Repository navigation
feat(vag_vehicle): sign in with email and password, report SoC age - #156
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6aeb86a95e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| -- An ended session answers 401/403, or redirects to the sign-in page. | ||
| if r.status == 401 or r.status == 403 or (r.status >= 300 and r.status < 400) then | ||
| session_ok = false | ||
| return nil, "HTTP 401: session ended" | ||
| end |
There was a problem hiding this comment.
Retry sessions expired during dataset download
When the session expires on the /download request, this branch sets session_ok = false, but the download error handler at driver_poll only logs download failed and returns the normal 300000 ms interval. Unlike expiry during metadata or list retrieval, renewal is therefore delayed by five minutes rather than the intended one-second retry; handle the session-ended state in the download failure path as well.
Useful? React with 👍 / 👎.
The EU Data Act portal session lasts about an hour, and the driver needed a pasted Cookie header each time (#143). On an FTW Core with host.http_request the driver now signs in itself, as evcc does: the identity form, the password page's window._IDK state, then the redirects back to the portal, skipping an optional marketing consent page. The host keeps the session cookies; each redirect is a separate request checked against allowed_hosts. A failed sign-in waits 15 minutes. A pasted cookie still works on older hosts. The SoC point's timestampUtc and the portal's Date header give the reading's age without a wall clock. The driver reports it as vehicle_soc_age_s, and a reading older than 20 minutes is not fresh. The channel builder accepts auth_post_paths (a list) next to auth_post_path, publishes it in signed metadata, and guards POST through host.http_request the same way as host.http_post. The host API profile lists http_request and http_cookies_clear. Paired with srcfl/ftw (host.http_request, auth_post_paths). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
Adding the guard to every read-only artifact changed the bytes of all of them, and the signed channel would have required a version bump for each. A driver gets the http_request guard only when its source calls host.http_request, and a single auth_post_path keeps its old guard, so only vag_vehicle's artifact changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
6aeb86a to
08b6391
Compare
A Core without auth_post_paths refuses a read-only driver that holds http.post but declares no auth_post_path, so beta installs on the current Core would lose the driver. The first path now sits in auth_post_path. That Core has no host.http_request, so the driver runs in cookie mode and never posts there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
Fixes #143.
Problem
The EU Data Act portal session lasts about an hour.
vag_vehicle0.1.1 needs the owner to paste a new Cookie header each time, so the car's SoC disappears every hour. The driver also had no clock, so it could not tell how old a reading was. After every restart it marked the first file stale, even when the reading was fresh.Change
Sign-in (needs srcfl/ftw#1505). With
emailandpasswordthe driver signs in throughidentity.vwgroup.io, following evcc'svehicle/vw/eudataact:emailPasswordFormidentifier form.window._IDKstate with patterns. No JavaScript runs.How it behaves:
host.http_requestthat Core checks againstallowed_hosts.login.errors.password_invalid) goes to the log; the password never does.http_request, a pastedcookieworks as before. Email and password alone log what is missing.Age. The SoC point's
timestampUtcis when the car measured it, and the portal'sDateheader is VW's time now. Their difference is the reading's age, reported asvehicle_soc_age_s.http_getreturns no headers.Metadata.
identity.vwgroup.iojoinshttp_hosts, so FTW setup fillsallowed_hostswith both hosts.passwordjoinsconfig_secrets.auth_post_pathslists the two form paths for each of the four brand client ids.allowed_hostslists only the portal get a log line telling them to add the identity host.Channel builder (
tools/ftw_repository.py).auth_post_pathsnext toauth_post_pathand validates each path.host.http_requestgets a guard for it too. GET passes, and POST passes only to a declared path. Drivers that do not call it, and a singleauth_post_path, keep their old guard, sovag_vehicleis the only published artifact that changes (check-versionsagainstdrivers-beta: changed[vag_vehicle]).Host API profile. Lists
http_requestandhttp_cookies_clear.Paired PR
srcfl/ftw#1505 adds
host.http_request, the cookie jar andauth_post_pathsto Core. Merge that first. This driver runs on an older Core in cookie mode, and the guard skipshttp_requestwhen the host lacks it.Validation
test_vag_vehicle_login.luaagainst a scripted VW sign-in and portal:Dateheader, growing on replayhttp_requestguard only invag_vehicle, andvag_vehicleadded to the sign-in exemptions.make check: 4808 passed, 923 skipped./signin-service/v1/<client>/login/identifier, Core refuses the POST and the log names the path.🤖 Generated with Claude Code