From 61e9bfab7c4b248db050138577eaa31f570353be Mon Sep 17 00:00:00 2001 From: bonamin Date: Wed, 30 Sep 2026 01:00:43 +0300 Subject: [PATCH] docs(mqtt-auth): note old-firmware boards subscribe to vesper/{sn}/control Broker logs after the 2026-09-30 restart show some boards (PV26B02BP01R01, BSVSPR-26C20B-STD10R-2KCDPH) subscribing to vesper/{serial}/control rather than control/command. The app ACL only allows publishing to control/command, so the app can't command those boards until their firmware is updated. Recorded so nobody widens the ACL by accident. Co-Authored-By: Claude Opus 5.5 --- docs/mqtt-app-user-auth.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/mqtt-app-user-auth.md b/docs/mqtt-app-user-auth.md index 2577fa9..6231064 100644 --- a/docs/mqtt-app-user-auth.md +++ b/docs/mqtt-app-user-auth.md @@ -146,6 +146,13 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`. ## Known gaps / decisions +- **Old-firmware boards use a different command topic.** Broker logs (2026-09-30) show + some boards (e.g. `PV26B02BP01R01`, `BSVSPR-26C20B-STD10R-2KCDPH`) subscribing to + `vesper/{serial}/control`, not `vesper/{serial}/control/command`. The app ACL only + allows publishing to `control/command`, so the app cannot command those boards until + they run current firmware. (The Console's own `publish_command` has the same limitation.) + Do not widen the ACL to `control` without deciding it deliberately. + - **FlutterFlow writes to `user_list`.** If the app changes `user_list` directly in Firestore (e.g. a claim flow), it must also update `device_serials` the same way (ArrayUnion / ArrayRemove of the serial on the user doc). Otherwise that user