chore: drop the plain-HTTP route now the panel is proven on TLS

The transport log settles it: the device reaches the server over https
and validates the Let's Encrypt chain without trouble. The dedicated
port, the Traefik entrypoint and the plain-HTTP router were all built on
a hypothesis the evidence has since refused.

DEVICE_ALLOW_HTTP goes back to false, so the device routes refuse an
unencrypted request again.

DEPLOY.md is rewritten around the real cause — the firmware does not
follow redirects, and a trailing slash was answered with a 308 — and
records the three hypotheses that were wrong, so nobody spends another
evening on them. It also names the trap that made this slow: Traefik,
a production Next server and tcpdump were each read as saying "no
traffic" when all three were simply silent by default.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
2026-09-21 23:19:45 +02:00
co-authored by Claude Opus 5
parent 235af90aed
commit 13abcf3242
3 changed files with 67 additions and 81 deletions
+3 -2
View File
@@ -63,8 +63,9 @@ DEVICE_IMAGE_FORMAT=bmp
# « true » : c'est une décision explicite, pas un effet de bord d'une
# configuration de proxy.
#
# À activer quand le firmware ESP32 ne peut pas valider la chaîne TLS — le cas
# lorsque la racine Let's Encrypt est plus récente que le firmware lui-même.
# À activer seulement si le firmware ESP32 s'avère incapable de valider la
# chaîne TLS. Celui du kit Seeed (1.5.12) y parvient sans problème : ne pas
# supposer le contraire devant une panne de connexion, voir DEPLOY.md.
# Le jeton d'appareil circule alors en clair : il ne sert à rien d'autre et se
# révoque depuis /admin/parametres. Voir DEPLOY.md.
DEVICE_ALLOW_HTTP=false