A customizable SmartThings web app for mobile devices
The Samsung SmartThings Android application is good for basic tasks but lacks customizable interfaces and advanced rules for SmartThings actions. The SmartThingsWebAPP can be used to integrate existing SmartThings devices into a customizable interface designed to work inside a hybrid Android application.
- Develop an Android hybrid applicaton
- Create a simple and intuitive user interface
- Interact with SmartThings API to show current configured SmartThings devices
- Create new routines, or actions for SmartThings devices
- Add advanced configuration items
- Add at least 2 user interfaces switchable by user
As an application user, I want to change the app UI so I can see the app how I like it.
Acceptance Criteria:
- A setting or switch must exist to modify the UI
- At least 2 UI must exist for user to swtich between
As an applcation user, I want to modify SmartThings actions/routines to only work at certain times of day so I can turn on the lights only if its dark outside
Acceptance Criteria:
- SmartThings device action must accept time as arguments
As an guest, I want to not use the app so I don't have to sign into SmartThingsWebAPP to use them
- The app must be available from local wifi as as website with limited functionality
As a hacker, I want to use the SmartThingsWebAPP to modify SmartThings actions/routines so I can break into someones house
Mitigations
- The SmartThingsWebAPP must use a Samsung SmartThings API token to authenticate to SmartThings devices
As a malicious user, I want to exploit the SmartThingsWebAPP guest access so I can steal location information of users
Mitigations:
- The guest acces will only be available from local WiFi, or other whitelisted locations
The Hybrid Android Application for the phone
This web service will be used to track if it is daylight for advanced SmartThings actions/routines
SmartThings API for interfacing with hardware components such as SmartThings hub or Phillips hue lightbulbs https://smartthings.developer.samsung.com/
A web page which is unauthenticated to provide access to a limited set of SmartThings devices. This will be limited to whitelisted networks.
Hosts the content and makes API calls to SmartThings and other web services
Runs the SmartThingsWebAPP and sends instructions to the web server
The on premise hardware interface for the SmartThings Applicaiton
WiFi enabled light bulbs which can be controlled by SmartThings
Text describing high level diagram with red or other callouts identifying problem points or attacks.
| Component name | Category of vulnerability | Issue Description | Mitigation |
|---|---|---|---|
| SmartThings API | Unauthorized Access | This application exposes API endpoints for SmarthThings which could be used malicioulsy. | The API endpoints will require an API token to prevent misuse. |
| Guest Access | Access to unauthoized devices | The guest access site will provide unauthenticated access to a set of devices | Certain devices will only be available to authenticated users (with the Android App) |
| Web Server | Denial of Service | The web server could be affected by a Denial of Service attack | Access will be whitelisted for guests and authenticated for application users |
- SmartThings Hub and Samsung account will be required to use this SmartApp.
- Web server with valid web certificate (HTTPS will be used by SmartThings API).
- Smart lighting or switches to command with this SmartApp.
- SmartThings Classic or SmartThings Android or iOS Application
- Running this application requires Docker. Once Docker is running, build the image as follows.
git clone --recursive https://github.com/woonat01/SmartThingsWebAPP.git
cd SmartThingsWebAPP
docker-compose build
- Create an API key with Open Weather Map (free tier is fine), and store it in a file
/api/backend/tokenWeather.txt. - Create an API key with SmartThings and store it in a file
/api/backend/tokenST.txt. - Create an Admin user for the site
python manage.py createsuperuser- fill in the username and password (this should be strong since this site is exposed)
- Once the image is configured, it can be run using the following command:
docker-compose up
-
Go to the Automation section of the Developer Workspace and create an Automation.
- For the SmartApp Type select WebHook endpoint and enter the https URL of your webserver.
- For the Scope, click on Settings and select the following scopes:
r:installedapps:*l:devices:*r:devices:*x:devices:*
- Click SAVE AND NEXT.
- In the next screen you will be presented with the Public Key.
-
Copy this public key and replace the contents of the file
backend/toeknST.txtwith it. -
Click CONFIRM to register your automation in self-publishing mode.
-
Copy the Public Key generated by SmartThings and store it in a file
/api/backend/publicKey_SmartThings.txt. -
Stop the Docker container:
CTRL-C. -
Start the Docker container again:
docker-compose up
- Install the SmartApp in the SmartThings mobile app (go to Marketplace->SmartApps->Smart Weather Lighting.
- Enter all required inputs on the configuration screens.
- Once installed the SmartApp will monitor your desired presence sensor and turn on the lights designated during setup.
