fix: let the panel reach the API over plain HTTP, deliberately

The e-ink firmware carries a certificate-authority bundle fixed when it
was built, so it cannot validate a chain rooted in an authority created
afterwards. Let's Encrypt's ISRG Root YR was issued in May 2026 and is
not even in an up-to-date Ubuntu CA bundle yet; the kit's firmware
predates it. The handshake fails before a request is ever sent, which is
why neither Traefik nor the application saw anything at all while the
device reported "API connection cannot be established".

Ruled out first, with evidence: TLS 1.2 and the ECDHE-RSA-AES-GCM suites
an ESP32 needs are both offered, and the intermediate is not
cross-signed by an older root, so no alternate path exists in what is
served.

A Traefik router now serves four device paths over :80, ahead of the
entrypoint-wide redirect. The administration stays on TLS. The device
token travels in clear; it is used for nothing else and is revocable
from the settings page, and the image URL is an unguessable content hash.

DEVICE_ALLOW_HTTP existed but was never read — a setting that does
nothing misrepresents what it protects. The device routes now refuse an
unencrypted request unless it is set, so opening this door is a written
decision rather than the silent consequence of a proxy change.

DEPLOY.md records the whole diagnosis, including the commands that
distinguish a TLS failure from an application one, and what to do the
day the firmware learns the new roots.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
This commit is contained in:
2026-09-21 22:17:16 +02:00
co-authored by Claude Opus 5
parent efd91c3e8e
commit eae3f89aca
8 changed files with 192 additions and 16 deletions
+9 -3
View File
@@ -58,9 +58,15 @@ AUTHENTIK_ADMIN_GROUP=horaires-admins
# Format d'image servi à l'appareil. Le firmware Seeed référence des .bmp ;
# basculer sur `png` si l'appareil refuse le BMP.
DEVICE_IMAGE_FORMAT=bmp
# Autorise l'appareil à appeler l'API en clair (HTTP). À n'activer que si le
# firmware ESP32 échoue sur la chaîne TLS. Le jeton d'appareil circulerait alors
# en clair : il est distinct de tout autre secret et révocable depuis /admin/parametres.
# Autorise l'appareil à appeler l'API en clair (HTTP). Les routes de l'écran
# REFUSENT une requête non chiffrée tant que ce réglage vaut autre chose que
# « true » : c'est une décision explicite, pas un effet de bord d'une
# configuration de proxy.
#
# À activer quand le firmware ESP32 ne peut pas valider la chaîne TLS — le cas
# lorsque la racine Let's Encrypt est plus récente que le firmware lui-même.
# Le jeton d'appareil circule alors en clair : il ne sert à rien d'autre et se
# révoque depuis /admin/parametres. Voir DEPLOY.md.
DEVICE_ALLOW_HTTP=false
# Intervalles de réveil, en secondes. Court quand la boutique est ouverte ou sur le
# point de changer d'état, long la nuit et les jours de fermeture.