Home Assistant closes a route that let any signed-in user retrieve a script’s raw configuration, including credentials written into its sequence. Access through that connection command requires an administrator.

Franck Nijhof brings the route into line with the existing protection for automation configuration and the other script-configuration interface. The change restricts reading the script’s definition; it does not change permission to run it.