2 * Copyright (c) 2010-2023 Contributors to the openHAB project
4 * See the NOTICE file(s) distributed with this work for additional
7 * This program and the accompanying materials are made available under the
8 * terms of the Eclipse Public License 2.0 which is available at
9 * http://www.eclipse.org/legal/epl-2.0
11 * SPDX-License-Identifier: EPL-2.0
13 package org.openhab.binding.shelly.internal.api;
15 import static org.openhab.binding.shelly.internal.ShellyBindingConstants.SHELLY_API_TIMEOUT_MS;
16 import static org.openhab.binding.shelly.internal.api1.Shelly1ApiJsonDTO.*;
17 import static org.openhab.binding.shelly.internal.api2.Shelly2ApiJsonDTO.*;
18 import static org.openhab.binding.shelly.internal.util.ShellyUtils.*;
20 import java.nio.charset.StandardCharsets;
21 import java.text.MessageFormat;
22 import java.util.Base64;
24 import java.util.concurrent.ExecutionException;
25 import java.util.concurrent.TimeUnit;
26 import java.util.concurrent.TimeoutException;
28 import javax.ws.rs.core.HttpHeaders;
30 import org.eclipse.jdt.annotation.NonNullByDefault;
31 import org.eclipse.jdt.annotation.Nullable;
32 import org.eclipse.jetty.client.HttpClient;
33 import org.eclipse.jetty.client.api.ContentResponse;
34 import org.eclipse.jetty.client.api.Request;
35 import org.eclipse.jetty.client.util.StringContentProvider;
36 import org.eclipse.jetty.http.HttpFields;
37 import org.eclipse.jetty.http.HttpHeader;
38 import org.eclipse.jetty.http.HttpMethod;
39 import org.eclipse.jetty.http.HttpStatus;
40 import org.openhab.binding.shelly.internal.api2.Shelly2ApiJsonDTO.Shelly2AuthChallenge;
41 import org.openhab.binding.shelly.internal.api2.Shelly2ApiJsonDTO.Shelly2AuthRsp;
42 import org.openhab.binding.shelly.internal.api2.Shelly2ApiJsonDTO.Shelly2RpcBaseMessage;
43 import org.openhab.binding.shelly.internal.config.ShellyThingConfiguration;
44 import org.openhab.binding.shelly.internal.handler.ShellyThingInterface;
45 import org.slf4j.Logger;
46 import org.slf4j.LoggerFactory;
48 import com.google.gson.Gson;
51 * {@link ShellyHttpClient} implements basic HTTP access
53 * @author Markus Michels - Initial contribution
56 public class ShellyHttpClient {
57 private final Logger logger = LoggerFactory.getLogger(ShellyHttpClient.class);
59 public static final String HTTP_HEADER_AUTH = HttpHeaders.AUTHORIZATION;
60 public static final String HTTP_AUTH_TYPE_BASIC = "Basic";
61 public static final String HTTP_AUTH_TYPE_DIGEST = "Digest";
62 public static final String CONTENT_TYPE_JSON = "application/json; charset=UTF-8";
63 public static final String CONTENT_TYPE_FORM_URLENC = "application/x-www-form-urlencoded";
65 protected final HttpClient httpClient;
66 protected ShellyThingConfiguration config = new ShellyThingConfiguration();
67 protected String thingName;
68 protected final Gson gson = new Gson();
69 protected int timeoutErrors = 0;
70 protected int timeoutsRecovered = 0;
71 private ShellyDeviceProfile profile;
72 protected boolean basicAuth = false;
74 public ShellyHttpClient(String thingName, ShellyThingInterface thing) {
75 this(thingName, thing.getThingConfig(), thing.getHttpClient());
76 this.profile = thing.getProfile();
79 public ShellyHttpClient(String thingName, ShellyThingConfiguration config, HttpClient httpClient) {
80 profile = new ShellyDeviceProfile();
81 this.thingName = thingName;
82 setConfig(thingName, config);
83 this.httpClient = httpClient;
84 this.httpClient.setConnectTimeout(SHELLY_API_TIMEOUT_MS);
87 public void setConfig(String thingName, ShellyThingConfiguration config) {
88 this.thingName = thingName;
93 * Submit GET request and return response, check for invalid responses
95 * @param uri: URI (e.g. "/settings")
97 public <T> T callApi(String uri, Class<T> classOfT) throws ShellyApiException {
98 String json = httpRequest(uri);
99 return fromJson(gson, json, classOfT);
