secrets.h.example (1888B)
1 #pragma once 2 // ───────────────────────────────────────────────────────────────────────── 3 // secrets.h — the crew GROUP SECRET (HMAC key for beacon auth) 4 // 5 // THIS FILE (secrets.h.example) IS A TEMPLATE, TRACKED IN GIT. It holds only 6 // the public throwaway placeholder — it is NOT a real key. 7 // 8 // To set the real crew key for a fleet flash, on the flashing machine: 9 // 1. cp firmware/src/secrets.h.example firmware/src/secrets.h 10 // (secrets.h is gitignored — it must never be committed) 11 // 2. openssl rand -hex 32 12 // 3. paste those 32 bytes into GROUP_PSK below, in secrets.h 13 // 4. DELETE the GROUP_PSK_IS_PLACEHOLDER line at the bottom 14 // 5. store the same key in your password manager — it is unrecoverable, 15 // and every crew badge must flash the IDENTICAL key 16 // 17 // Then build the fleet with env oled_v3_prod, which REFUSES to compile unless 18 // a real secrets.h (placeholder line removed) is present. See config.h. 19 // ───────────────────────────────────────────────────────────────────────── 20 #include <stdint.h> 21 #include <stddef.h> 22 23 // REPLACE these 32 bytes with the output of `openssl rand -hex 32`. 24 static const uint8_t GROUP_PSK[] = { 25 0xde,0xad,0xbe,0xef, 0x00,0x11,0x22,0x33, 0x44,0x55,0x66,0x77, 0x88,0x99,0xaa,0xbb, 26 0xcc,0xdd,0xee,0xff, 0x13,0x37,0xc0,0xde, 0xfe,0xed,0xfa,0xce, 0xba,0xdc,0x0f,0xee 27 }; 28 static const size_t GROUP_PSK_LEN = sizeof(GROUP_PSK); 29 30 #define GROUP_PSK_SET 1 // tells config.h a key was provided here 31 32 #define GROUP_PSK_IS_PLACEHOLDER 1 // ← DELETE this line once you set a real key above