Files
parking_solution/wiki/index.md
T
julian dbf1fa17d7 wiki: document dev environment (WSL networking, workflow)
Capture hard-won dev knowledge that was only in commit messages:

- wsl-dev-networking: WSL2 NAT blocks UDP broadcast (device discovery can't
  reach the LAN); fix is mirrored networking (.wslconfig, Win11 22H2+), plus the
  gotchas that remained after — multiple interfaces, subnet-directed broadcast,
  localhost->IPv6 stall. Alternatives for non-mirrored setups.
- local-dev-workflow: first-time setup, pnpm dev, and the gotchas (the
  strip-types dev-server hang -> tsx, the 127.0.0.1 proxy fix, .env loading,
  seeding into the right DB).
- device-discovery: corrected the old "broadcast permission (EACCES)" note — the
  real cause was the lib not enabling SO_BROADCAST for global 255.255.255.255;
  documented the three verified broadcast gotchas + I/O serialization.
- schema: add a `reference` page type; new "Dev environment" index section; log.

Links lint clean; both new pages well-connected.
2026-06-14 13:09:35 +02:00

4.3 KiB

type, tags, updated
type tags updated
overview
parking
index
2026-06-14

Index

Content catalog for the wiki. Start at overview. Maintained on every ingest. Counts: 1 source · 14 entities · 10 concepts · 2 decision records.

Overview & navigation

  • overview — the top-level synthesis and entry point.
  • index — this catalog.
  • log.md — chronological record of ingests/queries/lints.

Sources

Entities — technology stack

  • technology-stack — the full stack table; all MIT/Apache/BSD, chosen to avoid lock-in.
  • fastify — Node backend; hosts device-driver plugins + auth; serves the SPA.
  • sqlite — local single-writer DB (WAL); limits & why it fits.
  • drizzle-orm — ORM; schemas port to PostgreSQL for remote sync.
  • turborepo — monorepo tool.
  • react-vite-spa — React/Vite frontend served by Fastify.
  • local-jwt-auth — fully local auth (JWT + bcrypt + role guard); forced by offline-first.

Entities — rejected alternatives

  • payload-cms — strong, but rejected over BSL license shift (the rug-pull cautionary case).
  • refine — dropped for plain React; UI too simple to justify a framework.
  • logto-zitadel-oidc — OIDC providers ruled out by offline-first.

Entities — hardware & devices

  • uhppote-controller — current access controller; cheap, tamper-evident, open-UDP, fixed firmware.
  • esp32-custom-controller — prevention-grade upgrade; device-level auth.
  • atecc608 — secure element; non-extractable signing key (host events + controller auth).
  • wiegand — reader standard feeding the controller directly (autonomous permit-holder path).
  • lpr-camera — edge-AI plate recognition; host-side casual-identity source.
  • zkteco-controller — C3/inBio controller; aux-input path may enable host-in-the-loop (driver TBD).
  • bom — reference bill of materials (barrier, loops, controller, readers, payment, host, network).

Concepts — foundational forces

  • offline-first — no network dependency in core operation; what it forces (and doesn't).
  • threat-model — the operator-at-the-booth reframing; why encryption defends the wrong threat.

Concepts — integrity & anti-fraud

Concepts — device architecture & safety

  • device-adapter-pattern — business logic talks to interfaces; swap hardware → new adapter.
  • device-registry — catalog of selectable drivers per category (admin-configurable).
  • first-run-setup — admin assigns devices per lane from the catalog at install.
  • device-discovery — optional driver capability to scan the LAN (UHPPOTE UDP broadcast).
  • barrier-not-a-door — never timed-close a barrier; safety lives in barrier firmware.
  • trust-boundary — the core fork: network vs. device; auditable vs. unforgeable.
  • fail-state-safety — entry fails closed, exit fails open; manual override; watchdog.

Concepts — access control

Dev environment (reference)

  • local-dev-workflow — running the stack locally; setup, the dev-hang gotchas, seed:admin.
  • wsl-dev-networking — WSL2 NAT blocks device broadcast; use mirrored mode + the gotchas after.

Decisions