Implement a full permissions system replacing simple admin/user roles:
Backend:
- Add Group model with many-to-many user relationship
- Add 50+ granular permissions (resource:action pattern)
- Create default groups: Administrators, Operators, Viewers
- Add permission-checking dependencies for route protection
- Add groups API endpoints (CRUD, user assignment)
- Add change password endpoint for users
- Update backup/restore to include groups
- Migrate existing users to groups on startup
Frontend:
- Add GroupsPage for managing groups and permissions
- Add permission helpers to AuthContext (hasPermission, hasAnyPermission)
- Add PermissionRoute component for protected routes
- Disable buttons/features based on permissions (with tooltips)
- Add change password modal in sidebar for all users
- Add forgot password info modal on login page
- Show user groups in UsersPage with group assignment
Testing:
- Add integration tests for groups API
- Add tests for user-group assignments
- Add tests for change password endpoint
- Seed default groups in test fixtures
Closes#28#161
Home Assistant smart plugs can now use separate sensor entities for
energy monitoring, enabling energy tracking for plugs that expose
power/energy data as separate sensors (Tapo, IKEA Zigbee2mqtt, etc.).
Features:
- Configure dedicated power (W), today (kWh), and total (kWh) sensors
- New API endpoint GET /api/v1/smart-plugs/ha/sensors lists available sensors
- Falls back to switch entity attributes if no sensors configured
- Print energy tracking now works for HA plugs (not just Tasmota)
Backend:
- Added ha_power_entity, ha_energy_today_entity, ha_energy_total_entity
fields to SmartPlug model
- Updated get_energy() to fetch from configured sensor entities
- Added _get_plug_energy() helper to handle both plug types
- Updated backup/restore to include new fields
- Added database migration for new columns
Frontend:
- Added energy sensor dropdowns in AddSmartPlugModal (shown for HA plugs)
- Dropdowns filtered by unit (W/kW for power, kWh/Wh for energy)
Tests:
- Added 4 new integration tests for HA energy sensor functionality
Docs:
- Updated README with new feature
- Updated CHANGELOG with 0.1.6b11 entry
Fixes:
- Fixed is_auth_enabled() returning None instead of False when setting doesn't exist (in both auth.py and routes/auth.py)
- Fixed get_current_user() crashing when credentials is None
- Added missing async_session patch in conftest.py for auth tests
Backup/Restore - Added Users Support
- Added include_users parameter to backup export
- Users are exported with username, role, and is_active (passwords excluded for security)
- Restore creates users with temporary passwords that must be changed
Backend Tests - 16 New Auth Tests
- test_auth_api.py with tests for:
- Auth status endpoint
- Auth setup (enable/disable)
- Login flow (success, invalid credentials, auth disabled)
- /me endpoint with/without token
- User management (list, create, update, delete)
- Auth disable
Frontend Tests - 6 New Login Tests
- LoginPage.test.tsx with tests for:
- Form rendering
- Input validation
- Login submission
- Loading states
Documentation Updates
- CHANGELOG.md/README.md: Added authentication feature description
- Website (features.html): Added new "Optional Authentication" section
- Wiki: Created authentication.md with full documentation
- Wiki index: Added authentication to features list