Move the authenticated drift check into the repository as
tools/compat_auth.py, run daily by .github/workflows/compat-auth.yml on the
maintainer's forge only. Credentials come from FH_EMAIL and FH_PASSWORD, the
output is pass/fail labels only because the run log is public, and a failed
run pushes the report to ntfy. Exit 5 means all hold, 10 drift, anything
else that it could not run.
Point compat.yml, tools/compat.py and the docs at it, add a README section,
and cut 0.5.1.
Both jobs fail on the Gitea mirror for reasons no secret or input changes.
hassfest is a Docker-container action that bind-mounts $GITHUB_WORKSPACE. The
Gitea runner runs the job inside a container against a separate docker-in-docker
daemon, so the path resolves on the daemon's filesystem, not the job's; docker
creates an empty directory and mounts that, and hassfest then accurately reports
that it found no integrations in the empty tree it was given. It takes no token,
so credentials were never the issue.
HACS asks the github.com API about github.repository, which on Gitea is
flan/ha-freshharvest -- a slug that exists only on Gitea. That is the 401. The
action has no input to point the lookup at the sudolulo mirror.
The same commit that fails here passes on github.com/sudolulo/ha-freshharvest,
which mirrors every push, so the validation still happens -- it just happens
where it is capable of running. The guard is "not Gitea" rather than "is
GitHub" so an unexpected server_url runs the checks instead of dropping them.
pytest is untouched and still gates every push on both forges.
The compat badge was red on bookkeeping, not on compatibility: the check passed
16/16 and the run then failed trying to commit the refreshed matrix and open a
PR. That step should never have existed here — GitHub is a read-only mirror of
Gitea, so anything a bot pushes is clobbered by the next sync. It now publishes
the matrix to the run summary and the workflow only needs contents:read, so the
badge means what it says.
The README had grown into an implementation document. Endpoints, markup traps,
the login handshake and the drift-detection design move to docs/internals.md;
what is left is installation, entities, events, the dashboard, requirements and
troubleshooting.
pytest could not even collect: actions.py imports yarl for URL joining, which
Home Assistant ships but a bare CI python does not. The suite passed locally
only because the venv had picked it up as a transitive dependency.
The HACS check wants repository topics, which are GitHub-side metadata and so
cannot come from the canonical Gitea repo; set on the mirror directly.
actions.py covers skip, donate, cart add/remove, subscriptions and vacation
holds. Every mutating endpoint on the site is guarded by rotating per-render
tokens, so each action re-derives them from a live page rather than storing
anything; skip additionally compares the date the server states in its
confirmation against the date it was asked to skip, and refuses on a mismatch.
All actions default to dry_run.
tools/compat.py records what the integration assumes about a site that offers
no API and no stability contract, and CI asserts it daily. Only the
unauthenticated surface is covered: checking the rest would mean putting a
personal account password in public repo secrets.
Each cost line is now an entity rather than an attribute: subtotal, box price,
add-ons, tax and delivery fee, plus a total and free-delivery-remaining for the
open order, a delivery-day sensor, and a binary sensor that turns off at the
cutoff. Entities share a base class and declare a scope, so a description
states only the field it reads.
Also parses the driver tip, Bounty savings and the free-delivery threshold. The
threshold is carried across orders because the progress bar only renders on
carts that have not met it.
Adds LICENSE, hacs.json, a CI workflow, a pre-publish audit script, and a test
that cross-checks every entity's translation_key against both translation
files. Manifest URLs now point at GitHub rather than a private forge.