The panel now pairs, fetches its image and files its logs against this application rather than against the TRMNL cloud. Four endpoints: /api/setup issues a token on first contact, /api/display hands back an image and a wake interval, /api/log stores firmware diagnostics, and /api/device/image/<hash> serves the bytes. The wake interval is where freshness and battery are traded off. In BYOS nothing can be pushed: the device sleeps, wakes, asks and sleeps again. So the interval is short while the shop trades and long overnight, and it is shortened further whenever a change of state falls inside it — the door opening in twenty minutes means waking in twenty-one, whatever the base interval says. The image filename is the hash of its own bytes. The firmware skips the redraw when the name is unchanged, which is the whole battery strategy, and the URL is immutable, unguessable and safe to cache forever. Two integration tests pin this: unchanged data must yield the same filename and store one row, changed hours must yield a different one. MAC addresses are normalised before use. They are a primary key here, and firmwares are inconsistent about case and separators; without this a panel could register twice by capitalising itself differently. Header names are read in both the hyphen and underscore spellings for the same reason — the TRMNL docs and the Seeed sources disagree, and being liberal costs nothing while being wrong costs a blank shop window. Pairing is deliberately made to survive a rendering failure. The token is issued once and only its digest is kept, so a device stranded by a failed response would be registered yet hold no credential, and unable to register again. The welcome image is worth far less than that. This was found by running the flow, not by reading it. satori, yoga and harfbuzz are marked external: bundling rewrites the relative path satori uses to load its WebAssembly, and the renderer dies on a missing hb.wasm. The integration tests run against a real Postgres, in CI too. Mocking Prisma here would only prove the mock works. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
67 lines
2.2 KiB
TypeScript
67 lines
2.2 KiB
TypeScript
/**
|
|
* Device credentials.
|
|
*
|
|
* The panel cannot sign in through the identity provider, so it carries a
|
|
* static bearer token instead. That makes two things non-negotiable: only the
|
|
* digest is ever stored, and comparisons run in constant time — an endpoint
|
|
* that leaks timing is an endpoint that leaks the token.
|
|
*/
|
|
|
|
import { createHash, randomBytes, timingSafeEqual } from 'node:crypto';
|
|
|
|
/** Unambiguous in print: no O/0, no I/1. Friendly ids get read aloud. */
|
|
const FRIENDLY_ALPHABET = 'ABCDEFGHJKLMNPQRSTUVWXYZ23456789';
|
|
|
|
/** 256 bits of entropy, URL-safe so it survives a captive-portal form. */
|
|
export function generateDeviceToken(): string {
|
|
return randomBytes(32).toString('base64url');
|
|
}
|
|
|
|
export function hashToken(token: string): string {
|
|
return createHash('sha256').update(token, 'utf8').digest('hex');
|
|
}
|
|
|
|
/**
|
|
* Constant-time comparison of a presented token against a stored digest.
|
|
*
|
|
* Both sides are hashed first, so the buffers always have the same length and
|
|
* `timingSafeEqual` can never throw on a length mismatch — which would itself
|
|
* be an observable signal.
|
|
*/
|
|
export function tokenMatches(presented: string, storedHash: string): boolean {
|
|
const presentedDigest = Buffer.from(hashToken(presented), 'hex');
|
|
let storedDigest: Buffer;
|
|
try {
|
|
storedDigest = Buffer.from(storedHash, 'hex');
|
|
} catch {
|
|
return false;
|
|
}
|
|
if (storedDigest.length !== presentedDigest.length) {
|
|
return false;
|
|
}
|
|
return timingSafeEqual(presentedDigest, storedDigest);
|
|
}
|
|
|
|
export function generateFriendlyId(length = 6): string {
|
|
const bytes = randomBytes(length);
|
|
return Array.from(bytes, (byte) => FRIENDLY_ALPHABET[byte % FRIENDLY_ALPHABET.length]).join('');
|
|
}
|
|
|
|
/**
|
|
* Normalises a MAC address to upper-case colon-separated form.
|
|
*
|
|
* Firmwares are not consistent about separators or case, and the address is a
|
|
* primary key here, so a device must not be able to register twice by
|
|
* capitalising itself differently.
|
|
*/
|
|
export function normaliseMac(value: string | null | undefined): string | null {
|
|
if (!value) {
|
|
return null;
|
|
}
|
|
const hex = value.replace(/[^0-9a-fA-F]/g, '').toUpperCase();
|
|
if (hex.length !== 12) {
|
|
return null;
|
|
}
|
|
return (hex.match(/.{2}/g) ?? []).join(':');
|
|
}
|