Skip to content

Reolink Home Hub Pro firmware requires token auth for Snap; plugin sends inline credentials, snapshots fail #2088

Description

@psantia01

Hi there. In Apple Home, the camera's stopped responding and no response has shown up. I've done a tremendous amount of troubleshooting, and some strange things happen. The camera's come and go within Apple Home. I'm running Scrypted and they are all there. I have them as independent items to add as accessories to Home. I deleted one camera to try and add it back and now it can't find that camera. I'm literally watching my camera's in Home and they come and go from no response to a snapshot version. When I click on them, when they are responding, I can get to a live feed. If I stay on the live feed, they seem to stay online. Once I close the camera, they drop again and I get a no response until they pop back up.

According to the below, they seem to lose connection somehow. I don't know if the bottom information is what is needed, but, this used to work fine. I've updated quite a bit of software so I'm up to date on everything within Scrypted as well as Homebridge (not necessary) and HomeKit plugins, etc.


Environment

  • Scrypted server 0.143.0, Docker on Raspberry Pi (linux arm64, Debian bookworm)
  • @scrypted/reolink 0.0.111
  • @scrypted/snapshot 0.2.68
  • @scrypted/homekit 1.2.65
  • Reolink Home Hub Pro (current firmware), cameras added via the hub

Summary

The hub's HTTP API no longer accepts inline user/password on cmd=Snap — it returns rspCode -7 ("login failed"). It does accept a token obtained from cmd=Login. The Reolink plugin appears to still use inline credentials, so every snapshot request fails.

Because snapshots fail, @scrypted/snapshot falls back to its ffmpeg placeholder generator, which is also broken (see below), so nothing is returned at all. HomeKit then marks the accessories unresponsive and the plugin churns, withdrawing their mDNS records.

Reproduction

Inline credentials — fails:

curl -G --data-urlencode "user=admin" --data-urlencode "password=$PW" \
  'http://HUB_IP/cgi-bin/api.cgi?cmd=Snap&channel=0&rs=test'
[{"cmd":"Snap","code":1,"error":{"detail":"login failed","rspCode":-7}}]

Login — succeeds, returns token:

curl -X POST -H 'Content-Type: application/json' \
  -d '[{"cmd":"Login","param":{"User":{"Version":"0","userName":"admin","password":"PASS"}}}]' \
  'http://HUB_IP/cgi-bin/api.cgi?cmd=Login'
[{"cmd":"Login","code":0,"value":{"Token":{"leaseTime":3600,"name":"..."}}}]

Snap with token — succeeds, returns JPEG in ~1s:

curl -o snap.jpg 'http://HUB_IP/cgi-bin/api.cgi?cmd=Snap&channel=0&rs=test&token=TOKEN'
# JPEG image data, baseline, 3840x2160

Individual cameras behind the hub behave the same way when addressed directly.

Secondary bug: snapshot fallback command is invalid

When a snapshot times out, @scrypted/snapshot runs an ffmpeg command that uses both -filter_complex and -vf on the same stream, which ffmpeg rejects:

Filtergraph 'select=eq(pict_type,I)' was specified for a stream fed from a
complex filtergraph. Simple and complex filtering cannot be used together
for the same stream.
Error opening output files: Invalid argument
exit=234

Source: @scrypted/snapshot/zip/src/ffmpeg-image-filter.ts:186

So the "Snapshot Timed Out" placeholder can never be generated on current ffmpeg builds, turning a recoverable timeout into a total failure.

Expected

The Reolink plugin obtains and refreshes a token (1-hour lease) and uses it for Snap, rather than passing credentials inline.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions