Trust is earned, not given

A different perspective

2020-08-09 · Projects

Fetching weather on an ESP8266 with the WeatherAPI.com client

Several of my display projects need outdoor weather. Rather than duplicate that code, I wrapped it in its own small library: esp8266-weather-WeatherApi, a client for WeatherAPI.com where a single HTTPS request returns both current conditions and a multi-day forecast.

Usage in fifteen lines

#include "WeatherApiWeather.h"

WeatherApiWeather weatherClient;
WeatherApiCurrentData current;
WeatherApiForecastData forecast[3];

void setup() {
  // ... connect WiFi first ...
  uint8_t n = weatherClient.updateWeather(
      &current, forecast,
      "YOUR_API_KEY", "London", "en", 3);
  Serial.printf("Now: %.1fC, %s\n", current.temp_c, current.text.c_str());
  for (uint8_t i = 0; i < n; i++)
    Serial.printf("%s: %.1f/%.1fC\n", forecast[i].date.c_str(),
                  forecast[i].mintemp_c, forecast[i].maxtemp_c);
}

Free API keys are available at WeatherAPI.com; the location parameter accepts city names or lat,lon.

The security trade-off worth teaching

The client calls WiFiClientSecure::setInsecure(), which skips TLS certificate validation. That is a real security trade-off, and the README says so plainly: validating the server's identity properly requires pinning a root CA (setTrustAnchors()), which breaks every time the provider renews certificates. For a hobby weather display, the pragmatic choice is setInsecure(); for anything handling secrets it is not. Understanding why matters more than the line of code.

Design notes

Repository: github.com/bobhuang1/esp8266-weather-WeatherApi