Files
python-kasa/kasa/transports
nopoz 53823ea9a5 Do not authenticate with a credentials_hash from a different transport (#1749)
A `credentials_hash` is specific to the transport that produced it, but
nothing checked that the hash a transport was handed was its own.

This matters because a device can change its encryption type without the
credentials changing. For example, toggling **Third-Party Compatibility** in the Tapo
app moves a plug or strip between TPAP and KLAP, and firmware updates are known to introduce new transports.

This introduces a per-transport check that the hash has the shape that transport produces, and treats a foreign hash as absent rather than as a bad password. This makes the failure honest but still ends in a reauth.

This also changes how credentials are read back out when the hash is one of the plaintext forms and lets the transport derive its own, so the change of encryption type needs no reauth in all cases.
2026-10-04 15:30:01 +02:00
..