Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 34 additions & 21 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

Display HA dashboards in kiosk mode directly on your HAOS server.

## Author: Jeff Kosowsky (version: 1.3.0, February 2026)
## Author: Jeff Kosowsky (version: 1.3.1, April 2026)

## Description

Expand Down Expand Up @@ -42,7 +42,7 @@ please file an
\*\*include full details of your setup (including computer hardware and
display type details)and what you did along with a complete log.

You can also use the `screenshot` REST API or keybinding (`Ctl+Alt+k`) or
Note you can use the `screenshot` REST API or keybinding (`Ctl+Alt+k`) or
touch gesture (Quadruple 3 finger tap) to save a screenshot to
`/media/screenshots`

Expand Down Expand Up @@ -74,19 +74,11 @@ ______________________________________________________________________
4. Press **Start** to run the Add-on.

**If you are having trouble installing the add-on or getting displays and
touchscreens working, please see the github issues page
(https://github.com/puterboy/HAOS-kiosk/issues)as many common issues have
touchscreens working, please see the **TROUBLESHOOTING** section below as
well as the github issues page
(https://github.com/puterboy/HAOS-kiosk/issues) as many common issues have
already been addressed and resolved**

### Notes

- If screen is not working on an RPi3, try adding the following lines to
the `[pi3]` section of your `config.txt` on the boot partition:
```
dtoverlay=vc4-fkms-v3d
max_framebuffers=2
```

______________________________________________________________________

## Configuration Options
Expand Down Expand Up @@ -263,11 +255,16 @@ examples, and default gestures.

### Command Whitelist Regex

Regex (Python) of shell command that can be used in creating gesture action
commands or when running the `run_command` and `run_commands` REST APIs.
Regex (Python) of shell commands that can be used in creating gesture
action commands or when running the `run_command` and `run_commands` REST
APIs.

If left blank, then all commands are allowed except for those blacklisted
as dangerous (otherwise, whitelist overrides internal blacklist).
If only base name given, then path is assumed to be:
`PATH=/bin:/usr/bin/:/usr/local/bin`

If left blank, then all commands in `$PATH` are allowed except for those
blacklisted as dangerous (otherwise, whitelist overrides path restrictions
and internal blacklist).

The pre-defined command blacklist includes commands like:

Expand All @@ -279,16 +276,13 @@ The pre-defined command blacklist includes commands like:
cp, chmod, chown, dd, ln, mv, rm, tar
mount, umount
curl, nc, wget
find, xargs"
find, xargs
```

Note that if you want to truly allow *all* commands, then use the wildcard
`.*` but beware that it is DANGEROUS. If you want to disallow all commands
set the regex to `^$`.

Note that regardless of setting only commands found in `/bin`, `/usr/bin`,
and `/usr/local/bin` of the HAOSKiosk Add-on container are allowed.

### VNC SERVER

Launch VNC Server on port 5900 if password non-blank. If password set to
Expand Down Expand Up @@ -983,3 +977,22 @@ Luakit modes and commands are similar to vi

See [luakit documentation](https://wiki.archlinux.org/title/Luakit) for
further usage information and available commands.

______________________________________________________________________

## TROUBLESHOOTING

- If the display is not working on an RPi3, try adding the following lines
to the `[pi3]` section of your `config.txt` on the boot partition:

```
dtoverlay=vc4-fkms-v3d
max_framebuffers=2
```

- If you see black borders (underscan) around the display on a Raspberry Pi
you can disable overscan in `config.txt` on the boot partition:

