Files
espresso_frame/firmware/main/wifi_provisioning.h
T
tfaour 6c7468a36e
Build and push server image / build-and-push (push) Successful in 31s
Add HTTPS support and a management-token gate for the web UI
ESP32 side can now reach the tools server over HTTPS: the Tools Server
field accepts an https:// address for a TLS-terminating reverse proxy
in front of the server (which still only ever speaks plain HTTP
itself), trusting Cloudflare's Origin CA root (embedded at build time)
since that's the common way to get a real cert on a private origin.
Every URL the device builds -- image fetch, config check, manage-menu
data, the QR codes' own links -- goes through one build_url() helper
that picks the scheme from what's configured.

Also adds an optional MANAGEMENT_TOKEN (docker-compose.yml) that gates
the web UI (/, /api/*) behind a shared secret -- unset by default, so
existing trusted-LAN deployments are unaffected. The same token is
entered once during the ESP32's captive-portal setup and gets baked
into the manage-menu's QR code (?token=...), so scanning it just works;
visiting the page without a valid token shows a plain entry prompt
instead of the config UI, and a valid query-param hit sets a cookie so
the page's own fetch()/<img> calls stay authorized for the rest of the
visit. Device-facing /frame/* endpoints are unaffected -- a separate,
already-documented trust boundary.
2026-07-19 09:42:38 -04:00

86 lines
3.3 KiB
C

#pragma once
#include <stdbool.h>
#include <stddef.h>
#include "esp_err.h"
#define FRAME_CFG_SSID_MAX_LEN 32
#define FRAME_CFG_PASSWORD_MAX_LEN 64
#define FRAME_CFG_SERVER_MAX_LEN 128
#define FRAME_CFG_TOKEN_MAX_LEN 64
#define FRAME_AP_PASSWORD_LEN 10
typedef struct {
char sta_ssid[FRAME_CFG_SSID_MAX_LEN + 1];
char sta_password[FRAME_CFG_PASSWORD_MAX_LEN + 1];
char toolsserver[FRAME_CFG_SERVER_MAX_LEN + 1];
char access_token[FRAME_CFG_TOKEN_MAX_LEN + 1]; /* optional; matches the server's MANAGEMENT_TOKEN */
} frame_config_t;
/**
* Loads the saved home-network config from NVS.
* Returns ESP_ERR_NVS_NOT_FOUND if the device has never been provisioned.
*/
esp_err_t frame_config_load(frame_config_t *out);
/** Saves the home-network config to NVS. Resets the "connected once"
* flag below, since this is a fresh (re)provisioning event. */
esp_err_t frame_config_save(const frame_config_t *cfg);
/**
* Whether the device has already shown the post-connect status screen at
* least once since the current WiFi config was saved. Used so the status
* screen always shows on the first connection after (re)provisioning, but
* is skipped on later successful wakes to save an extra refresh.
*/
bool frame_config_has_connected_once(void);
/** Marks the status screen as having been shown for the current WiFi config. */
void frame_config_mark_connected_once(void);
/**
* Erases the stored home-network config (SSID/password/tools server) so the
* device falls back into provisioning on its next boot. Leaves the softAP
* identity (SSID/password) untouched, since that's tied to the device
* itself, not a particular home network -- regenerating it on every reset
* would force re-scanning the join QR code for no reason. Also leaves the
* last-displayed-photo CRC (below) untouched -- it describes what's
* physically on screen, not network config, and stays valid regardless.
*/
void frame_config_clear(void);
/**
* Returns the CRC32 of the last frame actually written to the panel via a
* physical refresh. Returns ESP_ERR_NVS_NOT_FOUND if nothing's been
* displayed yet.
*/
esp_err_t frame_config_get_last_display_crc32(uint32_t *out);
/** Records the CRC32 of the frame just displayed, for next time. */
void frame_config_set_last_display_crc32(uint32_t crc32);
/**
* Invalidates the tracked last-displayed-photo CRC. Call this whenever
* something other than a tracked photo fetch writes to the panel (status
* screens, QR onboarding) -- otherwise a later photo fetch that happens
* to produce the same CRC as whatever photo was showing *before* the
* panel got overwritten would wrongly skip refreshing back onto it,
* leaving the other screen stuck on-screen indefinitely.
*/
void frame_config_invalidate_last_display_crc32(void);
/**
* Returns this device's provisioning AP identity: a fixed SSID (from
* Kconfig) and a password that's generated once on first use and persisted
* in NVS from then on. The password is drawn from an easy-to-type charset
* since it's shown on the e-ink panel (as both a QR code and plaintext) and
* may need to be typed in by hand.
*/
void ap_identity_get(char *ssid_out, size_t ssid_len, char *pass_out, size_t pass_len);
/**
* Brings up the ESPRESSO softAP + captive portal (DNS + HTTP) so the user
* can provision the device. Does not return.
*/
void wifi_provisioning_start(void);