home-assistant: a new MQTT entry says plain MQTT for its certificate choices

Home Assistant's MQTT user flow shows no value for set_ca_cert and set_client_cert (a reconfigure
pre-fills them from the entry), and refuses a submit without them — found against the pinned
2026.9.3 in a throwaway instance.
This commit is contained in:
2026-09-30 13:11:40 +02:00
parent 31af3f0ecc
commit 1e34ecc16b
2 changed files with 11 additions and 4 deletions
@@ -246,8 +246,15 @@ async function createEntry(deps: MqttDeps, want: MqttWanted, note?: string): Pro
if (flow.type !== "form" || !flow.flow_id) {
return { what, result: "refused", problem: `Home Assistant's MQTT user flow answered ${describe(flow)}` };
}
const shown = formValues(flow.data_schema);
// A new entry's form has no value for its two certificate choices (a reconfigure pre-fills them
// from the entry): plain MQTT, so neither a CA nor a client certificate.
const other = (shown.other_settings ?? {}) as Record<string, unknown>;
if (flow.data_schema?.some((f) => f.name === "other_settings")) {
shown.other_settings = { set_ca_cert: "off", set_client_cert: false, ...other };
}
flow = await deps.hass.stepFlow(flow.flow_id, {
...formValues(flow.data_schema),
...shown,
broker: want.host,
port: want.port,
username: want.username,
@@ -33,7 +33,7 @@ function brokerForm(data: Record<string, unknown>): SchemaField[] {
{ name: "username", type: "string", optional: true, description: { suggested_value: data.username } },
{ name: "password", type: "string", optional: true, description: { suggested_value: data.password ? PWD_NOT_CHANGED : undefined } },
{
name: "advanced_options",
name: "other_settings",
type: "expandable",
required: true,
schema: [
@@ -161,7 +161,7 @@ test("mqtt: ace's entry (127.0.0.1, luffy) is moved to the bound broker and logi
assert.deepEqual(out, { what: "mqtt", result: "written", fields: ["broker", "username", "password"] });
assert.deepEqual(f.entries.mqtt[0].data, {
broker: "ace.internal", port: 1883, protocol: "5", username: "mesh_ace_hass", password: MINTED,
advanced_options: { keepalive: 60, transport: "tcp", set_ca_cert: "off", set_client_cert: false },
other_settings: { keepalive: 60, transport: "tcp", set_ca_cert: "off", set_client_cert: false },
});
assert.ok(marks.store.get("mqtt"));
assert.ok(![...marks.store.values()].some((v) => v.includes(MINTED)));
@@ -285,7 +285,7 @@ test("servarr: a reauth Home Assistant started is finished with the bound URL an
test("form values: suggested first, then default, sections nested", () => {
assert.deepEqual(formValues(brokerForm({ broker: "b", port: 1, protocol: "5", username: "u", password: "p" })), {
broker: "b", port: 1, protocol: "5", username: "u", password: PWD_NOT_CHANGED,
advanced_options: { keepalive: 60, transport: "tcp", set_ca_cert: "off", set_client_cert: false },
other_settings: { keepalive: 60, transport: "tcp", set_ca_cert: "off", set_client_cert: false },
});
assert.ok(sameUrl("http://ace.internal:8989/", "http://ace.internal:8989"));
assert.ok(sameUrl("http://ACE.internal", "http://ace.internal:80"));