Commit Graph

15 Commits

Author SHA1 Message Date
Brent Perteet
9ffe021354 fix(S2-a): expose scoped app MQTT through WSS 2026-08-20 15:43:42 -05:00
Brent Perteet
b66ae2cc47 fix(S2-a): load public MQTT TLS cert from broker volume 2026-08-20 15:27:03 -05:00
Brent Perteet
8bcc12ec96 feat(S2-a): ingest durable app MQTT points securely 2026-08-20 15:22:40 -05:00
Brent Perteet
daa3407b9d test: wire jest harness for QA gate (S1-f)
Add jest + ts-jest to the NestJS backend with an app.service smoke spec that
exercises Nest DI. `npm test` is the documented command the QA gate runs.

Trace: SRS §6 gate, NFR-8.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-20 12:53:36 -05:00
ulhub
9eefe50401 Replace Google Maps with Esri (ArcGIS) basemaps
Swaps the map provider behind the existing provider-neutral JobMapProps
interface: EsriJobMap.tsx (ArcGIS Maps SDK) replaces GoogleJobMap.tsx,
loaded via esri-loader's CDN script rather than bundled through webpack —
next dev's inline source-mapping of a library this size was OOM-killing
the whole host on first compile. Also fixes a bug in the fit-bounds camera
call: view.goTo() needs real Graphic/Geometry instances, not plain point
literals, so the map was never zooming to the plotted points.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-16 21:06:05 +00:00
ulhub
5de7b4d7a2 Add BLE challenge-response for short-lived MQTT session certs
BLE-only locators can't hold the MQTT/TLS connection themselves — a phone
relays their data — so handing the phone a device's permanent client-cert
key would export its identity to every phone it pairs with. Instead the
device signs a server-issued nonce with its permanent key over BLE; once
verified, the backend mints a short-lived session certificate for the
phone's actual MQTT connection, keeping the permanent key on-device always.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-13 20:51:58 +00:00
ulhub
842cb23e1f Add device-certificate mTLS auth, live position tracking, and API docs
Introduces a CA/PKI module so field devices can authenticate to Mosquitto
over TLS (8883) with per-device client certificates (CN = serial number)
instead of a shared password, with matching Devices/MQTT-Certs UI. Adds
live transmitter position tracking alongside logged points, an MQTTS
transport option in the simulator for exercising the real cert-auth path,
and Swagger API docs at /api/docs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-18 01:40:12 +00:00
ulhub
f1c94e9279 Add remote device disable with reason, and a public device status check
Device gains disabledReason (cleared automatically on re-enable). The
devices admin page prompts for a reason when disabling, and shows it
under the device's status once disabled.

New public GET /api/devices/:serial/status lets a field device check
whether it's disabled and why, before any user session exists —
unauthenticated by design, matching the existing serial-based trust
model used for devices/<serial>/log ingestion, and only ever reveals
a boolean plus a short reason string.

The devices/<serial>/log ingest path didn't check isActive at all
(the devices/<mqttUsername>/points path already did) — closed that
gap for both "log" and "status" message types so a disabled device's
data is rejected regardless of which path it arrives on.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 15:11:11 +00:00
ulhub
8c5de40c5d Add live transmitter position (status) alongside logged points
devices/<serial>/log messages now carry a "type": "log" or "status".
"log" persists a LocatePoint as before; "status" carries the same
position + telemetry shape but is broadcast live over the job's
realtime channel without touching locate_points — it's a current-
position update, not a recorded point.

The job map renders the latest status as a blue "you are here" marker
(with a soft accuracy-radius halo) that moves in place as new updates
arrive, separate from the colored polyline of logged points. Clicking
it shows the same detail readout as a logged point.

The simulator gained a message-type toggle (Log point / Status
update) so both paths can be exercised from /sim.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 14:52:53 +00:00
ulhub
e91c91e037 Tie points to locator serial numbers and store receiver telemetry
Adds devices/<serial>/log as a job-anchored MQTT ingest path: a locator
identifies itself by serial in the topic (auto-registered on first
sight, org resolved from the job in the payload) rather than by a
pre-provisioned broker credential. Device.serialNumber is now globally
unique so the bare topic segment is enough to resolve identity.
Locator lookup/auto-register logic is shared (LocatorRegistryService)
between this and the existing devices/<mqttUsername>/points path.

