Implements the backend half of the ESP32-P4 sensor node spec's pairing, ingestion, and live-broadcast contract: - New Device model (backend/app/models/device.py): id, user_id FK, name, token_hash (unique+indexed), created_at, last_seen_at. Reuses generate_session_token()/hash_token() from auth_session.py verbatim for the one-time raw pairing token / stored hash. - POST /api/device, GET /api/device (session-cookie authenticated REST pairing endpoints) and POST /api/device/telemetry (device bearer-token authenticated ingestion, per-device rate limited, 16KB body cap, 64 reading cap, strict shape validation — never a 500 on garbage input) in backend/app/routes/device.py. - /ws/device-feed live dashboard WS (qm_session cookie authenticated), fanning out ingested readings to the owning user's connected dashboard sockets via an in-process dict[user_id, connections] registry, each with its own send-queue + single sender task (mirrors app.ws's SeanceState/_sender convention). - last_seen_at updates on every successful ingestion. - _process_reading(device, reading) left as an explicit no-op handoff point for Workstream K's summon-pipeline integration. Backend suite: 102 passed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
502 B
502 B