Couple hours ago someone activated every cloud link I had on one of my hubs.
Has anyone else had the same problem?
Couple hours ago someone activated every cloud link I had on one of my hubs.
Has anyone else had the same problem?
No, and this is very concerning.
Tagging @support_team
Could you please share more details about this event? What makes you think the links were activated? What kind of links.
I assume these are cloud end points from Rule Machine. How are they accessed/automated to be triggered?
Yes, sorry, that's correct.
I have shortcuts which post the Cloud End Point Link on my iphone, I have a widget for them.
I can understand if something happened in my pocket, but I had the phone in my hand when this happened.
It would be pretty hard to trigger every single one that quickly anyways
What kind of widget? Even a background refresh of some sort can trigger it. It doesn't have to be a manual trigger.
I forgot to mention, I've had these for 5 years, this has never happened.
If you are on the main screen on the iphone and wipe right, theres a page for widgets.
Can you guys pull up logs on your end?
There wouldn't be anything on your hub, other than what you already have, that an external source triggered the end point.
Each endpoint uses a unique access token. To protect your privacy, we do not collect enough information to trace activity back to an individual token. If you suspect that a token may have been exposed or used without authorization, we recommend deleting the existing tokens and generating new ones.
I get that the easy answer is my token leaked or my phone did something in the background, but look at the timestamps in that log. Every single cloud link fired sequentially within about 5 seconds. A widget refresh or pocket activation doesn't do that.
And per your own explanation, each endpoint has a unique token. So for this to be on my end, every one of my tokens would have had to be compromised and used at the same instant. That doesn't point to my phone. It points to something on the cloud side, either a bug or someone running a script against your endpoints.
I'll rotate my tokens, but that's treating the symptom. My original post was to see if anyone else has seen this, because if the answer is yes, this isn't a me problem.
I use cloud links along with the iOS Shortcuts app to trigger RM cloud endpoints on my hub. I have 4 such shortcuts. I haven't seen this happen in 3+ years.
I have a couple rules triggered by cloud endpoints. And I use Homebridge to get my HE devices in the Apple home app, and I use a couple shortcuts. I haven’t seen this issue.
None of my shortcuts use a cloud endpoint, though.
We will keep a close eye on this thread. I wouldn't rebuild the end points just yet. I am afraid that refreshing the tokens and using them with the same widgets would result in the same outcome, sooner or later. From our end, we need the exact token to trigger the end point. That is the whole point of having unique tokens, to prevent accidents like you describe.
I know we can take AI answers with a grain of salt, but this is what it says:
" AI Overview
An iPhone widget can fire or refresh unintentionally due to ghost touch (screen hardware glitch), a background push notification batch wake-up, or a focus mode switch. Triggering simultaneously within a 5-second window is almost always caused by a system-wide push notification data sync or a SpringBoard (iOS home screen) refresh/crash loop
Causes for Simultaneous Triggering (Within 5 Seconds)
Thanks for everyone who chimed in.
I should have mentioned that I have these Cloud End Point links for more than one hub on my iOS widget page, and only one hub got hammered.