# Implementation Priorities - Updated **Date**: 2026-03-03 **Status**: Active Development - Phase 4 Enhancement --- ## 📊 Current Feature Status (2026-03-03) | Feature | Status | Notes | |---------|--------|-------| | **HTTPS** | ✅ 100% | Toggle, cert info, regenerate all working | | **Authentication** | 40% | Basic + WS token auth done; JWT/RBAC remaining | | **Plugin System** | 85% | Hooks wired; remote install remaining | --- ## ✅ COMPLETED: Quick Wins (Done 2026-03-03) ### ~~1.1 HTTPS Settings UI~~ ✅ DONE - [x] Enable/Disable toggle via `POST /api/system/ssl/toggle` - [x] Regenerate Certificate button - [x] SSL info display (expiration, SANs, SHA256 fingerprint) ### ~~1.2 Plugin Hook Wiring~~ ✅ DONE - [x] `trigger_hook("pm3_command", command)` in `pm3_service.py` - [x] `trigger_hook("update_check")` in `update_manager.py` --- ## ✅ ~~PRIORITY 2: WebSocket Security~~ DONE (2026-03-03) - [x] Token store with 24h TTL (`app/backend/api/token_store.py`) - [x] `POST /api/auth/token` - exchanges Basic Auth for WS token - [x] `GET /api/auth/status` - public endpoint to check if auth enabled - [x] WebSocket validates token query param, closes with 4401 if invalid - [x] Frontend fetches token, passes as `?token=` on WS URL - [x] LoginPrompt modal shown when WS returns auth_required - [x] No-op when AUTH_ENABLED=false (existing behavior preserved) --- ## 🟢 PRIORITY 3: Full Authentication System (~3-4 weeks) **Why Important:** Required for production deployment, but large effort. ### Phase A: JWT Implementation (~3-5 days) - [ ] Implement JWT token generation/validation - [ ] Create `/api/auth/login` endpoint - [ ] Create `/api/auth/logout` endpoint - [ ] Token refresh mechanism ### Phase B: Login UI (~2-3 days) - [ ] Create login page (`app/frontend/app/routes/login.tsx`) - [ ] Auth context/state management - [ ] Protected route handling - [ ] 401 error handling and redirect ### Phase C: User Management (~3-5 days) - [ ] User database schema - [ ] Password hashing (bcrypt/argon2) - [ ] User CRUD endpoints - [ ] Multi-user support ### Phase D: RBAC (~3-5 days) - [ ] Role definitions (admin, user, guest) - [ ] Permission system - [ ] Endpoint-level authorization --- ## 🔵 PRIORITY 4: Plugin Ecosystem (~2-3 weeks) ### 4.1 Remote Installation (~1 week) - [ ] GitHub releases integration - [ ] Download/extract/verify plugins - [ ] pip dependency installation ### 4.2 Permission Consent UI (~2-3 days) - [ ] Show permissions before enabling - [ ] Consent dialog with accept/reject ### 4.3 Plugin Configuration (~2-3 days) - [ ] Plugin settings persistence - [ ] Plugin-specific config UI --- ## ✅ COMPLETED (Power Management) ### ~~PRIORITY 1: Power Management~~ ✅ DONE (2025-11-26) - [x] `get_power_restrictions()` method implemented - [x] API endpoint `/api/system/power/restrictions` working - [x] Returns correct response when UPS not detected - [x] Returns correct response when UPS on AC - [x] Returns correct response when UPS on battery - [x] Documentation updated --- ## 🎯 Recommended Implementation Order ### ✅ Done (2026-03-03) 1. ~~HTTPS Settings UI~~ - Complete 2. ~~Plugin Hook Wiring~~ - Complete 3. ~~WebSocket Auth~~ - Complete ### Next Up 1. **JWT for REST endpoints** - Replace Basic Auth with proper tokens 2. **Login Page** - Full auth UI (currently only WS login prompt) 3. **Full Auth System** - Multi-user, RBAC --- ## 📁 Key Files Reference ### HTTPS | File | Lines | Purpose | |------|-------|---------| | `scripts/generate-ssl-cert.sh` | 1-115 | EC P-256 certificate generation | | `scripts/configure-nginx.sh` | 1-91 | nginx config switching | | `nginx/dangerous-pi-https.conf` | 1-161 | TLS 1.2/1.3, HSTS, captive portal | | `app/backend/api/system.py` | 578-794 | SSL API endpoints | | `app/frontend/app/routes/settings.tsx` | 381-394 | UI display (currently read-only) | ### Authentication | File | Purpose | |------|---------| | `app/backend/api/auth.py` | Basic HTTP auth + token endpoints | | `app/backend/api/token_store.py` | In-memory WS auth token store (24h TTL) | | `app/backend/config.py:54` | AUTH_ENABLED setting | | `app/backend/websocket/routes.py` | WebSocket with token validation | | `app/frontend/app/hooks/useWebSocket.ts` | WS manager with auth flow | | `app/frontend/app/components/LoginPrompt.tsx` | Login modal for WS auth | ### Plugins | File | Purpose | |------|---------| | `app/backend/managers/plugin_manager.py` | Full plugin framework (804 lines) | | `app/backend/api/plugins.py` | 7 CRUD endpoints | | `app/backend/services/pm3_service.py` | Triggers `pm3_command` hook | | `app/backend/managers/update_manager.py` | Triggers `update_check` hook | | `app/plugins/hello_world/main.py` | Example hook registration | | `app/frontend/app/routes/settings.tsx` | Plugin management UI |