chore(access): prune unwired readers, amend ADR-003 for what shipped
ADR-003, .env.example, the access module's headers and the provisioning schema still described the planned npub-QR → UID → serial-reader path. What shipped (#86) is Bolt Card tap-to-enter over the main-process pcscd reader with external_id as the identity, soft entry and verify-at-payment. Nothing ever called availableAccessReaders(): the camera npub-QR reader, the mock reader and the AccessReader seam were dead, so they go; services/access now holds authorize, the card parser and the credential types. The unused 'uid' scan variant goes with them; 'npub' (+PIN) and the 'challenge' seam stay. The ADR gets an amendment section recording the differences, including that open enrollment is not a security boundary and that the audit is still a stub (both tracked as issues). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
a652089441
commit
f11aced450
6 changed files with 62 additions and 107 deletions
|
|
@ -12,11 +12,11 @@
|
|||
# access.json schema (all keys optional; omitted keys fall back to env/defaults):
|
||||
# {
|
||||
# "enabled": true, // master switch for the gate
|
||||
# "openEnrollment": true, // prototype: admit any valid npub
|
||||
# "openEnrollment": true, // admit any Bolt Card (gate is not a security boundary)
|
||||
# "devUnlock": false, // on-screen dev/operator unlock (bypasses the gate; default off)
|
||||
# "salt": "per-machine", // hashing salt (provision a real one for prod)
|
||||
# "allowList": [ // authorized identities (hashed); empty in open mode
|
||||
# { "idHash": "<hashId(hexpubkey,salt)>", "role": "user", "pinHash": "<hashPin(pin,salt)>" }
|
||||
# { "idHash": "<hashId(external_id,salt)>", "role": "user", "pinHash": "<hashPin(pin,salt)>" }
|
||||
# ]
|
||||
# }
|
||||
#
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue