feat(device-core): add authorized project read model

This commit is contained in:
Codex
2026-08-10 20:10:29 +03:00
parent 43dc9b1f45
commit f5d7916338
7 changed files with 629 additions and 3 deletions
+6 -2
View File
@@ -46,8 +46,12 @@ the remaining activation gates. The staged admission update keeps the relay
opaque but requires a public IPv4 source and bounds its source table and bytes
per direction; it does not enable router/NAT exposure.
The Foundry `Device Manager` is a canonical page template using a server-owned
`device-plane-control` binding. It is not a service in this directory.
The standalone Hub application `Device Core` / `Device Manager` is the human
control-plane shell. Its server-owned BFF calls the disabled-by-default
management and query API in `device-control-core`; browsers never receive the
Core bearer token and never author actor, role, group or owner-scope headers.
Foundry remains a downstream consumer for project-approved device data and is
not the device registry or administration boundary.
Run the foundation tests: