UHPPOTE hardware bring-up + entry-flow blocker
Brought up the real UHPPOTE controller (serial 225088491, fw 09120) end to end and recorded a procurement-level blocker. Verified on hardware: - discovery (LAN scan), host-commanded openDoor on doors 1 & 2 (physically actuated; reason="remote open door"), and live button capture (reason="push button ok"). Driver/networking fixes (packages/devices/src/drivers/access-uhppote.ts): - broadcast to subnet-directed address (lib doesn't enable SO_BROADCAST for the global 255.255.255.255 -> EACCES); - Config broadcast must match the target's subnet for unicast reply routing (fixes the health-check timeout: 5s -> 24ms ready); - discover across all local subnets, dedupe by serial; - serialize all controller I/O (concurrent calls collided on UDP :60001). Server/UX: - load .env via node --env-file-if-exists (vars weren't being read before); - SETUP_AUTH_BYPASS hardened: env-gated, dev + loopback only, fails closed otherwise; surfaced as catalog.authBypass so the wizard drops the token field; - .env.example documents all vars; inline favicon stops a 404. - apps/server/scripts/: uhppote-listen (live events, restores prior listener) and uhppote-relay (guarded door-open test). BLOCKER (wiki/decisions/access-controller-button-flow.md): the controller's push-button input auto-opens the relay in firmware with no report-without-open mode, so ticket-first entry (button -> print -> open, fail-closed) is impossible as wired. UHPPOTE can't do it on that input; ZKTeco *might* via a programmable aux input + PULL SDK but that's unverified and needs a new driver. Entry-lane hardware decision paused to focus on the business side. wiki: access-controller-button-flow (blocker), zkteco-controller (stub + assessment), uhppote-controller callout, index + log.
This commit is contained in:
@@ -1,11 +1,23 @@
|
||||
# Copy to .env and fill in. The server refuses to start without a strong JWT_SECRET.
|
||||
# Copy this file to `.env` (same folder: apps/server/.env) and fill it in.
|
||||
# The dev/start scripts load it automatically via Node's --env-file-if-exists.
|
||||
#
|
||||
# Generate a strong secret:
|
||||
# openssl rand -hex 32
|
||||
# cp apps/server/.env.example apps/server/.env
|
||||
#
|
||||
# Required ----------------------------------------------------------------
|
||||
# The server refuses to start without a strong JWT_SECRET (>=32 chars).
|
||||
# Generate one with: openssl rand -hex 32
|
||||
JWT_SECRET=
|
||||
|
||||
# Optional
|
||||
# Optional ----------------------------------------------------------------
|
||||
# PORT=3000
|
||||
# HOST=0.0.0.0
|
||||
# HOST=0.0.0.0 # interface to bind. 127.0.0.1 = loopback only.
|
||||
# LOG_LEVEL=info
|
||||
# DATABASE_URL=./parking.sqlite
|
||||
|
||||
# Testing-only ------------------------------------------------------------
|
||||
# Bypass the admin auth on /api/setup/* so you can discover/assign devices
|
||||
# before the login flow exists. HARDENED: only honoured when NODE_ENV is not
|
||||
# "production" AND HOST is loopback (127.0.0.1 / ::1 / localhost); otherwise
|
||||
# the server refuses to start. Never set this in production.
|
||||
# SETUP_AUTH_BYPASS=1
|
||||
# HOST=127.0.0.1
|
||||
|
||||
Reference in New Issue
Block a user