```
disable_overscan=1
```
5 changes: 5 additions & 0 deletions haoskiosk/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# Changelog

## v1.3.1 - April 2026

- Updated auto-login JS injection in 'userconf.lua' for 2026.4+
- Fixed whitelist logic to allow commands outside of default path

## v1.3.0 - February 2026

- Added more key bindings for opening/closing/rotating tabs and windows
Expand Down
4 changes: 2 additions & 2 deletions haoskiosk/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
################################################################################
# Add-on: HAOS Kiosk Display (haoskiosk)
# File: Dockerfile
# Version: 1.3.0
# Version: 1.3.1
# Copyright Jeff Kosowsky
# Date: February 2026
# Date: April 2026
################################################################################

ARG BUILD_FROM
Expand Down
55 changes: 34 additions & 21 deletions haoskiosk/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

Display HA dashboards in kiosk mode directly on your HAOS server.

## Author: Jeff Kosowsky (version: 1.3.0, February 2026)
## Author: Jeff Kosowsky (version: 1.3.1, April 2026)

## Description

Expand Down Expand Up @@ -42,7 +42,7 @@ please file an
\*\*include full details of your setup (including computer hardware and
display type details)and what you did along with a complete log.

You can also use the `screenshot` REST API or keybinding (`Ctl+Alt+k`) or
Note you can use the `screenshot` REST API or keybinding (`Ctl+Alt+k`) or
touch gesture (Quadruple 3 finger tap) to save a screenshot to
`/media/screenshots`

Expand Down Expand Up @@ -74,19 +74,11 @@ ______________________________________________________________________
4. Press **Start** to run the Add-on.

**If you are having trouble installing the add-on or getting displays and
touchscreens working, please see the github issues page
(https://github.com/puterboy/HAOS-kiosk/issues)as many common issues have
touchscreens working, please see the **TROUBLESHOOTING** section below as
well as the github issues page
(https://github.com/puterboy/HAOS-kiosk/issues) as many common issues have
already been addressed and resolved**

### Notes

- If screen is not working on an RPi3, try adding the following lines to
the `[pi3]` section of your `config.txt` on the boot partition:
```
dtoverlay=vc4-fkms-v3d
max_framebuffers=2
```

______________________________________________________________________

## Configuration Options
Expand Down Expand Up @@ -263,11 +255,16 @@ examples, and default gestures.

### Command Whitelist Regex

Regex (Python) of shell command that can be used in creating gesture action
commands or when running the `run_command` and `run_commands` REST APIs.
Regex (Python) of shell commands that can be used in creating gesture
action commands or when running the `run_command` and `run_commands` REST
APIs.

If left blank, then all commands are allowed except for those blacklisted
as dangerous (otherwise, whitelist overrides internal blacklist).
If only base name given, then path is assumed to be:
`PATH=/bin:/usr/bin/:/usr/local/bin`

If left blank, then all commands in `$PATH` are allowed except for those
blacklisted as dangerous (otherwise, whitelist overrides path restrictions
and internal blacklist).

The pre-defined command blacklist includes commands like:

Expand All @@ -279,16 +276,13 @@ The pre-defined command blacklist includes commands like:
cp, chmod, chown, dd, ln, mv, rm, tar
mount, umount
curl, nc, wget
find, xargs"
find, xargs
```

Note that if you want to truly allow *all* commands, then use the wildcard
`.*` but beware that it is DANGEROUS. If you want to disallow all commands
set the regex to `^$`.

Note that regardless of setting only commands found in `/bin`, `/usr/bin`,
and `/usr/local/bin` of the HAOSKiosk Add-on container are allowed.

### VNC SERVER

Launch VNC Server on port 5900 if password non-blank. If password set to
Expand Down Expand Up @@ -983,3 +977,22 @@ Luakit modes and commands are similar to vi

See [luakit documentation](https://wiki.archlinux.org/title/Luakit) for
further usage information and available commands.

______________________________________________________________________

## TROUBLESHOOTING

- If the display is not working on an RPi3, try adding the following lines
to the `[pi3]` section of your `config.txt` on the boot partition:

```
dtoverlay=vc4-fkms-v3d
max_framebuffers=2
```

- If you see black borders (underscan) around the display on a Raspberry Pi
you can disable overscan in `config.txt` on the boot partition:

```
disable_overscan=1
```
3 changes: 2 additions & 1 deletion haoskiosk/config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,9 @@ name: "HAOS Kiosk Display"
description: |
Start X server and browser on local HAOS server and display dashboards in
kiosk mode (Jeff Kosowsky)
version: "1.3.0"
version: "1.3.1"
slug: "haoskiosk"
url: https://github.com/puterboy/HAOS-kiosk/tree/main/haoskiosk

arch:
- aarch64
Expand Down
4 changes: 2 additions & 2 deletions haoskiosk/gesture_commands.json
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
# ==============================================================================
# HAOS Kiosk Display — Mouse & Touch Input Engine
# File: gesture_commands.json
# Version: 1.3.0
# Version: 1.3.1
# Copyright Jeff Kosowsky
# Date: February 2026
# Date: April 2026
# ------------------------------------------------------------------------------
# USER CUSTOMIZABLE GESTURES — loaded BEFORE built-in
# defaults in CMD_DICTand thus have higher precedence since
Expand Down
31 changes: 16 additions & 15 deletions haoskiosk/mouse_touch_inputs.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@
"""-------------------------------------------------------------------------------
# HAOS Kiosk Display — Mouse & Touch Input Engine
# File: MouseTouchInputs
# Version: 1.3.0
# Version: 1.3.1
# Copyright Jeff Kosowsky
# Date: February 2026
# Date: April 2026
#
#### DESCRIPTION:
Full-featured X11 parser and command launcher for multi-button press and
Expand Down Expand Up @@ -250,8 +250,8 @@
Each command string/list is validated to make sure that all programs mentioned are
allowed (using function is_command_allowed). Specifically, unless ALLOW_ALL_USER_COMMANDS
is True, the programs are tested to ensure:
- Program exists within ALLOWED_PATH
- Program is white-listed (if COMMAND_WHITELIST_REGEX is not None)
- Program exists within ALLOWED_PATH
- Program is not black-listed (note whitelist when set overrides blacklist)

