A parking lot is one pool of spaces with a flexible set of entry/exit
points — no "lane". Direction is a property of each RELAY inside an access
controller; readers/cameras bind to a controller relay and inherit it.
Schema:
- drop `lane` from ledger_events, device_events, sessions
- rename lane_devices -> devices (no lane/direction columns)
- access config.relays=[{relay,direction,button?}]; reader/camera
config.controllerId+relay binding
- fresh 0000_baseline migration (history reset; dev data was throwaway)
Signed ledger:
- remove `lane` from canonicalize(); bump signer keyId sw-hmac-v1 -> v2
(v1 events won't verify under v2 — intentional, gated per-event by keyId)
Server:
- new device-resolve.ts (replaces lane-map.ts): relayForButton,
relayForDevice, firstRelayByDirection, devicesByDirection
- entry-flow: button terminal -> its relay; exit/permit: reader's bound
relay; dispatcher resolves the bound relay + inherited direction
- camera snapshots fire by direction site-wide, async, never block open
- DeviceConfig widened to nested JSON for relays[]
Web:
- wizard: no lane selector; add controllers (relay map + entry-button
terminal) first, then bind readers/cameras/printers to a controller relay
Wiki: new entry-exit-points.md (replaces lane-direction); reworked
entry-exit-readers, parking-session, first-run-setup, device-registry,
append-only-event-chain, device-events; removed stale lane/LaneMap mentions.
3.5 KiB
type, tags, sources, updated
| type | tags | sources | updated | |||||
|---|---|---|---|---|---|---|---|---|
| concept |
|
|
2026-06-15 |
First-Run Setup (device selection)
The admin install flow that makes the system device-agnostic in practice: on first run, an admin adds controllers (each declaring its relays — entry/exit/both — and the entry-button terminal) and then readers/cameras/printers bound to a controller relay, choosing from the device-registry catalog and entering each device's connection config. There is no lane — the pool-of-spaces model; see entry-exit-points.
Implementation-derived (from
apps/server+apps/web), not the source doc.
Flow
- Read the catalog —
GET /api/setup/catalogreturns supported drivers per category (no secrets, just schema) plus adiscoverablelist. The webSetupWizardrenders a picker + the driver's config fields, and a Scan button for discoverable drivers (device-discovery). - Test (optional, no save) —
POST /api/setup/test(admin-only). Validates the config, probes reachability (healthCheck), and reports preconditions (e.g.input_link_relay) — without saving or changing the device. The wizard's Test connection button shows a health badge + any precondition warnings. - Save & configure —
POST /api/setup/assign(admin-only). Validates, then configures the device: fixes preconditions (e.g. disablesinput_link_relay) and sets up the Digest- authenticated input push (device-input-flow) — the admin never touches the device's own web UI. Fails the save (no DB row) if the device can't be configured, so there are no orphan/half-configured rows. On success persists todevices. - Remove —
DELETE /api/setup/assign/:id(admin-only) drops one instance's row. Only our row is removed; the device itself is not un-hardened/un-configured (a stale push from an unknown device id is already rejected, and re-assigning reconfigures it). - Complete —
POST /api/setup/completemarks the single-rowsetup_state.
Config granularity — multi-instance per category
The data model is multi-instance: devices holds one row per instance, keyed by a
generated id. So the site can have more than one of every category — multiple controllers,
readers, cameras, and printers (e.g. an entry dispenser + a booth printer; see
printer-roles-failover). assign always inserts a new row (never an upsert), and state
returns the full list.
The SetupWizard reflects this: each category shows the list of assigned instances (with
Remove) plus an Add another form — not a single fixed slot. select-type config fields
(e.g. a printer's role) render as dropdowns.
There is no lane. Direction lives on each access relay; readers/cameras bind to a
controller relay (config.controllerId + relay) — the barrier they serve — and inherit its
direction. The wizard adds controllers first, then binds the other devices to a relay. See
entry-exit-points, entry-exit-readers.
Security notes
- The assign/state/delete/complete endpoints require the admin role (local-jwt-auth).
- Device credentials are stored in
devices.config— protect at rest (disk-os-hardening); device hosts belong on the isolated VLAN (network-isolation). - Secrets are stripped on the way out:
assignandstateboth redactpushPassword,webPassword, andrelayPasswordfrom the returned config (the UI lists devices; it never needs the stored secrets).