# Wiki Log Append-only chronological record. Each entry: `## [YYYY-MM-DD] | `. Query with `grep "^## \[" log.md | tail -5`. ## [2026-06-14] ingest | Parking System — Architecture & Design Notes First source ingested. Bootstrapped wiki scaffolding (CLAUDE.md schema, index.md, overview.md, log.md). Created source summary, 14 entity pages, 9 concept pages, and decision records (settled decisions + 6 open questions). Source is a dense design doc covering stack, threat model, device architecture, UHPPOTE access control, the custom ESP32 controller alternative, readers, and a reference BOM. ## [2026-06-15] decision | JWT key choice + ESP32 deferred From app work, not a new source. Added [[open-questions]] #7 (symmetric vs. asymmetric JWT signing key — raised by the commit security review; prefer RS256/EdDSA so verifying hosts hold only a public key, mirroring the ATECC608 / challenge-response property). Marked [[esp32-custom-controller]] `status: deferred` per decision not to implement device-level auth for now (access control stays on UHPPOTE + network isolation); noted in [[open-questions]] #6. Updated [[local-jwt-auth]] (hardened secret handling + 8h expiry, asymmetric-key pointer) and the index. ## [2026-06-15] decision | Device-agnostic registry + first-run setup From app work. Made the [[device-adapter-pattern]] selectable: added a [[device-registry]] (catalog of drivers per category) and a [[first-run-setup]] flow so the admin picks a device per lane at install. Categories: access (ZKTeco / ESP32 relay), reader (Wiegand / TCP-IP), camera (Hikvision / Dahua, snapshot-on-event), printer. Added a `CameraDevice` interface; new `lane_devices` + `setup_state` tables (migration 0001); admin-only setup endpoints. Stub drivers for now (no real vendor protocols yet). Verified catalog + assign + validation + auth end to end. ## [2026-06-15] decision | UHPPOTE library chosen + real driver Researched Node options for the UHPPOTE controller. Chose the official **`uhppoted`** npm package (MIT, actively maintained, full API incl. openDoor, get-event(s)/event-index, set-listener, restore-default — covers the whole [[event-log-ingestion]] design). Rejected: raw-dgram DIY (reinvents the lib), node-red-contrib-uhppoted (wrong model), Go REST sidecar (extra runtime). Added it to @parking/devices and implemented a real `uhppote` [[uhppote-controller]] access driver (pulseOpen→openDoor, healthCheck→getStatus), registered in the catalog. CJS interop: default-import + destructure. Verified it builds, appears in the catalog, and degrades to "offline" gracefully without hardware. Real on-VLAN test still pending. ## [2026-06-15] feature | Device discovery (UHPPOTE scan in setup) The frontend had no way to find a UHPPOTE — but the controllers self-announce via UDP broadcast. Added a generic [[device-discovery]] capability: optional `DiscoverableDriver.discover()` on the registry, implemented by the `uhppote` driver via `getDevices`. New admin-only `GET /api/setup/discover/:driverId` (health-checks each found device); catalog now returns a `discoverable` list. SetupWizard gains a "Scan for controllers" button that lists found devices with health badges and auto-fills serial + host on selection. Verified: catalog flags uhppote; discover runs and fails gracefully without hardware (broadcast EACCES); non-discoverable driver → 400; no token → 401. Modeled generically so cameras (ONVIF) can add discovery later.