Redesign phase C: claim flow, limited manage page, device protocol
The frame-claiming pipeline, end to end. Firmware: every request now carries ?id=<12-hex STA MAC> via build_url (mirrored in build_ota_url), and the captive portal's success page became a redirect that hands the user's browser to <server>/claim?device_id=... after ~7s -- enough time for the phone to drop the provisioning AP while the device reboots. The server pushes a per-frame device token through /frame/config during a one-time handshake; the firmware persists it to NVS (a dedicated single-key write that deliberately doesn't reset the connected-once flag or WiFi cache) and prefers it over the provisioned shared token from the next request on. Config response buffer grows 256->512. Both board variants compile clean; new firmware also works against an old server (which ignores ?id=) and old firmware against this server (the phase A legacy mapping), so either deploy order survives. Server: /claim lands the captive-portal redirect -- claim-gated signup (a valid unclaimed/unregistered device id IS the enrollment invitation), pending claims for the user-beats-the-frame race (auto-attached at self-registration, 24h expiry), and a waiting page that refreshes until the frame checks in. Unclaimed/unconfigured frames get a rendered instruction placeholder with a QR from /frame/image (200, never an error loop) -- new qrcode dep, placeholder shares the exact quantize/pack path photos use. The on-frame manage QR now resolves to a limited no-login page: scans of / carrying device credentials (new ?id&token or the legacy shared token) 303 to /m/<manage_token>, which allows exactly view queue, show-next, advance, back, and scoped thumbnails -- no settings, no removal, no other frames. Full control means logging in. One real protocol hole found by simulating full wake cycles: after self-registration the device could never authenticate again (the wake cycle fetches the image BEFORE /frame/config delivers its token). require_device now treats the id itself as the credential until the first authenticated request flips device_token_ack -- the same trust level as open registration, closing permanently once the handshake completes.
This commit is contained in:
@@ -11,13 +11,37 @@
|
||||
#define FRAME_CFG_TOKEN_MAX_LEN 64
|
||||
#define FRAME_AP_PASSWORD_LEN 10
|
||||
|
||||
#define FRAME_DEVICE_ID_LEN 12 /* 6-byte STA MAC as lowercase hex */
|
||||
|
||||
typedef struct {
|
||||
char sta_ssid[FRAME_CFG_SSID_MAX_LEN + 1];
|
||||
char sta_password[FRAME_CFG_PASSWORD_MAX_LEN + 1];
|
||||
char toolsserver[FRAME_CFG_SERVER_MAX_LEN + 1];
|
||||
char access_token[FRAME_CFG_TOKEN_MAX_LEN + 1]; /* optional; matches the server's MANAGEMENT_TOKEN */
|
||||
char access_token[FRAME_CFG_TOKEN_MAX_LEN + 1]; /* optional; legacy shared MANAGEMENT_TOKEN */
|
||||
/* Per-frame token issued by the server via GET /frame/config after
|
||||
* this device first introduces itself by id -- preferred over
|
||||
* access_token once present (see frame_client.c's build_url). Not
|
||||
* set at the captive portal; empty until the server pushes one. */
|
||||
char device_token[FRAME_CFG_TOKEN_MAX_LEN + 1];
|
||||
} frame_config_t;
|
||||
|
||||
/**
|
||||
* This device's stable identity as reported to the server (?id= on every
|
||||
* request): the full 6-byte STA MAC as 12 lowercase hex chars. Derived
|
||||
* from the same MAC the provisioning AP SSID suffix comes from; never
|
||||
* stored. out must hold at least FRAME_DEVICE_ID_LEN + 1 bytes.
|
||||
*/
|
||||
void frame_device_id_get(char *out, size_t out_size);
|
||||
|
||||
/**
|
||||
* Persists (only) the server-issued per-frame device token -- called
|
||||
* from the wake cycle when GET /frame/config delivers one. Deliberately
|
||||
* touches nothing else: unlike frame_config_save() it must not reset
|
||||
* the connected-once flag or invalidate the WiFi fast-connect cache,
|
||||
* since nothing about the network changed.
|
||||
*/
|
||||
void frame_config_set_device_token(const char *token);
|
||||
|
||||
/**
|
||||
* Loads the saved home-network config from NVS.
|
||||
* Returns ESP_ERR_NVS_NOT_FOUND if the device has never been provisioned.
|
||||
|
||||
Reference in New Issue
Block a user