102 public <T> T postApi(String uri, String data, Class<T> classOfT) throws ShellyApiException {
103 String json = httpPost(uri, data);
104 return fromJson(gson, json, classOfT);
107 protected String httpRequest(String uri) throws ShellyApiException {
108 ShellyApiResult apiResult = new ShellyApiResult();
110 boolean timeout = false;
111 while (retries > 0) {
113 apiResult = innerRequest(HttpMethod.GET, uri, null, "");
115 // If call doesn't throw an exception the device is reachable == no timeout
117 logger.debug("{}: API timeout #{}/{} recovered ({})", thingName, timeoutErrors, timeoutsRecovered,
121 return apiResult.response; // successful
122 } catch (ShellyApiException e) {
123 if (e.isConnectionError()
124 || (!e.isTimeout() && !apiResult.isHttpServerError()) && !apiResult.isNotFound()
125 || profile.hasBattery || (retries == 0)) {
126 // Sensor in sleep mode or API exception for non-battery device or retry counter expired
127 throw e; // non-timeout exception
131 timeoutErrors++; // count the retries
132 logger.debug("{}: API Timeout, retry #{} ({})", thingName, timeoutErrors, e.toString());
137 throw new ShellyApiException("API Timeout or inconsistent result"); // successful
140 public String httpPost(String uri, String data) throws ShellyApiException {
141 return innerRequest(HttpMethod.POST, uri, null, data).response;
144 public String httpPost(@Nullable Shelly2AuthChallenge auth, String data) throws ShellyApiException {
145 return innerRequest(HttpMethod.POST, SHELLYRPC_ENDPOINT, auth, data).response;
148 private ShellyApiResult innerRequest(HttpMethod method, String uri, @Nullable Shelly2AuthChallenge auth,
149 String data) throws ShellyApiException {
150 Request request = null;
151 String url = "http://" + config.deviceIp + uri;
152 ShellyApiResult apiResult = new ShellyApiResult(method.toString(), url);
155 request = httpClient.newRequest(url).method(method.toString()).timeout(SHELLY_API_TIMEOUT_MS,
156 TimeUnit.MILLISECONDS);
158 if (!uri.equals(SHELLY_URL_DEVINFO) && !config.password.isEmpty()) { // not for /shelly or no password
162 // Gen 2: Digest Auth
163 String authHeader = "";
164 if (auth != null) { // only if we received an Auth challenge
165 authHeader = formatAuthResponse(uri,
166 buildAuthResponse(uri, auth, SHELLY2_AUTHDEF_USER, config.password));
169 String bearer = config.userId + ":" + config.password;
170 authHeader = HTTP_AUTH_TYPE_BASIC + " " + Base64.getEncoder().encodeToString(bearer.getBytes());
173 if (!authHeader.isEmpty()) {
174 request.header(HTTP_HEADER_AUTH, authHeader);
177 fillPostData(request, data);
178 logger.trace("{}: HTTP {} {}\n{}\n{}", thingName, method, url, request.getHeaders(), data);
180 // Do request and get response
181 ContentResponse contentResponse = request.send();
182 apiResult = new ShellyApiResult(contentResponse);
183 apiResult.httpCode = contentResponse.getStatus();
184 String response = contentResponse.getContentAsString().replace("\t", "").replace("\r\n", "").trim();
185 logger.trace("{}: HTTP Response {}: {}\n{}", thingName, contentResponse.getStatus(), response,
186 contentResponse.getHeaders());
188 if (response.contains("\"error\":{")) { // Gen2
189 Shelly2RpcBaseMessage message = gson.fromJson(response, Shelly2RpcBaseMessage.class);
190 if (message != null && message.error != null) {
191 apiResult.httpCode = message.error.code;
192 apiResult.response = message.error.message;
193 if (getInteger(message.error.code) == HttpStatus.UNAUTHORIZED_401) {
194 apiResult.authChallenge = getString(message.error.message).replaceAll("\\\"", "\"");
198 HttpFields headers = contentResponse.getHeaders();
199 String authChallenge = headers.get(HttpHeader.WWW_AUTHENTICATE);
200 if (!getString(authChallenge).isEmpty()) {
201 apiResult.authChallenge = authChallenge;
204 // validate response, API errors are reported as Json
205 if (apiResult.httpCode != HttpStatus.OK_200) {
