Commit Graph
7 Commits
Author SHA1 Message Date
bonaminandClaude Opus 5.5 81365eed89 feat(mqtt-auth): put legacy "vesper" password behind MQTT_ALLOW_LEGACY_PASSWORD
The shared legacy password is still needed for boards on pre-HMAC
firmware, but it was accepted for any username. Now:
- controlled by MQTT_ALLOW_LEGACY_PASSWORD (config.py, default true;
  documented in .env.example) so it can be switched off without a deploy,
- only accepted for device-shaped usernames (uppercase alphanumeric
  segments joined by "-", optional "-kiosk"), never for app_ users or
  any other shape,
- every successful legacy login is logged at WARNING with the username,
  rate-limited to once per username per hour, so the boards still
  depending on it are visible before the flag is turned off.

HMAC auth is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:03:23 +03:00
bonamin 6f9fd5cba3 fix: Bugs created after the overhaul, performance and layout fixes 2026-03-08 22:30:56 +02:00
bonamin c62188fda6 update: Major Overhaul to all subsystems 2026-03-07 11:36:46 +02:00
bonamin 32a2634739 feat: Phase 3 manufacturing + firmware management 2026-02-27 02:47:08 +02:00
bonamin 8cb639c1bd First Production Push 2026-02-25 21:29:56 +02:00
bonamin 2b48426fe5 Phase 2 Complete by Claude Code 2026-02-17 00:10:37 +02:00
bonamin 19c069949d Phase 0 Complete by ClaudeCode 2026-02-16 20:21:20 +02:00