[web_server] Fix basic auth with long credentials (#18237)

This commit is contained in:
J. Nick Koston
2026-08-10 14:49:14 -05:00
committed by GitHub
parent 334afdefb5
commit 8a16ead8ce
8 changed files with 120 additions and 15 deletions
@@ -33,14 +33,49 @@ def test_web_server_auth_explicit_basic_no_warning(
generate_main: Callable[[str], str],
caplog: pytest.LogCaptureFixture,
) -> None:
"""Auth type basic builds Basic and does not warn."""
generate_main("tests/component_tests/web_server/web_server_auth_basic.yaml")
"""Auth type basic on ESP32 uses plaintext credentials and does not warn."""
main_cpp = generate_main(
"tests/component_tests/web_server/web_server_auth_basic.yaml"
)
assert '->set_auth_username("admin");' in main_cpp
assert '->set_auth_password("password");' in main_cpp
assert "set_auth_basic_hash" not in main_cpp
assert _has_define("USE_WEBSERVER_AUTH")
assert not _has_define("USE_WEBSERVER_AUTH_DIGEST")
assert _DEFAULT_CHANGE_WARNING not in caplog.text
def test_web_server_auth_basic_esp8266_uses_precomputed_hash(
generate_main: Callable[[str], str],
) -> None:
"""Auth type basic on ESP8266 emits the precomputed base64 hash, not the credentials."""
main_cpp = generate_main(
"tests/component_tests/web_server/web_server_auth_basic_esp8266.yaml"
)
assert '->set_auth_basic_hash("YWRtaW46cGFzc3dvcmQ=");' in main_cpp
assert "set_auth_username" not in main_cpp
assert "set_auth_password" not in main_cpp
assert _has_define("USE_WEBSERVER_AUTH")
assert not _has_define("USE_WEBSERVER_AUTH_DIGEST")
def test_web_server_auth_digest_esp8266_uses_plaintext_credentials(
generate_main: Callable[[str], str],
) -> None:
"""Auth type digest on ESP8266 uses plaintext credentials, not the basic hash."""
main_cpp = generate_main(
"tests/component_tests/web_server/web_server_auth_digest_esp8266.yaml"
)
assert '->set_auth_username("admin");' in main_cpp
assert '->set_auth_password("password");' in main_cpp
assert "set_auth_basic_hash" not in main_cpp
assert _has_define("USE_WEBSERVER_AUTH")
assert _has_define("USE_WEBSERVER_AUTH_DIGEST")
def test_web_server_auth_explicit_digest(
generate_main: Callable[[str], str],
caplog: pytest.LogCaptureFixture,
@@ -0,0 +1,16 @@
---
esphome:
name: test
esp8266:
board: esp01_1m
wifi:
ssid: MySSID
password: password1
web_server:
auth:
username: admin
password: password
type: basic
@@ -0,0 +1,16 @@
---
esphome:
name: test
esp8266:
board: esp01_1m
wifi:
ssid: MySSID
password: password1
web_server:
auth:
username: admin
password: password
type: digest
@@ -0,0 +1,8 @@
packages:
web_server: !include common_v2.yaml
web_server:
auth:
username: admin
password: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
type: basic
@@ -4,5 +4,5 @@ packages:
web_server:
auth:
username: admin
password: password
password: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
type: basic