Files
parking_solution/wiki/index.md
T
julian 355026dcf7 Remove UHPPOTE/ZKTeco; Dingtian is the only access driver
Neither UHPPOTE nor ZKTeco is used — the Dingtian relay controller was chosen
and verified. Remove their code and re-scope the wiki.

Code:
- delete access-uhppote.ts, uhppoted.d.ts, access.ts (zkteco/esp32-relay stubs),
  and the three uhppote-*.mjs hardware test scripts.
- remove the `uhppoted` npm dependency from @parking/devices and @parking/server.
- unregister uhppote/zkteco/esp32-relay from the driver registry; drop their
  exports. Catalog access drivers = dingtian only. Build green (5/5).
- refresh now-stale example comments (registry/interfaces/setup/api) to use
  current examples; keep the two "UHPPOTE blocker" references that explain why
  the precondition capability exists.

Wiki (kept pages, re-scoped):
- uhppote-controller, zkteco-controller -> rejected/historical with callouts;
  uhppote-vs-esp32 -> historical (detection-vs-prevention lens still useful).
- re-point all "current device" framing (standing-decisions, bom, overview,
  open-questions, device-registry, device-discovery, index) to dingtian-relay.
- transferable concepts (network-isolation, event-log-ingestion, barrier-not-a-
  door, threat-model) untouched. Raw source immutable. Links lint clean.
2026-06-14 14:28:52 +02:00

4.7 KiB

type, tags, updated
type tags updated
overview
parking
index
2026-06-14

Index

Content catalog for the wiki. Start at overview. Maintained on every ingest. Counts: 1 source · 14 entities · 10 concepts · 2 decision records.

Overview & navigation

  • overview — the top-level synthesis and entry point.
  • index — this catalog.
  • log.md — chronological record of ingests/queries/lints.

Sources

Entities — technology stack

  • technology-stack — the full stack table; all MIT/Apache/BSD, chosen to avoid lock-in.
  • fastify — Node backend; hosts device-driver plugins + auth; serves the SPA.
  • sqlite — local single-writer DB (WAL); limits & why it fits.
  • drizzle-orm — ORM; schemas port to PostgreSQL for remote sync.
  • turborepo — monorepo tool.
  • react-vite-spa — React/Vite frontend served by Fastify.
  • local-jwt-auth — fully local auth (JWT + bcrypt + role guard); forced by offline-first.

Entities — rejected alternatives

  • payload-cms — strong, but rejected over BSL license shift (the rug-pull cautionary case).
  • refine — dropped for plain React; UI too simple to justify a framework.
  • logto-zitadel-oidc — OIDC providers ruled out by offline-first.

Entities — hardware & devices

  • uhppote-controller — ❌ rejected/historical; firmware auto-open blocker drove the switch to Dingtian.
  • esp32-custom-controller — prevention-grade upgrade; device-level auth.
  • atecc608 — secure element; non-extractable signing key (host events + controller auth).
  • wiegand — reader standard feeding the controller directly (autonomous permit-holder path).
  • lpr-camera — edge-AI plate recognition; host-side casual-identity source.
  • zkteco-controller — ❌ rejected/historical; aux-input path was a contender, not pursued.
  • dingtian-relay — ✅ CHOSEN access controller; decoupled inputs solve the button blocker (driver verified on hardware).
  • bom — reference bill of materials (barrier, loops, controller, readers, payment, host, network).

Concepts — foundational forces

  • offline-first — no network dependency in core operation; what it forces (and doesn't).
  • threat-model — the operator-at-the-booth reframing; why encryption defends the wrong threat.

Concepts — integrity & anti-fraud

Concepts — device architecture & safety

  • device-adapter-pattern — business logic talks to interfaces; swap hardware → new adapter.
  • device-registry — catalog of selectable drivers per category (admin-configurable).
  • first-run-setup — admin assigns devices per lane from the catalog at install.
  • device-discovery — optional driver capability to scan the LAN (no current driver uses it; UHPPOTE was the example).
  • barrier-not-a-door — never timed-close a barrier; safety lives in barrier firmware.
  • trust-boundary — the core fork: network vs. device; auditable vs. unforgeable.
  • fail-state-safety — entry fails closed, exit fails open; manual override; watchdog.

Concepts — access control

Dev environment (reference)

  • local-dev-workflow — running the stack locally; setup, the dev-hang gotchas, seed:admin.
  • wsl-dev-networking — WSL2 NAT blocks device broadcast; use mirrored mode + the gotchas after.

Decisions

  • standing-decisions — settled decisions (stack, platform, integrity, access control, readers).
  • open-questions — 7 open items (6 procurement + JWT key choice); ESP32 device auth deferred.
  • access-controller-button-flow — ✅ RESOLVED: Dingtian decoupled inputs enable ticket-first entry (was a UHPPOTE/ZKTeco blocker).
  • autonomous-direction — roadmap: toward fully unmanned (no booth); reshapes threat model + fail-state.
  • dingtian-vs-mqtt — transport choice: direct HTTP/UDP now, MQTT parked until multi-lane scale.