Fix support bundle leaking virtual printer IP address

The debug support bundle included virtual_printer_remote_interface_ip
  unmasked in support-info.json. The setting key didn't match any
  sensitive-key filter substring. Added "_ip" to the filter set so IP
  address settings are excluded. Log file content was already redacted
  by the existing IPv4 regex.
This commit is contained in:
maziggy
2026-04-09 08:25:40 +02:00
parent 813d9dde38
commit d0b91ad4d5
2 changed files with 2 additions and 0 deletions
+1
View File
@@ -5,6 +5,7 @@ All notable changes to Bambuddy will be documented in this file.
## [0.2.3b3] - Unreleased
### Fixed
- **Support Bundle Leaks Virtual Printer IP Address** — The debug support bundle included the `virtual_printer_remote_interface_ip` setting value unmasked in `support-info.json`. The setting key didn't match any of the existing sensitive-key filters, so the raw IP address was included in the bundle. Added `_ip` to the sensitive key filter so IP address settings are excluded from support bundles. Log file content was already covered by the existing IPv4 regex redaction.
- **"Build Plate Cleared" Button Unclickable After Second Print** ([#912](https://github.com/maziggy/bambuddy/issues/912)) — After completing the first queued print and confirming the plate was cleared, the "Build plate cleared — ready for next print" button became unresponsive after the second print finished. The React Query mutation's `isSuccess` state persisted from the first plate-clear confirmation, causing the component to render the static "Plate Ready" confirmation instead of the clickable button. The mutation state is now reset when the printer leaves the FINISH/FAILED state, so the button works correctly on every print cycle.
- **Spoolman Location Not Cleared When Spool Removed from AMS** ([#921](https://github.com/maziggy/bambuddy/issues/921)) — When Spoolman auto-sync was enabled and a spool was removed from an AMS slot, its location in Spoolman was never cleared, causing "double-booked" slots where multiple spools shared the same location. The auto-sync callback set locations for newly inserted spools but skipped the cleanup step that clears stale locations. The location clearing logic now runs after every auto-sync cycle. Also fixed the single-printer manual sync endpoint which didn't track synced spool IDs, risking incorrect location clearing for location-matched (non-RFID) spools.
+1
View File
@@ -581,6 +581,7 @@ async def _collect_support_info() -> dict:
"url",
"path", # Filesystem paths may contain usernames
"config", # URLs may contain IPs, configs may have embedded secrets
"_ip", # IP address fields (e.g. virtual_printer_remote_interface_ip)
}
for s in all_settings:
# Skip sensitive settings