81365eed8919fb4afe0d7400d5af5232f429bbaf
The shared legacy password is still needed for boards on pre-HMAC firmware, but it was accepted for any username. Now: - controlled by MQTT_ALLOW_LEGACY_PASSWORD (config.py, default true; documented in .env.example) so it can be switched off without a deploy, - only accepted for device-shaped usernames (uppercase alphanumeric segments joined by "-", optional "-kiosk"), never for app_ users or any other shape, - every successful legacy login is logged at WARNING with the username, rate-limited to once per username per hour, so the boards still depending on it are visible before the flag is turned off. HMAC auth is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BellSystems Admin Panel
Self-hosted web admin panel for managing BellSystems devices, melodies, users, and MQTT communications.
Tech Stack
- Backend: Python / FastAPI
- Frontend: React + Tailwind CSS (Vite)
- Database: Google Firestore (Firebase Admin SDK)
- MQTT: Mosquitto (paho-mqtt)
- Auth: JWT with role-based access control
- Deployment: Docker Compose + Nginx
Getting Started
# Clone the repo
git clone <your-gitea-url>/bellsystems-admin.git
cd bellsystems-admin
# Copy env template and fill in your values
cp .env.example .env
# Place your Firebase service account key in the project root
# (file is gitignored — never commit it)
# Start everything
docker compose up --build
Project Structure
bellsystems-admin/
├── backend/ # FastAPI API server
├── frontend/ # React SPA
├── nginx/ # Reverse proxy config
├── docker-compose.yml
└── .env
Documentation
See BellSystems_AdminPanel_Strategy.md for the full architecture and build plan.
Description
BellSystems Contol Panel.
Handles everything from Devices to Clients.
Firebase / Mosquitto / Device Control / logging...
33 MiB
Languages
JavaScript
72.3%
Python
12.8%
HTML
12.4%
CSS
2.5%