docs(mqtt-auth): note old-firmware boards subscribe to vesper/{sn}/control

Broker logs after the 2026-09-30 restart show some boards (PV26B02BP01R01,
BSVSPR-26C20B-STD10R-2KCDPH) subscribing to vesper/{serial}/control rather
than control/command. The app ACL only allows publishing to control/command,
so the app can't command those boards until their firmware is updated.
Recorded so nobody widens the ACL by accident.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-30 01:00:43 +03:00
co-authored by Claude Opus 5.5
parent 43102c617d
commit 61e9bfab7c
+7
View File
@@ -146,6 +146,13 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`.
## Known gaps / decisions
- **Old-firmware boards use a different command topic.** Broker logs (2026-09-30) show
some boards (e.g. `PV26B02BP01R01`, `BSVSPR-26C20B-STD10R-2KCDPH`) subscribing to
`vesper/{serial}/control`, not `vesper/{serial}/control/command`. The app ACL only
allows publishing to `control/command`, so the app cannot command those boards until
they run current firmware. (The Console's own `publish_command` has the same limitation.)
Do not widen the ACL to `control` without deciding it deliberately.
- **FlutterFlow writes to `user_list`.** If the app changes `user_list` directly in
Firestore (e.g. a claim flow), it must also update `device_serials` the same way
(ArrayUnion / ArrayRemove of the serial on the user doc). Otherwise that user