diff --git a/frontend/public/sw.js b/frontend/public/sw.js index 42035c068..02cb236ad 100644 --- a/frontend/public/sw.js +++ b/frontend/public/sw.js @@ -184,46 +184,3 @@ self.addEventListener('fetch', (event) => { }) ); }); - -// Handle push notifications (for future use) -self.addEventListener('push', (event) => { - if (!event.data) return; - - const data = event.data.json(); - const options = { - body: data.body || 'New notification from Bambuddy', - icon: '/img/android-chrome-192x192.png', - badge: '/img/favicon-32x32.png', - vibrate: [100, 50, 100], - data: { - url: data.url || '/', - }, - }; - - event.waitUntil( - self.registration.showNotification(data.title || 'Bambuddy', options) - ); -}); - -// Handle notification clicks -self.addEventListener('notificationclick', (event) => { - event.notification.close(); - - const url = event.notification.data?.url || '/'; - - event.waitUntil( - clients.matchAll({ type: 'window', includeUncontrolled: true }).then((windowClients) => { - // Check if there's already a window open - for (const client of windowClients) { - if (client.url.includes(self.location.origin) && 'focus' in client) { - client.navigate(url); - return client.focus(); - } - } - // Open a new window if none exists - if (clients.openWindow) { - return clients.openWindow(url); - } - }) - ); -}); diff --git a/requirements.txt b/requirements.txt index 5275d7933..d994b5e92 100644 --- a/requirements.txt +++ b/requirements.txt @@ -41,14 +41,15 @@ aioftp>=0.22.0 # Virtual Printer (emulates Bambu printer for slicer uploads) pyftpdlib>=2.0.0 # Upstream's X.509 / PKCS#7 surface is in our trust path via asyncssh, -# pyOpenSSL, py-vapid, http_ece, pywebpush, so this floor tracks the current -# fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and 49.0.0 has -# PYSEC-2026-3552 (fixed in 50.0.0). +# pyOpenSSL and the virtual printer's certificates, so this floor tracks the +# current fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and +# 49.0.0 has PYSEC-2026-3552 (fixed in 50.0.0). cryptography>=50.0.0 -# Transitive of asyncssh / pywebpush, and the gate on the line above: each -# pyOpenSSL release caps `cryptography` to a narrow window (26.3.0 allows -# <50, 26.4.0 allows <51), so a stale pyOpenSSL silently pins cryptography -# below its fix line -- pip cannot upgrade past the cap even when asked. +# Nothing in the app imports it, but it is installed, and it is the gate on +# the line above: each pyOpenSSL release caps `cryptography` to a narrow +# window (26.3.0 allows <50, 26.4.0 allows <51), so a stale pyOpenSSL +# silently pins cryptography below its fix line -- pip cannot upgrade past +# the cap even when asked. # Raise this floor in the same commit as any cryptography floor. pyopenssl>=26.4.0 @@ -63,9 +64,6 @@ defusedxml>=0.7.0 # Safe XML parsing (prevents XXE attacks) # Excel Export openpyxl>=3.1.0 -# Notifications -pywebpush>=2.0.0 - # Utilities # 0.0.27 → 0.0.31 clears three CVEs in the parser surface that FastAPI # uses for multipart form bodies (CVE-2026-53538/53539/53540). @@ -151,12 +149,10 @@ urllib3>=2.7.0 # resolver from picking them. starlette>=1.3.1 -# Transitive of pywebpush (unpinned `aiohttp` requirement). pywebpush declares -# no bound in either direction, so without this floor the resolver happily -# installs a vulnerable line: 3.13.5 has CVE-2026-34993 and CVE-2026-47265 -# (fixed in 3.14.0), and 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears -# all three). Our direct usage in services/external_camera.py (ClientSession, -# ClientTimeout, ClientError, iter_chunked) is unaffected by either bump. +# Used directly by services/external_camera.py (ClientSession, ClientTimeout, +# ClientError, iter_chunked). The floor keeps the resolver off vulnerable +# lines: 3.13.5 has CVE-2026-34993 and CVE-2026-47265 (fixed in 3.14.0), and +# 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears all three). aiohttp>=3.14.3 # Plate Detection (optional - enables build plate empty detection) diff --git a/static/sw.js b/static/sw.js index 42035c068..02cb236ad 100644 --- a/static/sw.js +++ b/static/sw.js @@ -184,46 +184,3 @@ self.addEventListener('fetch', (event) => { }) ); }); - -// Handle push notifications (for future use) -self.addEventListener('push', (event) => { - if (!event.data) return; - - const data = event.data.json(); - const options = { - body: data.body || 'New notification from Bambuddy', - icon: '/img/android-chrome-192x192.png', - badge: '/img/favicon-32x32.png', - vibrate: [100, 50, 100], - data: { - url: data.url || '/', - }, - }; - - event.waitUntil( - self.registration.showNotification(data.title || 'Bambuddy', options) - ); -}); - -// Handle notification clicks -self.addEventListener('notificationclick', (event) => { - event.notification.close(); - - const url = event.notification.data?.url || '/'; - - event.waitUntil( - clients.matchAll({ type: 'window', includeUncontrolled: true }).then((windowClients) => { - // Check if there's already a window open - for (const client of windowClients) { - if (client.url.includes(self.location.origin) && 'focus' in client) { - client.navigate(url); - return client.focus(); - } - } - // Open a new window if none exists - if (clients.openWindow) { - return clients.openWindow(url); - } - }) - ); -});