diff --git a/docs/research/2026-09.md b/docs/research/2026-09.md new file mode 100644 index 0000000..60fa5ee --- /dev/null +++ b/docs/research/2026-09.md @@ -0,0 +1,35 @@ +# Research notes: September 2026 + +State as of 2026-09-15. The baseline is the August sweep (2026-08-14, release 1.9.1). The current release is 1.13.2. + +## Our tracker + +- No open issues and no open PRs. #56 (backfill dates) and #58 (repair resync) were closed by #59 (`create_time` backfill and `--repair-days`, 1.9.0) on the day of the last sweep. +- Every August action item landed. #59 fixed #56 and #58. #60 raised the garminconnect and curl_cffi floors and added Python 3.14 to CI. The README notes the Strava subscription prerequisite. `docs/security-and-troubleshooting.md` covers the stale-token false alarm and the Windows Let's Encrypt chain failure. The weekly scheduled CI run is live. +- Since then: the 2026-08-28 reliability sweep (1.10.x), the optional browser extra and lint in CI (1.11.0), Garmin upgrade recovery (1.12.0), experimental Zwift weight sync, all targets offered in first-run setup, and accurate outcome reporting across skipped and failed targets (1.13.x). +- CI on main is green, including the scheduled runs on 2026-09-07 and 2026-09-14. +- Traffic, trailing 14 days: 41 views (32 unique), 688 clones (107 unique). August recorded no traffic, so this is the first data point. +- PyPI downloads, excluding mirrors: 2,520 in July, 868 in August, 786 so far in September. The `recent` endpoint returned 429 on every attempt; these figures come from the `overall` endpoint. The July number probably includes the release burst around 1.8.x. +- Forks: gwgr, runinit (eufy-sync-multios), and james-b-fitzgerald. All three heads are strict ancestors of upstream main (41, 81, and 83 commits behind), so none carries its own commits. + +## Upstream + +- garminconnect went from 0.3.10 to 0.3.15 (0.3.11 on 2026-08-19, 0.3.15 on 2026-09-12). None of it touches our calls. `add_body_composition`, `get_body_composition`, and `delete_weigh_in` still use the same weight-service URLs, and none of them uses `display_name`, so the 0.3.13 display-name fix does not affect us. The 0.3.11 token-storage hardening applies to the library's file token store; we keep tokens in our own store through `client.dumps()` and `client.loads()`, so there is no reason to raise the 0.3.10 floor. The 0.3.12 fix for `resume_login()` retries does not apply either: our MFA path goes through a prompt callback and never calls `resume_login()`. garminconnect still requires `curl_cffi>=0.15.0`, which matches our floor. +- There were no new reports of Garmin login failures, Cloudflare blocks, or 429s in python-garminconnect since the last sweep, and no body-composition upload issues. The one MFA report (#386, no OTP delivered) was closed on 2026-08-21. +- garth is unchanged: 0.8.0 is still the final release, and there has been no issue activity. +- curl_cffi went from 0.16.0 (2026-08-01) to 0.16.3 (2026-09-02). 0.16.0 moved to curl 8.21 and curl-impersonate 2.0 and made `rich` optional. The point releases fix bugs, add Python 3.14 Android wheels, and bring Chrome 152 TLS extension support. Open issues about Chrome 150+ fingerprints concern custom JA3 fingerprints, not the preset targets garminconnect uses. Nothing breaking for us. +- Python 3.14.7 is the latest stable release. 3.15.0rc2 shipped on 2026-09-01, and 3.15.0 final is scheduled for 2026-10-01. The CI matrix (3.12, 3.13, 3.14) is right for now. + +## Market and platforms + +- Strava's changelog now settles the new base URL, which it did not in August: `https://api-v3.strava.com`, available from 2027-01-04. The old `www.strava.com/api/v3` stops working on 2027-06-01. `eufy_sync/strava_client.py` still sets `STRAVA_API_BASE` to the old host. The changelog does not mention the OAuth authorize and token URLs. The 2026-09-01 changes removed the club endpoints and restricted Explore Segments. `PUT /athlete`, the `weight` field, and `profile:write` are unchanged. +- EufyLife still has no native Garmin or Strava export. The iOS app's current version is 3.3.12, released 2025-12-17, and nothing newer has shipped. No announcement turned up. +- BLE Scale Sync shipped Eufy P2 Pro impedance decoding in v1.23.0 (2026-08-19), and since v1.28 and v1.29 it uses the measured impedance instead of a BMI estimate across its adapters. In v1.27.0 its Garmin exporter also gained weight-only uploads. The gap noted in August has narrowed as expected. What still sets this project apart is cloud capture (no BLE listener near the scale) and reporting Eufy's own body composition figures. +- `ohsugeek/eufylife-api` (created 2026-08-24, on PyPI) is a new standard-library client for the same EufyLife cloud API. It was derived from `m4ary/eufylife-api-hacs`. It is a library, not a sync tool, and has no issues filed. The HACS integration has been idle since March 2026, and `eufylife-mcp` since March 2026. None of them reports an auth or endpoint change. + +## Actionable + +1. Between 2027-01-04 and 2027-06-01, move `STRAVA_API_BASE` to `https://api-v3.strava.com`. First check whether Strava changes the OAuth URLs as well. Nothing to change before January. +2. Once 3.15.0 final ships (scheduled 2026-10-01), add 3.15 to the CI matrix. Confirm that curl_cffi publishes 3.15 wheels first. This belongs in the October sweep. + +Nothing else to act on.