The frame-claiming pipeline, end to end. Firmware: every request now carries ?id=<12-hex STA MAC> via build_url (mirrored in build_ota_url), and the captive portal's success page became a redirect that hands the user's browser to <server>/claim?device_id=... after ~7s -- enough time for the phone to drop the provisioning AP while the device reboots. The server pushes a per-frame device token through /frame/config during a one-time handshake; the firmware persists it to NVS (a dedicated single-key write that deliberately doesn't reset the connected-once flag or WiFi cache) and prefers it over the provisioned shared token from the next request on. Config response buffer grows 256->512. Both board variants compile clean; new firmware also works against an old server (which ignores ?id=) and old firmware against this server (the phase A legacy mapping), so either deploy order survives. Server: /claim lands the captive-portal redirect -- claim-gated signup (a valid unclaimed/unregistered device id IS the enrollment invitation), pending claims for the user-beats-the-frame race (auto-attached at self-registration, 24h expiry), and a waiting page that refreshes until the frame checks in. Unclaimed/unconfigured frames get a rendered instruction placeholder with a QR from /frame/image (200, never an error loop) -- new qrcode dep, placeholder shares the exact quantize/pack path photos use. The on-frame manage QR now resolves to a limited no-login page: scans of / carrying device credentials (new ?id&token or the legacy shared token) 303 to /m/<manage_token>, which allows exactly view queue, show-next, advance, back, and scoped thumbnails -- no settings, no removal, no other frames. Full control means logging in. One real protocol hole found by simulating full wake cycles: after self-registration the device could never authenticate again (the wake cycle fetches the image BEFORE /frame/config delivers its token). require_device now treats the id itself as the credential until the first authenticated request flips device_token_ack -- the same trust level as open registration, closing permanently once the handshake completes.
73 lines
2.9 KiB
HTML
73 lines
2.9 KiB
HTML
{% extends "base.html" %}
|
|
|
|
{% block page_class %}page-narrow{% endblock %}
|
|
|
|
{% block subtitle %}
|
|
<p class="sub">Claim your frame</p>
|
|
{% endblock %}
|
|
|
|
{% block extra_head %}
|
|
{% if status == "unregistered" %}<meta http-equiv="refresh" content="6">{% endif %}
|
|
{% endblock %}
|
|
|
|
{% block content %}
|
|
{% if error %}<div class="status err">{{ error }}</div>{% endif %}
|
|
|
|
<section class="card">
|
|
<h2 class="card-title">Frame <code>{{ device_id }}</code></h2>
|
|
|
|
{% if status == "claimed_yours" %}
|
|
<div class="status ok">This frame is linked to your account.</div>
|
|
<p class="sub">It will show up in your frame list. If it was just
|
|
provisioned, give it a minute to connect and fetch its first image.</p>
|
|
<p><a href="/">Go to your frames</a></p>
|
|
|
|
{% elif status == "claimed" %}
|
|
<p class="sub">This frame already belongs to someone. If it's yours,
|
|
ask them (or an admin) to link your account to it.</p>
|
|
|
|
{% elif status == "unregistered" %}
|
|
{% if pending_yours %}
|
|
<div class="status ok">Claim recorded.</div>
|
|
<p class="sub">Waiting for the frame to connect for the first time --
|
|
it links to your account automatically the moment it checks in.
|
|
This page refreshes itself; it's safe to close, too.</p>
|
|
{% else %}
|
|
<p class="sub">The frame hasn't checked in yet -- it's probably still
|
|
restarting and joining your WiFi. This page refreshes itself.
|
|
{% if user %}You can claim it now anyway; it'll attach when it
|
|
arrives.{% endif %}</p>
|
|
{% endif %}
|
|
{% elif status == "unclaimed" %}
|
|
<p class="sub">This frame is connected and ready to be claimed.</p>
|
|
{% endif %}
|
|
|
|
{% if user and status in ("unclaimed", "unregistered") and not pending_yours %}
|
|
<form method="post" action="/claim">
|
|
<input type="hidden" name="device_id" value="{{ device_id }}">
|
|
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
|
|
<button type="submit">Claim this frame</button>
|
|
</form>
|
|
{% endif %}
|
|
</section>
|
|
|
|
{% if not user and status in ("unclaimed", "unregistered") %}
|
|
<section class="card">
|
|
<h2 class="card-title">Create your account</h2>
|
|
<p class="sub">A valid frame is your invitation -- set up an account to
|
|
claim it. Already have one?
|
|
<a href="/login?next=/claim%3Fdevice_id%3D{{ device_id }}">Log in instead</a>.</p>
|
|
<form method="post" action="/claim/signup">
|
|
<input type="hidden" name="device_id" value="{{ device_id }}">
|
|
<label>Username
|
|
<input type="text" name="username" maxlength="64" required autocomplete="username">
|
|
</label>
|
|
<label>Password
|
|
<input type="password" name="password" minlength="8" required autocomplete="new-password">
|
|
</label>
|
|
<button type="submit">Create account & claim frame</button>
|
|
</form>
|
|
</section>
|
|
{% endif %}
|
|
{% endblock %}
|