feat: device pairing, telemetry ingestion, live dashboard WS (Workstream G)

Implements the backend half of the ESP32-P4 sensor node spec's pairing,
ingestion, and live-broadcast contract:

- New Device model (backend/app/models/device.py): id, user_id FK, name,
  token_hash (unique+indexed), created_at, last_seen_at. Reuses
  generate_session_token()/hash_token() from auth_session.py verbatim for
  the one-time raw pairing token / stored hash.
- POST /api/device, GET /api/device (session-cookie authenticated REST
  pairing endpoints) and POST /api/device/telemetry (device bearer-token
  authenticated ingestion, per-device rate limited, 16KB body cap, 64
  reading cap, strict shape validation — never a 500 on garbage input) in
  backend/app/routes/device.py.
- /ws/device-feed live dashboard WS (qm_session cookie authenticated),
  fanning out ingested readings to the owning user's connected dashboard
  sockets via an in-process dict[user_id, connections] registry, each with
  its own send-queue + single sender task (mirrors app.ws's
  SeanceState/_sender convention).
- last_seen_at updates on every successful ingestion.
- _process_reading(device, reading) left as an explicit no-op handoff point
  for Workstream K's summon-pipeline integration.

Backend suite: 102 passed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Indiana
2026-07-24 01:12:21 +00:00
parent cf817e5241
commit c88fbc843a
6 changed files with 780 additions and 0 deletions

View File

@@ -1,5 +1,6 @@
from app.models.auth_session import AuthSession
from app.models.contact_session import ContactSession
from app.models.device import Device
from app.models.entity import Entity
from app.models.entity_sighting import EntitySighting
from app.models.event import Event
@@ -10,6 +11,7 @@ __all__ = [
"User",
"AuthSession",
"ContactSession",
"Device",
"Entity",
"EntitySighting",
"Event",