Repository navigation
Implement V2 API authentication with HMAC-SHA1 signing - #101
Merged
Merged
Conversation
Migrate from the deprecated V1 API to the V2 API protocol used by the current Kasa Android app. The V2 API requires HMAC-SHA1 request signing on all requests and uses a different login flow with regional URL discovery. New modules: - signing.py: HMAC-SHA1 request signing (AccessKey/SecretKey from APK) - exceptions.py: TPLinkAuthError, TPLinkMFARequiredError, TPLinkTokenExpiredError, TPLinkDeviceOfflineError - certs/: Bundled TP-Link private CA chain for SSL verification Changes: - client.py: V2 login flow (regional URL discovery -> login), MFA callback support, refresh token support, signed requests - device_client.py: HMAC signing + SSL with TP-Link CA on all device passthrough requests - device_manager.py: MFA callback parameter, refresh token storage, automatic token refresh on expiry - api_response.py: Added error_code and msg properties - __init__.py: Export new exception classes - setup.py: Bundle certs as package data, require Python 3.10+ Device operations still use V1 JSON format (method/params wrapper) on the root path, but with V2 signing headers and query parameters. Closes #83, closes #84, closes #85, closes #86, closes #87, closes #88, closes #96
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Migrates from the deprecated V1 cloud API to the V2 API protocol used by the current Kasa Android app (v3.4.451). This is the core auth infrastructure for v5.0.
New modules:
signing.py- HMAC-SHA1 request signing using AccessKey/SecretKey extracted from the Kasa APKexceptions.py- Custom exception hierarchy:TPLinkCloudError,TPLinkAuthError,TPLinkMFARequiredError,TPLinkTokenExpiredError,TPLinkDeviceOfflineErrorcerts/- Bundled TP-Link private CA certificate chain for SSL verification with V2 API serversUpdated modules:
client.py- V2 login flow with regional URL discovery, MFA callback support, refresh token management, HMAC-signed requestsdevice_client.py- HMAC signing and TP-Link CA SSL on all device passthrough requestsdevice_manager.py- Newmfa_callbackparameter, refresh token storage/retrieval, automatic token refresh on expiryapi_response.py- Addederror_codeandmsgproperties__init__.py- Export new exception classessetup.py- Bundle certs as package data, require Python 3.10+Key technical details:
getAccountStatusAndUrl→ regional URL →login(flat JSON body, no method/params wrapper){"method": "passthrough", ...}) on root path, but with V2 signing headersX-Authorizationheader andContent-MD5headerVerified working end-to-end against the live TP-Link API:
Closes #83, #84, #85, #86, #87, #88, #96
Test plan
n-use1-wap.tplinkcloud.com)