Add remote device disable with reason, and a public device status check

Device gains disabledReason (cleared automatically on re-enable). The
devices admin page prompts for a reason when disabling, and shows it
under the device's status once disabled.

New public GET /api/devices/:serial/status lets a field device check
whether it's disabled and why, before any user session exists —
unauthenticated by design, matching the existing serial-based trust
model used for devices/<serial>/log ingestion, and only ever reveals
a boolean plus a short reason string.

The devices/<serial>/log ingest path didn't check isActive at all
(the devices/<mqttUsername>/points path already did) — closed that
gap for both "log" and "status" message types so a disabled device's
data is rejected regardless of which path it arrives on.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ulhub
2026-07-15 15:11:11 +00:00
parent 8c5de40c5d
commit f1c94e9279
10 changed files with 141 additions and 6 deletions

View File

@@ -38,6 +38,10 @@ export class LogIngestService {
}
const locator = await this.locatorRegistry.resolve(job.orgId, serial);
if (!locator.isActive) {
this.logger.warn(`Message from disabled device "${serial}" ignored`);
return;
}
if (msg.type === 'status') {
this.realtime.publish(`job:${job.id}`, {