Repository navigation
Keep household members' names in the home (#20) - #71
Merged
Merged
Conversation
Every snapshot and command reply now leaves through one filter in cloud_link: each household name, wherever it appears, becomes a stable id (hm_ + 10 hex, an HMAC under a secret kept in .storage and never sent). Inbound commands have the ids turned back into names, so a dashboard tile for person.hm_... is saved with the real person, and a Live Activity to notify.mobile_app_hm_..._iphone reaches the right phone. Whose names: everyone My Home counts, by display name and username, and every person entity except those linked to Dartec's, a panel's or Home Assistant's own accounts. Matched word by word, as HA slugs them, with a possessive s; Arabic names as Arabic words. Generic words are never matched. If the names cannot be read, the snapshot carries the core section only and commands are refused, rather than leaking. The snapshot is marked privacy.version 1, so the manager knows it may send ids to this home. Not released: intended for the next release. The live household test's name check had a literal backspace where a regex word boundary was meant, so it had never matched anything. It now fails on any name anywhere in the snapshot, and requires the people as ids.
The rig's customer is called "Live test", like the owner the rig onboards, so the integration title is sent as "Dartec: hm_... / Integration rig". Check the brand's spelling and the retitle, not the name.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #20. Intended for the next release. No version bump and no release in this PR; the manifest stays at 0.21.2 and the manager's companion change handles agents until they update.
What changes
The owner's decision (2026-09-27): send no person names, no person entities' friendly names and no log lines that carry them; where the manager needs to know something, send a count or a stable anonymous id.
Rather than cut each path out (which would break person tiles on family dashboards, Live Activities to phones and the Users tab, and miss the next path), the rule sits at the agent's only door to the manager,
cloud_link.py:privacy.Pseudonymiser.scrub. Each household name, anywhere in any string or key, becomes a stable id: "Layla's iPhone" →hm_3f2a91c07d's iPhone,person.omar→person.hm_8c1e0b44a2,mobile_app_laylas_iphone→mobile_app_hm_…_iphone, and the same in log lines, rooms, automations and theusers_listreply.reveal, which turns the home's own ids back into names, as an entity id or as written depending on where they sit. Ids the home did not issue, andtoken/passwordfields, are left alone..storage/dartec_ha_manager.privacy) and never sent, so the manager cannot hash a list of first names back to a person.person.*entity except those linked to Dartec's, panel or system accounts. Matched word by word (3+ letters), as HA slugs them, with a possessive "s"; Arabic names as Arabic words (عمر is hidden, عمرو is not). Generic words (home, admin, bin, …) are never matched.coreand commands are refused withprivacy_unavailable. The home stays online.privacy: {"version": 1}; the inventory digest is folded with the names so the manager refetches when they change, and a reply is scrubbed once, before and after names merged, so its digest still matches.The limit: a name the home does not know (a phone named after someone with no person or account) is not hidden.
Tests
tests/test_privacy.py: 20 claims over a synthetic Arabic- and English-speaking household (Maryam Al Hashimi, Omar, Layla, ليلى, عمر الهاشمي, a renamed child): no spelling of any name anywhere in a scrubbed snapshot orusers_listreply; ids stable, keyed per home and consistent between prose and ids; dashboards, notify actions and every snapshot id reveal back to the home's real ones; staff/panel accounts, عمرو, "Next dawn" and hex ids untouched; generic words and short names handled.tests/live/run_live_household.pynow fails on any name anywhere in the snapshot and requires both people asperson.hm_…. The check it replaces had a literal backspace character where a regex word boundary was meant, so it had never matched anything.tests/live/run_live.pycounts the owner's person as an id in the inventory check.Run locally: unit suite 868 passed; hassfest clean;
run_live.py2026.9.3 passed;run_live_household.pypassed on 2026.9.3 and 2026.8.3. No bench or real home was touched.Companion manager PR: cleans older agents' snapshots on arrival, refuses ids to agents that cannot resolve them, and purges names already stored (kaboomAE/dartec-ha-manager-server).
🤖 Generated with Claude Code