206 throw new ShellyApiException(apiResult);
209 if (response.isEmpty() || !response.startsWith("{") && !response.startsWith("[") && !url.contains("/debug/")
210 && !url.contains("/sta_cache_reset")) {
211 throw new ShellyApiException("Unexpected response: " + response);
213 } catch (ExecutionException | InterruptedException | TimeoutException | IllegalArgumentException e) {
214 ShellyApiException ex = new ShellyApiException(apiResult, e);
215 if (!ex.isConnectionError() && !ex.isTimeout()) { // will be handled by the caller
216 logger.trace("{}: API call returned exception", thingName, ex);
223 protected @Nullable Shelly2AuthRsp buildAuthResponse(String uri, @Nullable Shelly2AuthChallenge challenge,
224 String user, String password) throws ShellyApiException {
225 if (challenge == null) {
226 return null; // not required
228 if (!SHELLY2_AUTHTTYPE_DIGEST.equalsIgnoreCase(challenge.authType)
229 || !SHELLY2_AUTHALG_SHA256.equalsIgnoreCase(challenge.algorithm)) {
230 throw new IllegalArgumentException("Unsupported Auth type/algorithm requested by device");
232 Shelly2AuthRsp response = new Shelly2AuthRsp();
233 response.username = user;
234 response.realm = challenge.realm;
235 response.nonce = challenge.nonce;
236 response.cnonce = Long.toHexString((long) Math.floor(Math.random() * 10e8));
237 response.nc = "00000001";
238 response.authType = challenge.authType;
239 response.algorithm = challenge.algorithm;
240 String ha1 = sha256(response.username + ":" + response.realm + ":" + password);
241 String ha2 = sha256(HttpMethod.POST + ":" + uri);// SHELLY2_AUTH_NOISE;
242 response.response = sha256(
243 ha1 + ":" + response.nonce + ":" + response.nc + ":" + response.cnonce + ":" + "auth" + ":" + ha2);
247 protected String formatAuthResponse(String uri, @Nullable Shelly2AuthRsp rsp) {
248 return rsp != null ? MessageFormat.format(HTTP_AUTH_TYPE_DIGEST
249 + " username=\"{0}\", realm=\"{1}\", uri=\"{2}\", nonce=\"{3}\", cnonce=\"{4}\", nc=\"{5}\", qop=\"auth\",response=\"{6}\", algorithm=\"{7}\", ",
250 rsp.username, rsp.realm, uri, rsp.nonce, rsp.cnonce, rsp.nc, rsp.response, rsp.algorithm) : "";
254 * Fill in POST data, set http headers
256 * @param request HTTP request structure
257 * @param data POST data, might be empty
259 private void fillPostData(Request request, String data) {
260 boolean json = data.startsWith("{") || data.contains("\": {");
261 String type = json ? CONTENT_TYPE_JSON : CONTENT_TYPE_FORM_URLENC;
262 request.header(HttpHeader.CONTENT_TYPE, type);
263 if (!data.isEmpty()) {
264 StringContentProvider postData;
265 postData = new StringContentProvider(type, data, StandardCharsets.UTF_8);
266 request.content(postData);
267 // request.header(HttpHeader.CONTENT_LENGTH, Long.toString(postData.getLength()));
272 * Format POST body depending on content type (JSON or form encoded)
274 * @param dataMap Field list
275 * @param json true=JSON format, false=form encoded
276 * @return formatted body
278 public static String buildPostData(Map<String, String> dataMap, boolean json) {
280 for (Map.Entry<String, String> e : dataMap.entrySet()) {
281 data = data + (data.isEmpty() ? "" : json ? ", " : "&");
283 data = data + e.getKey() + "=" + e.getValue();
285 data = data + "\"" + e.getKey() + "\" : \"" + e.getValue() + "\"";
288 return json ? "{ " + data + " }" : data;
291 public String getControlUriPrefix(Integer id) {
293 if (profile.isLight || profile.isDimmer) {
294 if (profile.isDuo || profile.isDimmer) {
296 uri = SHELLY_URL_CONTROL_LIGHT;
299 uri = "/" + (profile.inColor ? SHELLY_MODE_COLOR : SHELLY_MODE_WHITE);
303 uri = SHELLY_URL_CONTROL_RELEAY;
305 uri = uri + "/" + id;
309 public int getTimeoutErrors() {
310 return timeoutErrors;
313 public int getTimeoutsRecovered() {
314 return timeoutsRecovered;
317 public void postEvent(String device, String index, String event, Map<String, String> parms)
318 throws ShellyApiException {