When a gesture sequence is generated, the GESTURE_CMDS_LIST is used to find the
Expand Down Expand Up @@ -342,7 +342,6 @@
#-------------------------------------------------------------------------------
### MYTODOS:
- Add arbitrary positions
- Test
#-------------------------------------------------------------------------------

"""
Expand Down Expand Up @@ -370,9 +369,9 @@
from Xlib import display #type: ignore[import-untyped] #pylint: disable=import-error
from Xlib.xobject.drawable import Window #type: ignore[import-untyped] #pylint: disable=import-error
#-------------------------------------------------------------------------------
__version__ = "1.3.0"
__version__ = "1.3.1"
__author__ = "Jeff Kosowsky"
__copyright__ = "Copyright 2025 Jeff Kosowsky"
__copyright__ = "Copyright 2025-2026 Jeff Kosowsky"
#-------------------------------------------------------------------------------
#### User Configuration

Expand Down Expand Up @@ -465,6 +464,7 @@ def debug(level: int, msg: str) -> None:

## Restrict paths to specific, non-system bins
ALLOWED_PATHS = {"/bin", "/usr/bin", "/usr/local/bin"} # Executables must be in these directoriesp
ALLOWED_PATHS_STR = ":".join(ALLOWED_PATHS)

## Commands that are white-listed -- all others are blocked (Note: set to ".*" to allow all or "" to block all)
DEFAULT_COMMAND_WHITELIST_REGEX = r"cat|date|dbus-send|echo|false|grep|head|ls|luakit|notify-send|ping|ping6|ps|pstree|sleep|tail|test|top|tree|xdotool|xset"
Expand Down Expand Up @@ -1761,14 +1761,15 @@ def _parse_command_value(value: Any) -> CommandsDict:
Returns the corresponding CommandsDict object with "cmds" and "execs" plus the optional "msg" and "timeout" keys.
Raise an exception if:
- Not a valid raw command object (i.e. not a CommandsType or CommandsDict)
- Command is blacklisted or not whitelisted (and ALLOW_ALL_USER_COMMANDS is False)
- Command is not whitelisted (and ALLOW_ALL_USER_COMMANDS is False) or path disallowed or not whitelisted
"""

def is_path_allowed(prog_path: str) -> bool:
"""Return True if binary is in an allowed directory."""
try:
real_path = os.path.realpath(prog_path)
return any(real_path.startswith(allowed + "/") for allowed in ALLOWED_PATHS)
parent_dir = os.path.dirname(real_path)
return parent_dir in ALLOWED_PATHS
except Exception:
return False

Expand Down Expand Up @@ -1800,21 +1801,21 @@ def is_command_allowed(command_str: str) -> tuple[bool, str]: #pylint: disable=

for prog in programs:
# 1. Program not found
prog_path = shutil.which(prog) or ""
prog_path = shutil.which(prog, path=ALLOWED_PATHS_STR) or ""
if not prog_path:
return False, f"Program not found: {prog}"

# 2. PATH restriction
if not is_path_allowed(prog_path):
return False, f"Program not in allowed paths: {prog_path}"

# 3. Whitelist — Allow if whitelisted; deny if not
# Note whitelist overrides blacklist if set
# 2. Whitelist — Allow if whitelisted; deny if not
# Note whitelist overrides blacklist and PATH restriction if set
if COMPILED_WHITELIST_REGEX is not None:
if not COMPILED_WHITELIST_REGEX.fullmatch(prog):
return False, f"Program not in Whitelist: {prog}"
continue

# 2. PATH restriction
if not is_path_allowed(prog_path):
return False, f"Program not in allowed paths: {prog_path}"

# 4. Blacklist — Deny if blacklisted
if COMPILED_BLACKLIST_REGEX.fullmatch(prog):
return False, f"Blacklisted program: {prog}"
Expand Down
Loading
Loading