ticket: site metadata header + scannable Albanian ticket; widen barcode
- site_config gains optional park identity (park_name, operator_name, nius, address, phone, email); additive Drizzle migration 0001. GET/PUT /api/site-config read/write the full config (PUT partial patch, admin only); SiteSettings + SetupWizard expose the fields. - renderTicket() prints an Albanian header sourced from site_config, the all-numeric 13-digit ticket id (12 random + Luhn) as Code128, large digits, and a lost-ticket footer. CP852 codepage so ë/ç render. - Widen the Code128 module width 2->3 and height 80->100 dots so the short-range "Simple" QR/barcode reader decodes reliably (was barely reading at module width 2 on the 80mm head). See wiki/concepts/site-metadata.md and ticket-encoding.md.
This commit is contained in:
@@ -58,3 +58,30 @@ export function buildSigner(log?: { warn: (msg: string) => void }): Signer {
|
||||
"event signing: no signing key. Set EVENT_SIGNING_KEY (>=16 chars) for the append-only event chain.",
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve the signer that can VERIFY an existing event, by its stored `keyId`.
|
||||
* Appends always use the one signer from buildSigner(), but a chain can contain
|
||||
* events signed under different keys across a rotation (e.g. the JWT_SECRET
|
||||
* fallback before a dedicated EVENT_SIGNING_KEY was set, or an ATECC608 swap).
|
||||
* Each event stores its own `keyId`, so verifyChain() must check each row against
|
||||
* the key that produced it — not the current append-signer. Returns undefined for
|
||||
* an unknown keyId (the key is gone / not configured), which verifyChain surfaces
|
||||
* as a distinct failure rather than a false "tampered" alarm.
|
||||
*
|
||||
* TODO(atecc608): add an "atecc608-slotN" case returning a public-key verifier.
|
||||
*/
|
||||
export function buildVerifier(keyId: string): Signer | undefined {
|
||||
switch (keyId) {
|
||||
case "sw-hmac-v2": {
|
||||
const k = process.env.EVENT_SIGNING_KEY;
|
||||
return k && k.length >= 16 ? new SoftwareSigner(k, "sw-hmac-v2") : undefined;
|
||||
}
|
||||
case "sw-hmac-jwtfallback": {
|
||||
const k = process.env.JWT_SECRET;
|
||||
return k && k.length >= 16 ? new SoftwareSigner(k, "sw-hmac-jwtfallback") : undefined;
|
||||
}
|
||||
default:
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user