8a668ca60fed4c1e4465962aa702a1d27b87e4f7
The remote FlutterFlow app connects to Mosquitto as "app_<firebase_uid>" with a Firebase ID token as the password, so no per-user MQTT accounts need to exist anywhere. For app_ usernames, POST /mqtt/auth/user now: - verifies the token with firebase_admin.auth.verify_id_token (check_revoked=True), - requires the decoded uid to equal the uid in the username, - requires a users doc with that `uid` field (queried, not by doc id) whose status is not "blocked" (same meaning as users.service.block_user). It returns 200/403 and logs the deny reason - never the token. app_ usernames never fall through to the HMAC / legacy "vesper" check. Device and kiosk auth are unchanged. App users are still denied every topic by the existing ACL until the app ACL lands in the next commit. Both handlers are now plain `def` so the blocking Firestore / Firebase calls run in FastAPI's threadpool instead of stalling the event loop. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
BellSystems Admin Panel
Self-hosted web admin panel for managing BellSystems devices, melodies, users, and MQTT communications.
Tech Stack
- Backend: Python / FastAPI
- Frontend: React + Tailwind CSS (Vite)
- Database: Google Firestore (Firebase Admin SDK)
- MQTT: Mosquitto (paho-mqtt)
- Auth: JWT with role-based access control
- Deployment: Docker Compose + Nginx
Getting Started
# Clone the repo
git clone <your-gitea-url>/bellsystems-admin.git
cd bellsystems-admin
# Copy env template and fill in your values
cp .env.example .env
# Place your Firebase service account key in the project root
# (file is gitignored — never commit it)
# Start everything
docker compose up --build
Project Structure
bellsystems-admin/
├── backend/ # FastAPI API server
├── frontend/ # React SPA
├── nginx/ # Reverse proxy config
├── docker-compose.yml
└── .env
Documentation
See BellSystems_AdminPanel_Strategy.md for the full architecture and build plan.
Description
BellSystems Contol Panel.
Handles everything from Devices to Clients.
Firebase / Mosquitto / Device Control / logging...
33 MiB
Languages
JavaScript
72.3%
Python
12.8%
HTML
12.4%
CSS
2.5%