Standalone support for the ThermalGrizzly WireView Pro II without
depending on the external wireview_reporter exporter:
- wireview.py: serial protocol (STX/ETX + 16-bit CRC16-CCITT) with
vendor-data product identification, config version, UID, build
string, screen layout, and temperature/power/current sensor reads;
hwmon fallback with per-channel index resolution; udev-based
detection (vendor 0x2560 / product 0x0101) with fallback port
probing; serial read timeout and watchdog reconnect
- server.py: startup detection (root only), 1 Hz poller gated on
subscribed clients, WS 'wireview' channel, GET /api/wireview,
rejected-product memoization, stale-read race guard
- frontend: WireView tab (visible when a device is detected) with
live temperature/power/current cards, sparkline history, and
device info; nullable temp channels
- tests: 76 tests covering parser, CRC, fault classification,
hwmon resolution, JSON safety, and the serial transport against
a pty-based fake device
Verified live: tab appears with the device connected, disappears
when unplugged, reconnects on re-plug, no serial traffic when idle.
- hatch_build.py: custom hatchling build hook that compiles the React
frontend (npm ci + build) when frontend/dist is missing or stale, so
'uv tool install git+https://gitea.zephyre.one/Pakobbix/nvcurve.git'
works as a single command
- install.sh: curl|bash installer (checks prerequisites, auto-installs uv,
clones and installs)
- Makefile: dev targets (frontend, install, dev, test, clean)
- README/docs: document the one-liner, clone, and direct-git installs
Add optional login protection for the web UI/API, intended for shared
machines (e.g. AI servers). Dual mode: with no users configured the API
and web UI are open (as before); once at least one user exists, every
/api/* and /ws/* endpoint requires a valid session.
- bcrypt password hashing: passwords stored as $2b$ hashes in
/etc/nvcurve/users.json (0600, root-owned); plaintext never persisted.
- 24-hour sessions: HttpOnly cookie for browsers, Authorization: Bearer
token for CLI/scripts; in-memory, invalidated on server restart.
- Multi-user: multiple named accounts (no shared-password mode).
- New CLI: nvcurve user add|list|remove|set-password (root for mutating
ops; password always prompted, never a CLI argument).
- New endpoints: GET /api/ping (public), /api/auth/status|login|logout|users.
- Web UI: sign-in screen when auth is enabled; status bar shows the
signed-in user with sign-out; expired sessions (401) re-show sign-in.
- Brute-force lockout: 10 failed logins/IP within 5 min -> 15 min lockout.
- New dependency: bcrypt.
Also: LSP config (pyrightconfig.json) pointing at the project .venv, and
small error-handling cleanups in daemon.py/server.py.
- Backend HAL (hal/fans.py): NVML v2 fan read/set/reset with min/max queries
- Server endpoints: GET/POST /api/fans, POST /api/fans/reset, POST /api/fans/speed
- Background fan poller: reads GPU temp every 2s, interpolates fan speed from curve
- Profile integration: fan_curve field saved/applied, auto-restore on shutdown
- Frontend: FanCurveEditor (SVG chart with drag/add/delete points), FanMonitor sidebar
- App.tsx: three-tab layout (Curve, Performance, Fans)
- GaugeCard: optional history sparkline, Fan Mode card without sparkline
- fan_mode field populated as 'curve' or 'auto' in GET /api/fans