The frame-claiming pipeline, end to end. Firmware: every request now carries ?id=<12-hex STA MAC> via build_url (mirrored in build_ota_url), and the captive portal's success page became a redirect that hands the user's browser to <server>/claim?device_id=... after ~7s -- enough time for the phone to drop the provisioning AP while the device reboots. The server pushes a per-frame device token through /frame/config during a one-time handshake; the firmware persists it to NVS (a dedicated single-key write that deliberately doesn't reset the connected-once flag or WiFi cache) and prefers it over the provisioned shared token from the next request on. Config response buffer grows 256->512. Both board variants compile clean; new firmware also works against an old server (which ignores ?id=) and old firmware against this server (the phase A legacy mapping), so either deploy order survives. Server: /claim lands the captive-portal redirect -- claim-gated signup (a valid unclaimed/unregistered device id IS the enrollment invitation), pending claims for the user-beats-the-frame race (auto-attached at self-registration, 24h expiry), and a waiting page that refreshes until the frame checks in. Unclaimed/unconfigured frames get a rendered instruction placeholder with a QR from /frame/image (200, never an error loop) -- new qrcode dep, placeholder shares the exact quantize/pack path photos use. The on-frame manage QR now resolves to a limited no-login page: scans of / carrying device credentials (new ?id&token or the legacy shared token) 303 to /m/<manage_token>, which allows exactly view queue, show-next, advance, back, and scoped thumbnails -- no settings, no removal, no other frames. Full control means logging in. One real protocol hole found by simulating full wake cycles: after self-registration the device could never authenticate again (the wake cycle fetches the image BEFORE /frame/config delivers its token). require_device now treats the id itself as the credential until the first authenticated request flips device_token_ack -- the same trust level as open registration, closing permanently once the handshake completes.
115 lines
3.7 KiB
HTML
115 lines
3.7 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<title>ESPRESSO Setup</title>
|
|
<style>
|
|
body {
|
|
font-family: Arial, sans-serif;
|
|
background-color: #f4f4f9;
|
|
display: flex;
|
|
justify-content: center;
|
|
align-items: center;
|
|
height: 100vh;
|
|
margin: 0;
|
|
}
|
|
.container {
|
|
background-color: white;
|
|
padding: 30px;
|
|
border-radius: 8px;
|
|
box-shadow: 0 4px 10px rgba(0, 0, 0, 0.1);
|
|
text-align: center;
|
|
width: 100%;
|
|
max-width: 320px;
|
|
}
|
|
h1 {
|
|
color: #333;
|
|
font-size: 24px;
|
|
margin-top: 0;
|
|
}
|
|
p {
|
|
color: #666;
|
|
font-size: 14px;
|
|
margin-bottom: 25px;
|
|
}
|
|
.input-group {
|
|
text-align: left;
|
|
margin-bottom: 15px;
|
|
}
|
|
label {
|
|
display: block;
|
|
font-size: 12px;
|
|
font-weight: bold;
|
|
color: #333;
|
|
margin-bottom: 5px;
|
|
}
|
|
input[type="text"],
|
|
input[type="password"] {
|
|
width: 100%;
|
|
padding: 10px;
|
|
box-sizing: border-box;
|
|
border: 1px solid #ccc;
|
|
border-radius: 4px;
|
|
font-size: 14px;
|
|
}
|
|
button {
|
|
background-color: #007BFF;
|
|
color: white;
|
|
border: none;
|
|
padding: 12px;
|
|
width: 100%;
|
|
border-radius: 4px;
|
|
font-size: 16px;
|
|
cursor: pointer;
|
|
margin-top: 10px;
|
|
}
|
|
button:hover {
|
|
background-color: #0056b3;
|
|
}
|
|
</style>
|
|
</head>
|
|
<body>
|
|
|
|
<div class="container">
|
|
<h1>Welcome to ESPRESSO</h1>
|
|
<p>Please connect me to your local wifi network</p>
|
|
|
|
<!-- The action attribute should point to wherever your server handles the data -->
|
|
<!-- maxlength on each field below mirrors its NVS buffer size in
|
|
wifi_provisioning.h (FRAME_CFG_*_MAX_LEN) -- firmware silently
|
|
truncates past that length, so keep these in sync if those
|
|
change. -->
|
|
<form action="/save_config" method="POST">
|
|
|
|
<div class="input-group">
|
|
<label for="ssid">Wifi SSID</label>
|
|
<input type="text" id="ssid" name="ssid" placeholder="Network Name" maxlength="32" required>
|
|
</div>
|
|
|
|
<div class="input-group">
|
|
<label for="password">Password</label>
|
|
<input type="password" id="password" name="password" placeholder="Network Password" maxlength="64">
|
|
</div>
|
|
|
|
<div class="input-group">
|
|
<label for="toolsserver">Tools Server</label>
|
|
<input type="text" id="toolsserver" name="toolsserver" placeholder="e.g. 192.168.1.50:8080 or https://frame.example.com" maxlength="128" required>
|
|
</div>
|
|
|
|
<div class="input-group">
|
|
<label for="access_token">Access Token (optional — only for older servers)</label>
|
|
<input type="text" id="access_token" name="access_token" placeholder="usually blank; current servers issue one automatically" maxlength="64">
|
|
</div>
|
|
|
|
<p style="font-size: 13px; color: #555;">After saving, this page will
|
|
take you to the server to claim your frame — reconnect to
|
|
your normal WiFi if it doesn't happen automatically.</p>
|
|
|
|
<button type="submit">Submit</button>
|
|
|
|
</form>
|
|
</div>
|
|
|
|
</body>
|
|
</html> |