feat(mqtt-auth): put legacy "vesper" password behind MQTT_ALLOW_LEGACY_PASSWORD
The shared legacy password is still needed for boards on pre-HMAC firmware, but it was accepted for any username. Now: - controlled by MQTT_ALLOW_LEGACY_PASSWORD (config.py, default true; documented in .env.example) so it can be switched off without a deploy, - only accepted for device-shaped usernames (uppercase alphanumeric segments joined by "-", optional "-kiosk"), never for app_ users or any other shape, - every successful legacy login is logged at WARNING with the username, rate-limited to once per username per hour, so the boards still depending on it are visible before the flag is turned off. HMAC auth is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -17,6 +17,10 @@ MOSQUITTO_PASSWORD_FILE=/etc/mosquitto/passwd
|
||||
MQTT_CLIENT_ID=bellsystems-admin-panel
|
||||
# HMAC secret used to derive per-device MQTT passwords (must match firmware)
|
||||
MQTT_SECRET=change-me-in-production
|
||||
# Accept the legacy shared "vesper" MQTT password for device usernames
|
||||
# (old firmware). Each use is logged once/hour per board; set to false
|
||||
# once no boards show up in those logs.
|
||||
MQTT_ALLOW_LEGACY_PASSWORD=true
|
||||
|
||||
# App
|
||||
BACKEND_CORS_ORIGINS=["http://localhost:5173"]
|
||||
|
||||
Reference in New Issue
Block a user