| Security |
AT gateway auth |
/api/at allows arbitrary AT commands. |
Add token‑based authentication or whitelist allowed commands. |
["git:backend/src/handlers.rs"] |
| Credentials |
Redacted sensitive fields |
APN password, FRPC token, etc. are stored as [REDACTED]. |
Store secrets in Vaultwarden or an encrypted config file; provide UI for secure entry. |
["git:backend/src/config.rs", "git:frontend/src/pages/Network.tsx", "git:frontend/src/pages/Frp.tsx"] |
| OTA |
No signing |
OTA packages are unsigned. |
Sign OTA tarballs (e.g., GPG) and verify signatures in ota.rs. |
["memory:e92dbe0b…"] |
| OTA |
No rollback |
Once applied, the device cannot revert to the previous version. |
Implement A/B partitions or keep a backup copy before applying OTA. |
["git:backend/src/ota.rs", "git:frontend/src/pages/OtaUpdate.tsx"] |
| FRPC |
Log rotation threshold |
Logs grow beyond 512 KB. |
Make log rotation size configurable or compress old logs. |
["git:backend/src/state.rs"] |
| USB |
File‑lock missing |
set_usb_mode_config writes directly to mode files. |
Use atomic rename or flock for exclusive access. |
["git:backend/src/usb_switch.rs"] |
| USB Monitor |
Hard‑coded Feishu webhook |
Monitor script only posts to a single Feishu URL. |
Add a CLI flag for a configurable webhook; support Slack/Discord. |
["usb_switch_demo.sh"] |
| Testing |
Lack of unit/integration tests |
Backend and front‑end have little test coverage. |
Add Rust unit tests for utils and Jest/React‑Testing‑Library tests for UI components. |
["git:backend/src/utils.rs", "git:frontend/src/pages/*.tsx"] |
| API |
HTTP 200 for all errors |
Errors are wrapped in JSON but HTTP status is always 200. |
Return appropriate HTTP status codes (400, 401, 500, …). |
["git:backend/src/handlers.rs"] |
| CORS |
* allowed |
Development CORS policy is wide open. |
Restrict origins to known production hosts before release. |
["git:backend/src/main.rs"] |
| Refresh |
Aggressive polling on visibility changes |
useAdaptivePolling may cause rapid extra requests. |
Debounce visibility changes (e.g., 500 ms) before adjusting interval. |
["git:frontend/src/hooks/useAdaptivePolling.ts"] |
| InitScript |
Dangerous commands only warned |
Scripts with rm -rf / etc. are only highlighted. |
Add a confirmation modal for dangerous commands and optionally block save. |
["git:frontend/src/pages/InitScript.tsx"] |
| Band‑lock UI |
May allow unsupported bands |
UI does not surface backend rejections. |
Parse backend error and display to the user. |
["git:frontend/src/pages/Network.tsx"] |
| USB hot‑switch |
Marked experimental |
May destabilise the device. |
Perform extensive testing; fallback to reboot on failure. |
["git:frontend/src/pages/Configuration.tsx"] |
| Global Error Boundary |
Missing in React tree |
Uncaught render errors crash the UI. |
Wrap the root <App/> with an ErrorBoundary component. |
["git:frontend/src/main.tsx"] |
| i18n |
No localisation |
All UI strings are hard‑coded Chinese. |
Introduce react-i18next (or similar) and externalise strings. |
["git:frontend/src/**/*.tsx"] |
| Performance |
Large tables lack virtualization |
Cell list may degrade performance. |
Use react-window or MUI DataGrid virtualization. |
["git:frontend/src/pages/Network.tsx"] |
| OTA upload cancellation |
No abort controller |
Users cannot stop a large OTA upload. |
Add AbortController support to the upload API wrapper. |
["git:frontend/src/pages/OtaUpdate.tsx"] |
| USB monitor daemonisation |
Script runs manually |
No systemd service provided. |
Provide a systemd unit template for usb_switch_demo.sh. |
["usb_switch_demo.sh"] |
| Docker image reproducibility |
Base image ubuntu:18.04 is outdated |
Security updates may be missing. |
Upgrade to a newer LTS base (e.g., ubuntu:24.04). |
["docker/gnu-builder.Dockerfile"] |
| Documentation |
No top‑level end‑to‑end guide |
New contributors lack a consolidated overview. |
Add a high‑level README covering build → deploy → operate workflow. |
[] |