chore(access): prune unwired readers, amend ADR-003 for what shipped
ADR-003, .env.example, the access module's headers and the provisioning schema still described the planned npub-QR → UID → serial-reader path. What shipped (#86) is Bolt Card tap-to-enter over the main-process pcscd reader with external_id as the identity, soft entry and verify-at-payment. Nothing ever called availableAccessReaders(): the camera npub-QR reader, the mock reader and the AccessReader seam were dead, so they go; services/access now holds authorize, the card parser and the credential types. The unused 'uid' scan variant goes with them; 'npub' (+PIN) and the 'challenge' seam stay. The ADR gets an amendment section recording the differences, including that open enrollment is not a security boundary and that the audit is still a stub (both tracked as issues). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
a652089441
commit
f11aced450
6 changed files with 62 additions and 107 deletions
|
|
@ -98,14 +98,16 @@ VITE_SPIRE_SEED=
|
|||
# Access Control (ADR-003)
|
||||
# =============================================================================
|
||||
|
||||
# Badge-to-enter gate. When disabled (default), the machine boots straight to
|
||||
# idle exactly as before. When enabled, it boots into a locked screen and
|
||||
# requires a credential (prototype: an npub QR scanned by the camera, with an
|
||||
# optional PIN) before transactions are reachable.
|
||||
# Tap-to-enter gate. When disabled (default), the machine boots straight to
|
||||
# idle exactly as before. When enabled, it boots into a locked screen and a
|
||||
# Bolt Card tap (read by the main-process NFC service over pcscd) unlocks it
|
||||
# and loads the card for the session, so buy/sell finish with one Complete.
|
||||
# ACCESS_CONTROL_ENABLED=true
|
||||
|
||||
# Prototype posture: admit ANY valid npub when the allow-list has no match.
|
||||
# Turn OFF once a real allow-list (/var/lib/bitspire/access.json) is provisioned.
|
||||
# Admit ANY Bolt Card when the allow-list has no match. With this on the gate
|
||||
# only keeps casual users off the menu — any NDEF tag with a /scan/<id> URL
|
||||
# unlocks it; money still moves only on a valid SUN at Complete. Turn OFF once
|
||||
# a real allow-list (/var/lib/bitspire/access.json) is provisioned.
|
||||
# ACCESS_OPEN_ENROLLMENT=true
|
||||
|
||||
# Show the on-screen runtime dev/operator unlock button on the locked screen.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue