diff --git a/docs/api.md b/docs/api.md index 79fd1d7..8c170aa 100644 --- a/docs/api.md +++ b/docs/api.md @@ -65,9 +65,13 @@ a 3.x PWA). | `/api/pli-dict` | GET | Current dictionary (hex values per qualifier) | | `/api/pli-dict` | POST | Update dictionary entries | | `/api/scp81/bip` | POST | Start/stop the HTTP OTA listener (dump capture or PSK TLS server) | -| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity) | +| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity, `owner`) | | `/api/scp81/log` | GET | HTTP OTA event log (`?after=`) | | `/api/scp81/log-clear` | POST | Clear the HTTP OTA event log | +| `/api/bip/control` | POST | Start/stop the generic BIP session (`sink` / `passthru` / `redirect`) | +| `/api/bip/status` | GET | BIP session state + owner (same shape as `/api/scp81/status`) | +| `/api/bip/log` | GET | BIP event log (`?after=`) | +| `/api/bip/log-clear` | POST | Clear the BIP event log | | `/api/scp81/queue` | POST | Replace the SCP81 command script (optionally force-restart) | | `/api/scp81/script` | GET | Active command script + execution state and R-APDUs | | `/api/scp81/psk-map` | POST | Replace the PSK table of a running TLS listener | @@ -985,6 +989,47 @@ its run progress. Stop either mode with `{"action": "stop"}` (also disables the BIP terminal). +### `POST /api/bip/control` + +Generic BIP terminal control for the Simulator's **BIP** pill - the terminal +side of the Bearer Independent Protocol for cards that use TCP without HTTP +OTA. The session is shared with the SCP81 listener: only one BIP session runs +at a time, starting either control stops the other, and the response reports +what was stopped as `replaced: {"owner": "scp81"|"bip", "mode": ...}` (the +PWA shows a notice). + +```json +{"action": "start", "mode": "sink", "host": "127.0.0.1", "port": 0} +``` + +Modes: + +- `sink` (default) - starts a local TCP listener that accepts the card's BIP + channels and only logs what arrives (`conn`, `sink-rx`, `conn-close`); it + never sends anything back. `port` may be `0`/omitted for an ephemeral port; + the bound address is reported in the status. Use it for cards that open a + TCP connection just to upload data. +- `passthru` - no listener and no target: each channel dials the destination + the card requests in OPEN CHANNEL (TCP client only, no default port; an + incomplete or non-TCP request fails with result `3A`). +- `redirect` - every channel connects to the required `host`/`port`; the + address the card requests is only logged. + +`link_events` (default `true`) controls the terminal-side Channel status +events (TS 102 223 7.5.11). An invalid request never disturbs a running +session. Stop with `{"action": "stop"}`; the response carries the same body +as the status endpoints. + +### `GET /api/bip/status` + +Same shape as `GET /api/scp81/status`: `{"owner": "bip"|"scp81"|null, +"bip": {...}, "listener": {...}}`. A running sink reports +`{"mode": "sink", "host": ..., "port": ..., "connections": N}`. + +### `GET /api/bip/log` / `POST /api/bip/log-clear` + +The shared BIP event log (`?after=`) - identical to `/api/scp81/log`. + ### `GET /api/scp81/status` ```json @@ -995,6 +1040,9 @@ Stop either mode with `{"action": "stop"}` (also disables the BIP terminal). "version_seen": "TLSv1.2", "cipher_seen": "PSK-AES128-CBC-SHA256"}} ``` +`owner` is `scp81` or `bip` (whichever control started the session), `null` +when idle; it is returned by both this endpoint and `/api/bip/status`. + Listener modes: `tls` (local PSK TLS server), `dump` (capture-only TCP listener), `redirect` (no local listener; the BIP channels go straight to the configured `host:port`, e.g. an external HTTP OTA platform — reported as diff --git a/frontend/help-ru.html b/frontend/help-ru.html index 35fc682..1598561 100644 --- a/frontend/help-ru.html +++ b/frontend/help-ru.html @@ -553,6 +553,15 @@
  • Шаблоны — Empty, Обзор меню STK, Апплет через SCP80; редактор шагов — формный, отдельные скрипты экспортируются/импортируются как JSON.
  • +

    8.10 BIP-терминал (обычный TCP)

    +

    Пилюля BIP запускает терминальную сторону Bearer Independent Protocol для карт, использующих TCP без HTTP OTA (SCP81): апплет или пуш-триггер может открыть канал и обменяться сырыми данными. Одновременно работает только одна BIP-сессия — запуск здесь останавливает слушатель SCP81, а запуск слушателя SCP81 останавливает эту сессию (в обоих случаях сообщается, что было заменено).

