7de5c74500
- open-questions #7: symmetric vs. asymmetric JWT signing key (from the commit security review). Prefer RS256/EdDSA so verifying hosts hold only a public key — mirrors the ATECC608 / challenge-response "public key only" property. Decide before multi-host/multi-lane deployment. - Mark esp32-custom-controller status: deferred per decision not to build device-level auth now; access control stays on UHPPOTE + network isolation (noted in open-questions #6). - local-jwt-auth: document hardened secret handling + 8h expiry and the asymmetric-key pointer. - Update index.md and append a log.md entry.
21 lines
1.2 KiB
Markdown
21 lines
1.2 KiB
Markdown
# Wiki Log
|
|
|
|
Append-only chronological record. Each entry: `## [YYYY-MM-DD] <op> | <subject>`.
|
|
Query with `grep "^## \[" log.md | tail -5`.
|
|
|
|
## [2026-06-14] ingest | Parking System — Architecture & Design Notes
|
|
First source ingested. Bootstrapped wiki scaffolding (CLAUDE.md schema, index.md,
|
|
overview.md, log.md). Created source summary, 14 entity pages, 9 concept pages, and
|
|
decision records (settled decisions + 6 open questions). Source is a dense design
|
|
doc covering stack, threat model, device architecture, UHPPOTE access control, the
|
|
custom ESP32 controller alternative, readers, and a reference BOM.
|
|
|
|
## [2026-06-15] decision | JWT key choice + ESP32 deferred
|
|
From app work, not a new source. Added [[open-questions]] #7 (symmetric vs.
|
|
asymmetric JWT signing key — raised by the commit security review; prefer RS256/EdDSA
|
|
so verifying hosts hold only a public key, mirroring the ATECC608 / challenge-response
|
|
property). Marked [[esp32-custom-controller]] `status: deferred` per decision not to
|
|
implement device-level auth for now (access control stays on UHPPOTE + network
|
|
isolation); noted in [[open-questions]] #6. Updated [[local-jwt-auth]] (hardened secret
|
|
handling + 8h expiry, asymmetric-key pointer) and the index.
|