355026dcf7
Neither UHPPOTE nor ZKTeco is used — the Dingtian relay controller was chosen and verified. Remove their code and re-scope the wiki. Code: - delete access-uhppote.ts, uhppoted.d.ts, access.ts (zkteco/esp32-relay stubs), and the three uhppote-*.mjs hardware test scripts. - remove the `uhppoted` npm dependency from @parking/devices and @parking/server. - unregister uhppote/zkteco/esp32-relay from the driver registry; drop their exports. Catalog access drivers = dingtian only. Build green (5/5). - refresh now-stale example comments (registry/interfaces/setup/api) to use current examples; keep the two "UHPPOTE blocker" references that explain why the precondition capability exists. Wiki (kept pages, re-scoped): - uhppote-controller, zkteco-controller -> rejected/historical with callouts; uhppote-vs-esp32 -> historical (detection-vs-prevention lens still useful). - re-point all "current device" framing (standing-decisions, bom, overview, open-questions, device-registry, device-discovery, index) to dingtian-relay. - transferable concepts (network-isolation, event-log-ingestion, barrier-not-a- door, threat-model) untouched. Raw source immutable. Links lint clean.
1.6 KiB
1.6 KiB
type, tags, sources, updated, status
| type | tags | sources | updated | status | |||
|---|---|---|---|---|---|---|---|
| decision |
|
|
2026-06-14 | settled |
Standing Decisions (settled)
The decisions treated as settled in the design notes. (See parking-system-architecture "Summary of standing decisions".)
- Stack: turborepo · fastify (Node) · react-vite-spa · sqlite + drizzle-orm · local-jwt-auth. All MIT/Apache/BSD — no vendor lock, no rug-pull risk (see payload-cms). Full table in technology-stack.
- Platform: a dedicated, hardened Linux appliance (LUKS + GRUB password + Secure Boot), not Windows/WSL — see disk-os-hardening.
- Integrity: append-only, hash-chained, atecc608-signed event log (append-only-event-chain); reconciliation is the anti-fraud control; encryption protects only at-rest (see threat-model).
- Access control: the dingtian-relay relay+input controller, on an isolated VLAN (network-isolation). Chosen because its inputs are decoupled from its relays, enabling host-in-the-loop ticket-first entry — the resolution to access-controller-button-flow. (The uhppote-controller and zkteco-controller were evaluated and rejected — kept as historical record. The esp32-custom-controller remains the documented prevention-grade alternative — the trust-boundary fork.)
- Readers: prefer wiegand-into-controller for permit holders (autonomous); host-in-the-loop for lpr-camera/QR/pure-network readers; both can share a relay (see entry-exit-readers).
Unsettled items live in open-questions.