Nabu Kasa keeps ignoring the elephant in the room of security and permissions. They have no native ability to set user groups and permissions. There is no serious RBAC. I guess it doesn't sell cloud subscriptions. I cant keep my children from affecting devices they shouldn't. I ended up replacing my automation with mqtt
This is false.
<a href="https://developers.home-assistant.io/docs/auth_permissions/" rel="nofollow">https://developers.home-assistant.io/docs/auth_permissions/
I don't understand, why is it a joke? HA permissions are just to lock certain users or groups out of controlling certain things. You wouldn't be randomly giving out accounts to people you don't know or trust. It's the controls to your smarthome after all, not a shell account on an open sign-up server.
> HA permissions are just to lock certain users or groups out of controlling certain things
Yes, but only very coarsly granular things.
- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.
- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions
- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups
- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.
voidnullvalue · · focus · HN ↗
montjoy · · focus · HN ↗
hobofan · · focus · HN ↗
wildzzz · · focus · HN ↗
hobofan · · focus · HN ↗
Yes, but only very coarsly granular things.
- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.
- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions
- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups
- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.