Remove leftover Web Push code and the unused pywebpush dependency (#3171)

This commit is contained in:
maziggy
2026-09-30 11:28:55 +02:00
parent bf7fc67dc0
commit 731ba3bfbe
3 changed files with 12 additions and 102 deletions
-43
View File
@@ -184,46 +184,3 @@ self.addEventListener('fetch', (event) => {
})
);
});
// Handle push notifications (for future use)
self.addEventListener('push', (event) => {
if (!event.data) return;
const data = event.data.json();
const options = {
body: data.body || 'New notification from Bambuddy',
icon: '/img/android-chrome-192x192.png',
badge: '/img/favicon-32x32.png',
vibrate: [100, 50, 100],
data: {
url: data.url || '/',
},
};
event.waitUntil(
self.registration.showNotification(data.title || 'Bambuddy', options)
);
});
// Handle notification clicks
self.addEventListener('notificationclick', (event) => {
event.notification.close();
const url = event.notification.data?.url || '/';
event.waitUntil(
clients.matchAll({ type: 'window', includeUncontrolled: true }).then((windowClients) => {
// Check if there's already a window open
for (const client of windowClients) {
if (client.url.includes(self.location.origin) && 'focus' in client) {
client.navigate(url);
return client.focus();
}
}
// Open a new window if none exists
if (clients.openWindow) {
return clients.openWindow(url);
}
})
);
});
+12 -16
View File
@@ -41,14 +41,15 @@ aioftp>=0.22.0
# Virtual Printer (emulates Bambu printer for slicer uploads)
pyftpdlib>=2.0.0
# Upstream's X.509 / PKCS#7 surface is in our trust path via asyncssh,
# pyOpenSSL, py-vapid, http_ece, pywebpush, so this floor tracks the current
# fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and 49.0.0 has
# PYSEC-2026-3552 (fixed in 50.0.0).
# pyOpenSSL and the virtual printer's certificates, so this floor tracks the
# current fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and
# 49.0.0 has PYSEC-2026-3552 (fixed in 50.0.0).
cryptography>=50.0.0
# Transitive of asyncssh / pywebpush, and the gate on the line above: each
# pyOpenSSL release caps `cryptography` to a narrow window (26.3.0 allows
# <50, 26.4.0 allows <51), so a stale pyOpenSSL silently pins cryptography
# below its fix line -- pip cannot upgrade past the cap even when asked.
# Nothing in the app imports it, but it is installed, and it is the gate on
# the line above: each pyOpenSSL release caps `cryptography` to a narrow
# window (26.3.0 allows <50, 26.4.0 allows <51), so a stale pyOpenSSL
# silently pins cryptography below its fix line -- pip cannot upgrade past
# the cap even when asked.
# Raise this floor in the same commit as any cryptography floor.
pyopenssl>=26.4.0
@@ -63,9 +64,6 @@ defusedxml>=0.7.0 # Safe XML parsing (prevents XXE attacks)
# Excel Export
openpyxl>=3.1.0
# Notifications
pywebpush>=2.0.0
# Utilities
# 0.0.27 → 0.0.31 clears three CVEs in the parser surface that FastAPI
# uses for multipart form bodies (CVE-2026-53538/53539/53540).
@@ -151,12 +149,10 @@ urllib3>=2.7.0
# resolver from picking them.
starlette>=1.3.1
# Transitive of pywebpush (unpinned `aiohttp` requirement). pywebpush declares
# no bound in either direction, so without this floor the resolver happily
# installs a vulnerable line: 3.13.5 has CVE-2026-34993 and CVE-2026-47265
# (fixed in 3.14.0), and 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears
# all three). Our direct usage in services/external_camera.py (ClientSession,
# ClientTimeout, ClientError, iter_chunked) is unaffected by either bump.
# Used directly by services/external_camera.py (ClientSession, ClientTimeout,
# ClientError, iter_chunked). The floor keeps the resolver off vulnerable
# lines: 3.13.5 has CVE-2026-34993 and CVE-2026-47265 (fixed in 3.14.0), and
# 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears all three).
aiohttp>=3.14.3
# Plate Detection (optional - enables build plate empty detection)
-43
View File
@@ -184,46 +184,3 @@ self.addEventListener('fetch', (event) => {
})
);
});
// Handle push notifications (for future use)
self.addEventListener('push', (event) => {
if (!event.data) return;
const data = event.data.json();
const options = {
body: data.body || 'New notification from Bambuddy',
icon: '/img/android-chrome-192x192.png',
badge: '/img/favicon-32x32.png',
vibrate: [100, 50, 100],
data: {
url: data.url || '/',
},
};
event.waitUntil(
self.registration.showNotification(data.title || 'Bambuddy', options)
);
});
// Handle notification clicks
self.addEventListener('notificationclick', (event) => {
event.notification.close();
const url = event.notification.data?.url || '/';
event.waitUntil(
clients.matchAll({ type: 'window', includeUncontrolled: true }).then((windowClients) => {
// Check if there's already a window open
for (const client of windowClients) {
if (client.url.includes(self.location.origin) && 'focus' in client) {
client.navigate(url);
return client.focus();
}
}
// Open a new window if none exists
if (clients.openWindow) {
return clients.openWindow(url);
}
})
);
});