fix: let the panel reach the API over plain HTTP, deliberately
The e-ink firmware carries a certificate-authority bundle fixed when it was built, so it cannot validate a chain rooted in an authority created afterwards. Let's Encrypt's ISRG Root YR was issued in May 2026 and is not even in an up-to-date Ubuntu CA bundle yet; the kit's firmware predates it. The handshake fails before a request is ever sent, which is why neither Traefik nor the application saw anything at all while the device reported "API connection cannot be established". Ruled out first, with evidence: TLS 1.2 and the ECDHE-RSA-AES-GCM suites an ESP32 needs are both offered, and the intermediate is not cross-signed by an older root, so no alternate path exists in what is served. A Traefik router now serves four device paths over :80, ahead of the entrypoint-wide redirect. The administration stays on TLS. The device token travels in clear; it is used for nothing else and is revocable from the settings page, and the image URL is an unguessable content hash. DEVICE_ALLOW_HTTP existed but was never read — a setting that does nothing misrepresents what it protects. The device routes now refuse an unencrypted request unless it is set, so opening this door is a written decision rather than the silent consequence of a proxy change. DEPLOY.md records the whole diagnosis, including the commands that distinguish a TLS failure from an application one, and what to do the day the firmware learns the new roots. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
+9
-3
@@ -58,9 +58,15 @@ AUTHENTIK_ADMIN_GROUP=horaires-admins
|
||||
# Format d'image servi à l'appareil. Le firmware Seeed référence des .bmp ;
|
||||
# basculer sur `png` si l'appareil refuse le BMP.
|
||||
DEVICE_IMAGE_FORMAT=bmp
|
||||
# Autorise l'appareil à appeler l'API en clair (HTTP). À n'activer que si le
|
||||
# firmware ESP32 échoue sur la chaîne TLS. Le jeton d'appareil circulerait alors
|
||||
# en clair : il est distinct de tout autre secret et révocable depuis /admin/parametres.
|
||||
# Autorise l'appareil à appeler l'API en clair (HTTP). Les routes de l'écran
|
||||
# REFUSENT une requête non chiffrée tant que ce réglage vaut autre chose que
|
||||
# « true » : c'est une décision explicite, pas un effet de bord d'une
|
||||
# configuration de proxy.
|
||||
#
|
||||
# À activer quand le firmware ESP32 ne peut pas valider la chaîne TLS — le cas
|
||||
# lorsque la racine Let's Encrypt est plus récente que le firmware lui-même.
|
||||
# Le jeton d'appareil circule alors en clair : il ne sert à rien d'autre et se
|
||||
# révoque depuis /admin/parametres. Voir DEPLOY.md.
|
||||
DEVICE_ALLOW_HTTP=false
|
||||
# Intervalles de réveil, en secondes. Court quand la boutique est ouverte ou sur le
|
||||
# point de changer d'état, long la nuit et les jours de fermeture.
|
||||
|
||||
Reference in New Issue
Block a user