feat: Bolt Card writer CLI for PC/SC NFC readers

Provision, inspect and wipe NTAG 424 DNA Bolt Cards from a Linux PC
using an LNbits /boltcards/api/v1/auth link, replacing the phone app
for desks with a USB reader (ACR1252U).

- pcsc.py: ctypes client for libpcsclite (no compiled deps)
- ntag424.py: EV2 secure messaging (AuthenticateEV2First, ChangeKey,
  ChangeFileSettings, GetCardUID, WriteData) per NT4H2421Gx / AN12196
- boltcard.py: the same write/wipe sequence as bolt-card-programmer
  (NDEF URL, SDM 40 00E0 C1 FF12, keys 1-4 then 0, key version 1)
  plus local p/c verification identical to the extension's nxp424.py
- cli.py: readers / read / write / wipe, keys backed up before any
  card mutation, uid cross-check on wipe

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-20 21:41:24 +02:00
commit 7d35d3e2c7
10 changed files with 1772 additions and 0 deletions

7
shell.nix Normal file
View file

@ -0,0 +1,7 @@
# NixOS / nix users: `nix-shell` then `uv run boltcard-writer ...`.
# pcscd itself must run on the host: services.pcscd.enable = true;
{ pkgs ? import <nixpkgs> { } }:
pkgs.mkShell {
packages = [ pkgs.uv pkgs.python3 pkgs.pcsclite pkgs.pcsc-tools ];
PCSCLITE_LIB = "${pkgs.pcsclite.lib}/lib/libpcsclite.so.1";
}