Security:
- Add token-based WebSocket authentication (closes critical security gap)
- In-memory token store with 24h TTL (token_store.py)
- POST /api/auth/token exchanges Basic Auth for WS token
- GET /api/auth/status public endpoint for auth check
- WebSocket validates token query param, rejects with close code 4401
- Frontend LoginPrompt modal for credential entry
- WebSocket manager handles full auth flow with auth_required state
- No-op when AUTH_ENABLED=false (preserves existing behavior)
HTTPS:
- Wire HTTPS toggle in Settings UI (POST /api/system/ssl/toggle)
- Add certificate regeneration button
- Display SSL info (expiration, SANs, SHA256 fingerprint)
Plugins:
- Wire trigger_hook("pm3_command") in PM3 service
- Wire trigger_hook("update_check") in update manager
Build/Infrastructure:
- Enable NetworkManager in pi-gen AP setup stage
- Add HF booster board detection patch for Proxmark3
- Update LED PWM control patch
- Fix BLE adapter, UPS drivers, WiFi manager improvements
- Update HTTPS support stage script
Documentation:
- Update PROJECT_STATUS.md and IMPLEMENTATION_PRIORITIES.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
4.7 KiB
4.7 KiB
Implementation Priorities - Updated
Date: 2026-03-03 Status: Active Development - Phase 4 Enhancement
📊 Current Feature Status (2026-03-03)
| Feature | Status | Notes |
|---|---|---|
| HTTPS | ✅ 100% | Toggle, cert info, regenerate all working |
| Authentication | 40% | Basic + WS token auth done; JWT/RBAC remaining |
| Plugin System | 85% | Hooks wired; remote install remaining |
✅ COMPLETED: Quick Wins (Done 2026-03-03)
1.1 HTTPS Settings UI ✅ DONE
- Enable/Disable toggle via
POST /api/system/ssl/toggle - Regenerate Certificate button
- SSL info display (expiration, SANs, SHA256 fingerprint)
1.2 Plugin Hook Wiring ✅ DONE
trigger_hook("pm3_command", command)inpm3_service.pytrigger_hook("update_check")inupdate_manager.py
✅ PRIORITY 2: WebSocket Security DONE (2026-03-03)
- Token store with 24h TTL (
app/backend/api/token_store.py) POST /api/auth/token- exchanges Basic Auth for WS tokenGET /api/auth/status- public endpoint to check if auth enabled- WebSocket validates token query param, closes with 4401 if invalid
- Frontend fetches token, passes as
?token=on WS URL - LoginPrompt modal shown when WS returns auth_required
- No-op when AUTH_ENABLED=false (existing behavior preserved)
🟢 PRIORITY 3: Full Authentication System (~3-4 weeks)
Why Important: Required for production deployment, but large effort.
Phase A: JWT Implementation (~3-5 days)
- Implement JWT token generation/validation
- Create
/api/auth/loginendpoint - Create
/api/auth/logoutendpoint - Token refresh mechanism
Phase B: Login UI (~2-3 days)
- Create login page (
app/frontend/app/routes/login.tsx) - Auth context/state management
- Protected route handling
- 401 error handling and redirect
Phase C: User Management (~3-5 days)
- User database schema
- Password hashing (bcrypt/argon2)
- User CRUD endpoints
- Multi-user support
Phase D: RBAC (~3-5 days)
- Role definitions (admin, user, guest)
- Permission system
- Endpoint-level authorization
🔵 PRIORITY 4: Plugin Ecosystem (~2-3 weeks)
4.1 Remote Installation (~1 week)
- GitHub releases integration
- Download/extract/verify plugins
- pip dependency installation
4.2 Permission Consent UI (~2-3 days)
- Show permissions before enabling
- Consent dialog with accept/reject
4.3 Plugin Configuration (~2-3 days)
- Plugin settings persistence
- Plugin-specific config UI
✅ COMPLETED (Power Management)
PRIORITY 1: Power Management ✅ DONE (2025-11-26)
get_power_restrictions()method implemented- API endpoint
/api/system/power/restrictionsworking - Returns correct response when UPS not detected
- Returns correct response when UPS on AC
- Returns correct response when UPS on battery
- Documentation updated
🎯 Recommended Implementation Order
✅ Done (2026-03-03)
HTTPS Settings UI- CompletePlugin Hook Wiring- CompleteWebSocket Auth- Complete
Next Up
- JWT for REST endpoints - Replace Basic Auth with proper tokens
- Login Page - Full auth UI (currently only WS login prompt)
- Full Auth System - Multi-user, RBAC
📁 Key Files Reference
HTTPS
| File | Lines | Purpose |
|---|---|---|
scripts/generate-ssl-cert.sh |
1-115 | EC P-256 certificate generation |
scripts/configure-nginx.sh |
1-91 | nginx config switching |
nginx/dangerous-pi-https.conf |
1-161 | TLS 1.2/1.3, HSTS, captive portal |
app/backend/api/system.py |
578-794 | SSL API endpoints |
app/frontend/app/routes/settings.tsx |
381-394 | UI display (currently read-only) |
Authentication
| File | Purpose |
|---|---|
app/backend/api/auth.py |
Basic HTTP auth + token endpoints |
app/backend/api/token_store.py |
In-memory WS auth token store (24h TTL) |
app/backend/config.py:54 |
AUTH_ENABLED setting |
app/backend/websocket/routes.py |
WebSocket with token validation |
app/frontend/app/hooks/useWebSocket.ts |
WS manager with auth flow |
app/frontend/app/components/LoginPrompt.tsx |
Login modal for WS auth |
Plugins
| File | Purpose |
|---|---|
app/backend/managers/plugin_manager.py |
Full plugin framework (804 lines) |
app/backend/api/plugins.py |
7 CRUD endpoints |
app/backend/services/pm3_service.py |
Triggers pm3_command hook |
app/backend/managers/update_manager.py |
Triggers update_check hook |
app/plugins/hello_world/main.py |
Example hook registration |
app/frontend/app/routes/settings.tsx |
Plugin management UI |