Stefan AgnerandClaude Fable 5.1 94b4a0b77c Forward Core API proxy paths byte-for-byte and match deny rules on decoded path (#7225)
The Core API proxy compared its deny pattern against the once-decoded route
capture and then formatted that string into the upstream URL, where yarl
decoded percent-encoded unreserved characters a second time. A path such as
hassio%255Fauth/password_reset passed both the middleware blacklist and the
proxy's deny check but reached Core as /api/hassio_auth/password_reset,
which the proxy executes as the Supervisor user.

Forward the raw path exactly as received instead of the decoded capture, and
build the upstream URL with encoded=True so the bytes checked are the bytes
sent. This also stops lossy re-encoding of legitimate paths, e.g. an encoded
slash no longer turns into a path separator. Match both the middleware
blacklist and the proxy deny pattern against the recursively unquoted path
so any encoding depth resolves to the same decision. The recursive unquote
helper moves to module level so both call sites share it.

Reported in GHSA-m2gm-724m-7rf9.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 13:11:08 +02:00
2025-10-08 10:44:49 +02:00
…
2024-09-30 18:42:08 +02:00

Home Assistant Supervisor

First private cloud solution for home automation

Home Assistant (former Hass.io) is a container-based system for managing your Home Assistant Core installation and related applications. The system is controlled via Home Assistant which communicates with the Supervisor. The Supervisor provides an API to manage the installation. This includes changing network settings or installing and updating software.

Installation

Installation instructions can be found at https://home-assistant.io/getting-started.

Development

For small changes and bugfixes you can just follow this, but for significant changes open a RFC first. Development instructions can be found here.

Release

Releases are done in 3 stages (channels) with this structure:

  1. Pull requests are merged to the main branch.
  2. A new build is pushed to the dev stage.
  3. Releases are published.
  4. A new build is pushed to the beta stage.
  5. The stable.json file is updated.
  6. The build that was pushed to beta will now be pushed to stable.

Home Assistant - A project from the Open Home Foundation

Languages
Python 96.3%
JavaScript 3.6%