Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
An asynchronous API client library for Remootio (http://www.remootio.com/)
aioremootio is an asynchronous API client library for Remootio written in Python 3 and based on asyncio and aiohttp.
With this client library is currently possible to listen to state changes of a Remootio device, to listen to some events triggered by it, furthermore to operate the gate or garage door connected to it.
This client library supports currently the listening to following kind of events triggered by the device:
STATE_CHANGE
which is triggered by the device when its state changesRELAY_TRIGGER
which is triggered by the device when its control output has been triggered to operate the
connected gate or garage doorLEFT_OPEN
which is triggered by the device when the connected gate or garage door has been left openRESTART
which is triggered by the device when it was restartedThe following example demonstrates how you can use this library.
from typing import NoReturn
import logging
import asyncio
import aiohttp
import aioremootio
class ExampleStateListener(aioremootio.Listener[aioremootio.StateChange]):
__logger: logging.Logger
def __init__(self, logger: logging.Logger):
self.__logger = logger
async def execute(self, client: aioremootio.RemootioClient, subject: aioremootio.StateChange) -> NoReturn:
self.__logger.info("State of the device has been changed. Host [%s] OldState [%s] NewState [%s]" %
(client.host, subject.old_state, subject.new_state))
async def main() -> NoReturn:
logger = logging.getLogger(__name__)
logger.setLevel(logging.INFO)
handler: logging.Handler = logging.StreamHandler()
handler.setFormatter(logging.Formatter(fmt="%(asctime)s [%(levelname)s] %(message)s"))
logger.addHandler(handler)
connection_options: aioremootio.ConnectionOptions = \
aioremootio.ConnectionOptions("192.168.0.1", "API_SECRET_KEY", "API_AUTH_KEY")
state_change_listener: aioremootio.Listener[aioremootio.StateChange] = ExampleStateListener(logger)
remootio_client: aioremootio.RemootioClient
async with aiohttp.ClientSession() as client_session:
try:
remootio_client = await aioremootio.RemootioClient(
connection_options,
client_session,
aioremootio.LoggerConfiguration(logger=logger),
[state_change_listener]
)
except aioremootio.RemootioClientConnectionEstablishmentError:
logger.exception("The client has failed to establish connection to the Remootio device.")
except aioremootio.RemootioClientAuthenticationError:
logger.exception("The client has failed to authenticate with the Remootio device.")
except aioremootio.RemootioError:
logger.exception("Failed to create client because of an error.")
else:
logger.info("State of the device: %s", remootio_client.state)
if remootio_client.state == aioremootio.State.NO_SENSOR_INSTALLED:
await remootio_client.trigger()
else:
await remootio_client.trigger_open()
await remootio_client.trigger_close()
while True:
await asyncio.sleep(0.1)
if __name__ == "__main__":
try:
asyncio.run(main())
except KeyboardInterrupt:
pass
To get the API Secret Key and API Auth Key of your Remootio device you must enable the API on it according to the Remootio Websocket API documentation.
The project source does also contain two examples.
The example example.py
demonstrates how you can
use the client as a Python object.
The example example_mc.py
demonstrates how you can
use the client as a Python object where it does not establish a connection to the Remootio device automatically
during its initialization.
The example example_acm.py
demonstrates how
you can use the client as an asynchronous context manager.
To run the bundled examples you must
/src
of the repository to your
PYTHONPATH
.After the two steps described above you can run the bundled examples with the argument --help
to show
the usage information. E.g.:
python example.py --help
To run the bundled tests you must create the .\remootio_device.configuration.json
file with a content according
to the following template.
{
"host": "IP-ADDRESS-OR-HOST-NAME-OF-YOUR-DEVICE",
"api_secret_key": "API-SECRET-KEY-OF-YOUR-DEVICE",
"api_auth_key": "API-AUTH-KEY-OF-YOUR-DEVICE",
"api_version": API-VERSION-OF-YOUR-DEVICE
}
Copyright © 2021 Gergö Gabor Ilyes-Veisz. Licensed under the Apache License, Version 2.0
FAQs
An asynchronous API client library for Remootio (http://www.remootio.com/)
We found that aioremootio demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.