fix: serve the device paths with or without a trailing slash
The panel's HTTP client does not follow redirects. It asks for /api/setup/ with a trailing slash, Next answered 308 to normalise it, and the firmware reported "returned code is not OK. Code - 308" and gave up. Never having obtained a token, it then called /api/display with an empty one, got 401, and told the user it could not reach the API. Not TLS, not the network, not the port — a slash. Two earlier fixes were aimed at hypotheses the evidence did not support: a certificate chain the firmware genuinely cannot validate, and a port the shop's network turned out not to block. Both were reasoned from silence, because neither Traefik nor a production Next server logs requests by default. The answer came from a packet capture, and from the device's own words. /api/log now accepts a report from a panel that cannot authenticate. Refusing it with a 401 threw away the one diagnostic that mattered: the firmware was saying exactly what was wrong and we were discarding the message. Nothing is stored — the rows would reference a device that does not exist — but it reaches the server log, and the route was already rate-limited. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
@@ -217,11 +217,19 @@ describe.skipIf(!hasDatabase)('device API', () => {
|
||||
});
|
||||
|
||||
describe('POST /api/log', () => {
|
||||
it('refuses a request with no token', async () => {
|
||||
it('accepts a log from a device that cannot authenticate, without storing it', async () => {
|
||||
// A panel that cannot authenticate is precisely the panel whose account
|
||||
// of the failure is worth having: this is how a 308 on /api/setup/ was
|
||||
// finally diagnosed, after a 401 had been discarding the evidence.
|
||||
const response = await log(
|
||||
deviceRequest('/api/log', {}, { method: 'POST', body: '{"logs":[]}' }),
|
||||
deviceRequest(
|
||||
'/api/log',
|
||||
{ ID: MAC },
|
||||
{ method: 'POST', body: '{"logs":[{"message":"returned code is not OK. Code - 308"}]}' },
|
||||
),
|
||||
);
|
||||
expect(response.status).toBe(401);
|
||||
expect(response.status).toBe(204);
|
||||
expect(await prisma.deviceLog.count()).toBe(0);
|
||||
});
|
||||
|
||||
it('stores what the firmware reports', async () => {
|
||||
|
||||
Reference in New Issue
Block a user