From 43f21dbf6c20657645de83cad99a43ef845c459c Mon Sep 17 00:00:00 2001 From: bonamin Date: Mon, 28 Sep 2026 17:42:06 +0300 Subject: [PATCH] docs: pack README - proxy :8443 and TLS key files Co-Authored-By: Claude Opus 5.5 --- docs/README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/README.md b/docs/README.md index bc92fa0..dc41d7b 100644 --- a/docs/README.md +++ b/docs/README.md @@ -15,7 +15,7 @@ This folder is its **own git repo**, nested inside the `xenia-pos` parent repo. | `local_backend` | FastAPI + SQLAlchemy + SQLite (`/app/data/pos.db`) | 8000 | only through proxy / inner nginx | `pos-backend` | | `waiter_pwa` | React + Vite + vite-plugin-pwa, axios, zustand, react-query, Dexie (IndexedDB) | 5173 | **`http://`** (80, LAN only) · `https://waiter.` / `https://` (443) | `pos-waiter` | | `manager_dashboard` | React + Vite | 5174 | **`http://:8081`** (LAN only; `http:///manager` redirects there) · `https://manager.` (443) · `https://:4443` | `pos-manager` | -| `proxy` | nginx:alpine | — | 80, 443, 4443, 8081. See the header of `nginx-proxy/nginx.conf` for the full routing map | stock | +| `proxy` | nginx:alpine | — | 80, 443, 4443, 8081, 8443. See the header of `nginx-proxy/nginx.conf` for the full routing map. Waits for the backend to be healthy | stock | ### Request path in production Phones normally use **plain HTTP by LAN IP** (`http://` → proxy:80 default_server). Only private source IPs are allowed; everything else gets 403. @@ -35,6 +35,7 @@ The manager calls the API **same-origin, with relative paths**. The waiter app r |---|---| | `local_backend/main.py` | App setup, router registration, CORS, **`_run_migrations()`** | | `local_backend/services/lan_ip.py`, `services/netinfo_helper.py` | Which LAN IP phones get (override → live detection → `HOST_IP`); the `netinfo` host-network helper | +| `local_backend/services/tls_identity.py`, `waiter_pwa/android/.../TrustStore.java`, `src/native/tls.js` | Encrypted LAN link: the server's self-managed key and cert, and the app's key pinning | | `local_backend/services/cloud_sync.py` | Every call to the cloud (see the parent's `docs/reference/cloud-contract.md`) | | `local_backend/roles.py`, `routers/deps.py` | Roles, permission checks, auth dependencies | | `local_backend/routers/ws.py` | Real-time event stream (seq + cursor replay) |