lines
1.6 KiB
Bash
37 lines
1.6 KiB
Bash
# Backend - server-side only (NEVER commit .env)
|
|
SECRET_KEY=change_me_in_production
|
|
SQLITE_PATH=./data/homelab.db
|
|
# Set this to the URL(s) you use to access Homelable in your browser.
|
|
CORS_ORIGINS=["http://localhost:5173","http://localhost:3000"]
|
|
|
|
# Auth — default credentials: admin / admin
|
|
# ⚠️ Change before exposing on a network.
|
|
# Generate a new hash: python3 -c "from passlib.context import CryptContext; print(CryptContext(schemes=['bcrypt']).hash('yourpassword'))"
|
|
# ⚠️ Keep the single quotes around the hash — bcrypt hashes contain \$ which Docker misinterprets without them.
|
|
AUTH_USERNAME=admin
|
|
AUTH_PASSWORD_HASH='$2b$12$RtMbyw17l4N5UGzeXMNAWuzCaVV.XFBY7ZetWheQhxcBDcxahapkG'
|
|
|
|
# Scanner — JSON array of CIDR ranges to scan
|
|
SCANNER_RANGES=["192.168.1.0/24"]
|
|
|
|
# Status checker interval in seconds
|
|
STATUS_CHECKER_INTERVAL=60
|
|
|
|
# MCP server — used by the mcp service (port 8001)
|
|
# MCP_API_KEY: authenticates AI clients (Claude Code, etc.) → MCP server
|
|
# MCP_SERVICE_KEY: authenticates MCP server → backend (never exposed externally)
|
|
# Generate keys: python3 -c "import secrets; print(secrets.token_hex(32))"
|
|
MCP_API_KEY=mcp_sk_changeme
|
|
MCP_SERVICE_KEY=svc_changeme
|
|
|
|
# Live view — read-only public canvas at /view?key=<value>
|
|
# Off by default. Set to a random secret to enable.
|
|
# Generate: python3 -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
# LIVEVIEW_KEY=
|
|
|
|
# Gethomepage widget — read-only stats at /api/v1/stats/summary
|
|
# Off by default. Set to a random secret to enable; clients must send
|
|
# the same value in the `X-API-Key` header.
|
|
# Generate: python3 -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
# HOMEPAGE_API_KEY=
|