Repository navigation
Daily email report of slowdowns and dropouts - #2
Merged
Merged
Conversation
Devices outside any eero profile report the profile name 'Unassigned', which showed up in explanations as if it were a person. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Dashboard card: recipients, sending account, app password, daily on/off, Send report now, and Preview report. - Sent once a day at startup (or 8 AM if already running) through the user's own SMTP account, TLS only. The password is DPAPI-encrypted and never returned by the API. - send-report CLI (with --preview). - Dashboard server now only answers Host 127.0.0.1/localhost (blocks DNS rebinding), and every POST needs the X-HogWatch header. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A daily email report of every slowdown and dropout, with its reason, the game that was running, and who was busy on the network at the time.
data/email.json(gitignored), so only that Windows account can read it. The API never returns it; it only reports whether one is saved.python -m hogwatch send-report [--hours N] [--preview]Security
The dashboard holds email settings now, so it's locked down further:
Hostis127.0.0.1:<port>orlocalhost:<port>. This blocks DNS-rebinding pages from reading the API.X-HogWatch: 1header, which cross-site pages can't send without a CORS preflight (never approved). A random web page can't change the recipient or trigger emails.Testing
tests/test_report.py: DPAPI storage, the password never appearing in API responses, Host and header enforcement, HTML escaping, report counts and advice, SMTP flows (smtplib mocked), and daily scheduling. 51/51 pass locally.Note: this repo's CI workflow is added in #1. This PR won't have its
testcheck until #1 is merged andmainis merged into this branch.🤖 Generated with Claude Code