New /sim page (own header, outside the main app nav) simulates a
transmitter: pick an open job or create one, set a serial number and
telemetry defaults, and send points one at a time or on an interval
along a simulated walking path. It calls a new authenticated backend
endpoint (POST /orgs/:orgId/sim/publish) that publishes onto the real
broker rather than writing the DB directly, so the simulator exercises
the actual ingest pipeline end-to-end.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-14 19:41:58 +00:00
ulhub
b7479fa68f Show point details on marker click
Clicking a point on the job map opens an InfoWindow with its full
telemetry readout (utility, fix, recorded time, depth, frequency,
current, signal, gain, locate mode, phase, compass, distortion, GPS
accuracy/satellites/HDOP, altitude, coordinates) — only the fields the
point actually has, since instruments vary in what they report.
Clicking empty map area dismisses it.

MapPoint gained altitude/hAccuracy/vAccuracy/satellites/hdop/phaseDeg,
which the backend already returned but the frontend type omitted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 16:28:07 +00:00
ulhub
21f5a04133 Tie points to locator serial numbers and store receiver telemetry
Field setups often relay through a phone/gateway that owns the MQTT
connection, so the publishing credential and the instrument are now
separate concepts:

- Points messages carry a "serial" identifying the locator receiver;
  unknown serials are auto-registered as devices in the publisher's
  org (name "Locator <serial>"). Device.mqttUsername is now optional
  and serialNumber is unique per org.
- LocatePoint gains standard receiver telemetry: frequencyHz,
  currentMa, signalDb, gainDb, locateMode (PEAK/NULL/BROAD_PEAK/SONDE),
  phaseDeg, compassDeg, distortionPct, plus GPS quality columns
  vAccuracy, satellites, hdop. All optional; raw payload still kept.
- Migration hand-edited to preserve the generated geom column and its
  GIST index (Prisma diff wanted to drop both).
- REST create/point DTOs, map tooltips, job-detail latest-point
  readout, devices settings form, seed, and the sample publisher all
  carry the new fields.
- Added .dockerignore for backend/web: COPY . . was clobbering the
  image's freshly generated Prisma client with the host's stale
  node_modules, breaking image builds after schema changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 14:58:12 +00:00
ulhub
eae4075265 Build core domain: orgs, users, jobs, locate points, auth, live map
Replaces the device-events demo with the actual product:

- Prisma + PostGIS data layer (postgis/postgis:17-3.5). Lat/lng decimals
  are the source of truth; a generated geometry(Point,4326) column with
  a GIST index backs bbox queries. Migrations apply on container boot.
- JWT auth (bcryptjs + httpOnly cookie) with public registration that
  creates an org; per-org roles (ORG_ADMIN/MEMBER/VIEWER) enforced by
  guards on all /orgs/:orgId routes.
- Scoped API keys (X-API-Key, sha256-hashed, shown once) for
  programmatic access, manageable by org admins.
- REST API: jobs/tickets CRUD with filters, points query (time range,
  recordedAt cursor, bbox), members, devices, api-keys.
- MQTT ingest: devices publish to devices/{username}/points and /jobs;
  unknown tickets auto-create stub jobs (source=DEVICE); every message
  is raw-logged to device_events; acks on devices/{username}/jobs/ack.
  Broker gets a dedicated backend user; testuser is now a plain device.
- Realtime: plain-WS gateway at /api/ws (socket.io removed) with
  cookie auth and per-job channels feeding the map live.
- Next.js frontend: login/register, jobs list with filters, job detail
  with live Google map (APWA utility colors, polylines per run) behind
  a provider-neutral JobMap abstraction for a future Esri swap, and
  settings pages for members/devices/api-keys.
- Seed: Umagul org, admin user, testuser device, demo job with RTK
  points. Sample publisher updated to the new topic contract.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 12:43:25 +00:00
ulhub
cbe0cc6da2 Replace browser MQTT bridge with backend device-events service
The frontend previously connected directly to the MQTT broker via a
CDN-loaded Paho client and a Paho-specific ws proxy. Move that
responsibility into the backend: DeviceDataService persists MQTT
messages to Postgres, and DeviceEventsController exposes them over a
REST endpoint plus a WebSocket gateway that the frontend now consumes
directly. Also adds a pgadmin service for inspecting the database.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-13 23:03:28 +00:00
ulhub
ed2fae9455 Initial commit: UlHub workspace 2026-07-12 01:09:33 +00:00