    +
      +
    • Локальный приёмник (только журнал) (по умолчанию) — принимает каналы карты на локальном слушателе и только записывает принятое в журнал; ничего не отправляется обратно. Оставьте порт пустым для эфемерного порта (занятый адрес появится в статусе). Подходит для карт, которые открывают TCP-соединение только чтобы выгрузить данные.
    • +
    • Адрес карты (OPEN CHANNEL) — каждый канал подключается к адресу, который карта запросила в OPEN CHANNEL (Other address + transport port, только TCP-клиент); Host и Port не используются, используется сеть сервера (только для лаборатории).
    • +
    • Заданный адрес — каждый канал подключается к указанному Host:Port; запрошенный картой адрес только записывается в журнал.
    • +
    +

    Строка статуса показывает активный режим, занятый адрес, владельца сессии и открытые каналы; блок Каналы перечисляет счётчики байт по каналам, а Журнал BIP записывает каждое событие open / send / receive / close с hex-превью (те же события, что показывает вкладка SCP81). CAT_TP через UDP не реализован.

    +

    9. Установка сервера

    Для работы с картой (вкладка «Картридер», «Симулятор», доставка OTA) нужен локальный pysim-simple-server — встроенный в SIMple HTTP-сервер, оборачивающий pySim, работающий с ридером через PC/SC или serial и раздающий сам PWA (откройте http://127.0.0.1:8080).

    diff --git a/frontend/help.html b/frontend/help.html index ecb55e4..e3c3a40 100644 --- a/frontend/help.html +++ b/frontend/help.html @@ -552,6 +552,15 @@
  • Templates — Empty, STK menu browsing, Applet via SCP80; the step editor is form-based and individual scripts export/import as JSON.
  • +

    8.10 BIP terminal (generic TCP)

    +

    The BIP pill runs the terminal side of the Bearer Independent Protocol for cards that use TCP without HTTP OTA (SCP81): an applet or a push trigger can open a channel and exchange raw data. Only one BIP session runs at a time — starting here stops a running SCP81 listener, and starting the SCP81 listener stops this session (both report what was replaced).

    +
      +
    • Local sink (log only) (default) — accepts the card's channels on a local listener and only logs what arrives; nothing is ever sent back. Leave the port empty for an ephemeral port (the bound address appears in the status). Use it for cards that open a TCP connection just to upload data.
    • +
    • Card's destination (OPEN CHANNEL) — each channel is connected to the destination the card requests in OPEN CHANNEL (Other address + transport port, TCP client only); Host and Port are not used and the server's network is used (lab only).
    • +
    • Fixed target — every channel is connected to the configured Host:Port; the address the card requests is only logged.
    • +
    +

    The status line shows the active mode, the bound address, the session owner and the open channels; the Channels box lists the per-channel byte counts and the BIP log records every open / send / receive / close event with a hex preview (the same events the SCP81 tab shows). CAT_TP over UDP is not implemented.

    +

    9. Server installation

    Live card operations (Card reader tab, Simulator, OTA delivery) require the local pysim-simple-server — a small HTTP server bundled with SIMple that wraps pySim, talks to the reader over PC/SC or serial, and also serves the PWA itself (open http://127.0.0.1:8080).

    diff --git a/frontend/index.html b/frontend/index.html index 4f7eb80..0a752ab 100644 --- a/frontend/index.html +++ b/frontend/index.html @@ -1032,6 +1032,7 @@
    +
    @@ -1183,6 +1184,47 @@ Loading... +