Repository navigation
Do not authenticate with a credentials_hash from a different transport #1749
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
rytilahti
merged 3 commits into
python-kasa:master
from
nopoz:feature/credentials-hash-transport-mismatch
Oct 4, 2026
Merged
Changes from 1 commit
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next
Next commit
Ignore a credentials_hash produced by a different transport
A credentials_hash is specific to the transport that made it. Klap stores the base64 of a raw digest, aes and ssltransport store base64 json of hashed credentials, and sslaestransport stores base64 json of the plaintext. Nothing checked that the hash a transport was handed was its own. A device can change its encryption type without the credentials changing. Toggling Third-Party Compatibility on a Tapo device moves it between tpap and klap, and discovery then hands the transport a stored hash the other transport wrote. Klap decodes any base64 successfully, so it built _local_auth_hash out of another transport's json and failed handshake1, reporting "Device response did not match our challenge". Callers cannot tell that from a wrong password; Home Assistant acts on it by deleting the stored hash and asking the user to reauthenticate. aestransport and ssltransport are worse and raise UnicodeDecodeError from the constructor, and sslaestransport raises KeyError. Check the hash has the shape the transport produces and treat a foreign one as absent instead.
- Loading branch information
commit da1e72587f54225899c946794a7d441b8932cba1
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,121 @@ | ||
| """Tests for credentials_hash handling across transports. | ||
|
|
||
| A credentials_hash is transport specific. Devices can change their encryption | ||
| type without the credentials changing, for example when Third-Party | ||
| Compatibility is toggled on a Tapo device, so a transport can be handed a hash | ||
| that a different transport produced. It must not treat that as a bad password. | ||
| """ | ||
|
|
||
| from __future__ import annotations | ||
|
|
||
| import base64 | ||
|
|
||
| import pytest | ||
|
|
||
| from kasa.credentials import Credentials | ||
| from kasa.deviceconfig import DeviceConfig | ||
| from kasa.json import dumps as json_dumps | ||
| from kasa.transports.aestransport import AesTransport | ||
| from kasa.transports.klaptransport import KlapTransportV2 | ||
| from kasa.transports.sslaestransport import SslAesTransport | ||
| from kasa.transports.ssltransport import SslTransport | ||
|
|
||
| pytestmark = [pytest.mark.requires_dummy] | ||
|
|
||
| CREDENTIALS = Credentials("user@example.com", "great_password") | ||
|
|
||
|
|
||
| def klap_hash(credentials: Credentials) -> str: | ||
| """Build a KLAP v2 credentials_hash: base64 of a raw sha256 digest.""" | ||
| return base64.b64encode(KlapTransportV2.generate_auth_hash(credentials)).decode() | ||
|
|
||
|
|
||
| def aes_hash(credentials: Credentials) -> str: | ||
| """Build an AES credentials_hash: base64 json of sha1'd credentials.""" | ||
| un, pw = AesTransport.hash_credentials(True, credentials) | ||
| return base64.b64encode( | ||
| json_dumps({"password2": pw, "username": un}).encode() | ||
| ).decode() | ||
|
|
||
|
|
||
| def plaintext_hash(credentials: Credentials) -> str: | ||
| """Build a TPAP or SSL-AES credentials_hash: base64 json of plaintext.""" | ||
| return base64.b64encode( | ||
| json_dumps({"un": credentials.username, "pwd": credentials.password}).encode() | ||
| ).decode() | ||
|
|
||
|
|
||
| async def test_klap_ignores_an_aes_credentials_hash(): | ||
| """KLAP must not build an auth hash out of another transport's hash.""" | ||
| transport = KlapTransportV2( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=aes_hash(CREDENTIALS)) | ||
| ) | ||
|
|
||
| assert transport._local_auth_hash == KlapTransportV2.generate_auth_hash( | ||
| Credentials() | ||
| ) | ||
| assert transport.credentials_hash is None | ||
|
|
||
|
|
||
| async def test_aes_ignores_a_klap_credentials_hash(): | ||
| """AES must not crash or authenticate on another transport's hash.""" | ||
| transport = AesTransport( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=klap_hash(CREDENTIALS)) | ||
| ) | ||
|
|
||
| assert transport._login_params == AesTransport._get_login_params( | ||
| transport, Credentials() | ||
| ) | ||
| assert transport.credentials_hash is None | ||
|
|
||
|
|
||
| async def test_klap_keeps_its_own_credentials_hash(): | ||
| """A hash the transport itself produced is still used.""" | ||
| credentials_hash = klap_hash(CREDENTIALS) | ||
| transport = KlapTransportV2( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=credentials_hash) | ||
| ) | ||
|
|
||
| assert transport.credentials_hash == credentials_hash | ||
|
|
||
|
|
||
| async def test_aes_keeps_its_own_credentials_hash(): | ||
| """A hash the transport itself produced is still used.""" | ||
| credentials_hash = aes_hash(CREDENTIALS) | ||
| transport = AesTransport( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=credentials_hash) | ||
| ) | ||
|
|
||
| assert transport.credentials_hash == credentials_hash | ||
|
|
||
|
|
||
| async def test_sslaes_ignores_a_klap_credentials_hash(): | ||
| """SSL-AES must not crash on another transport's hash.""" | ||
| transport = SslAesTransport( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=klap_hash(CREDENTIALS)) | ||
| ) | ||
|
|
||
| assert transport._username is None | ||
| assert transport._password is None | ||
| assert transport.credentials_hash is None | ||
|
|
||
|
|
||
| async def test_sslaes_keeps_its_own_credentials_hash(): | ||
| """A hash the transport itself produced is still used.""" | ||
| credentials_hash = plaintext_hash(CREDENTIALS) | ||
| transport = SslAesTransport( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=credentials_hash) | ||
| ) | ||
|
|
||
| assert transport.credentials_hash == credentials_hash | ||
|
|
||
|
|
||
| async def test_ssl_ignores_a_klap_credentials_hash(): | ||
| """The ssl transport must not crash on another transport's hash.""" | ||
| transport = SslTransport( | ||
| config=DeviceConfig("127.0.0.1", credentials_hash=klap_hash(CREDENTIALS)) | ||
| ) | ||
|
|
||
| assert transport._login_params == SslTransport._get_login_params( | ||
| transport, Credentials() | ||
| ) |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.