Replaces the device-events demo with the actual product:
- Prisma + PostGIS data layer (postgis/postgis:17-3.5). Lat/lng decimals
are the source of truth; a generated geometry(Point,4326) column with
a GIST index backs bbox queries. Migrations apply on container boot.
- JWT auth (bcryptjs + httpOnly cookie) with public registration that
creates an org; per-org roles (ORG_ADMIN/MEMBER/VIEWER) enforced by
guards on all /orgs/:orgId routes.
- Scoped API keys (X-API-Key, sha256-hashed, shown once) for
programmatic access, manageable by org admins.
- REST API: jobs/tickets CRUD with filters, points query (time range,
recordedAt cursor, bbox), members, devices, api-keys.
- MQTT ingest: devices publish to devices/{username}/points and /jobs;
unknown tickets auto-create stub jobs (source=DEVICE); every message
is raw-logged to device_events; acks on devices/{username}/jobs/ack.
Broker gets a dedicated backend user; testuser is now a plain device.
- Realtime: plain-WS gateway at /api/ws (socket.io removed) with
cookie auth and per-job channels feeding the map live.
- Next.js frontend: login/register, jobs list with filters, job detail
with live Google map (APWA utility colors, polylines per run) behind
a provider-neutral JobMap abstraction for a future Esri swap, and
settings pages for members/devices/api-keys.
- Seed: Umagul org, admin user, testuser device, demo job with RTK
points. Sample publisher updated to the new topic contract.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
20 lines
479 B
Plaintext
20 lines
479 B
Plaintext
# Certificate CN becomes the MQTT username — restrict each device to its own namespace.
|
|
pattern readwrite devices/%u/#
|
|
|
|
# Admin: brent
|
|
user brent
|
|
topic readwrite #
|
|
topic readwrite $SYS/#
|
|
|
|
# Admin: admin
|
|
user admin
|
|
topic readwrite #
|
|
topic readwrite $SYS/#
|
|
|
|
# Backend service: reads all device traffic, writes job acks back to devices
|
|
user backend
|
|
topic read devices/#
|
|
topic write devices/+/jobs/ack
|
|
|
|
# testuser is a demo *device*: only the per-device pattern rule above applies
|