From f03d0c4cf7e509769a076e32f2f5dd8bb0899a58 Mon Sep 17 00:00:00 2001 From: maziggy Date: Tue, 14 Apr 2026 11:16:26 +0200 Subject: [PATCH] fix: attribute direct library prints to the authenticated user The library POST /files/{file_id}/print endpoint discarded the authenticated user and passed requested_by_user_id=None to the dispatcher, so archives created from direct prints had no created_by_id and didn't show up in per-user statistics. Queue and reprint paths already forwarded the user correctly. Bind the auth dependency to current_user and pass its id/username through to dispatch_print_library_file, matching the reprint endpoint. The dispatcher already propagates this to printer_manager.set_current_print_user, which the archive creation reads. --- CHANGELOG.md | 1 + backend/app/api/routes/library.py | 6 +++--- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f48341a5d..dbd2152c5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -21,6 +21,7 @@ All notable changes to Bambuddy will be documented in this file. - **Plate-Clear Confirmation Disabled by Default** — New installs ship with Settings → Workflow → "Require Plate-Clear Confirmation" off. Multiple new users reported queued prints appearing to not start because the prompt was waiting for acknowledgement; opt in from Workflow if you want the confirmation gate. ### Fixed +- **Direct Print from Library Not Attributed to User** — Clicking the Print button on a library file dispatched the job with no `created_by_id`, so the resulting archive had no owner and the print didn't show up in per-user statistics. The Queue and Reprint paths already forwarded the authenticated user; the library `POST /files/{file_id}/print` endpoint now does the same, reading the user from the JWT and passing it through to the dispatcher so direct prints are attributed like queued and reprinted ones. - **Add/Edit Printer Modal Clipped on Short Viewports** ([#964](https://github.com/maziggy/bambuddy/issues/964)) — On short or zoomed-in browser windows, the Add Printer and Edit Printer dialogs exceeded the viewport height with no scroll, hiding the lower fields (Access Code, Model, Location) and the Save button. Users had to zoom the browser out to complete the form. The modal overlay now scrolls and the card caps at `calc(100vh - 2rem)` with internal overflow so every field stays reachable regardless of viewport height. Thanks to @MartinNYHC for reporting. - **AMS Drying Silently Does Nothing** ([#971](https://github.com/maziggy/bambuddy/issues/971)) — Clicking Start Drying on a supported printer (e.g. P1S with AMS 2 Pro) could publish the MQTT command successfully but leave the AMS idle with no UI feedback. Two issues: (1) the firmware rejects the command when `dry_sf_reason` reports a blocking state (most commonly code 8 — AMS 2 Pro external power adapter not plugged in — but also "AMS busy", "already drying", etc.), and Bambuddy parsed that array but never surfaced it to the user; (2) the payload sent `filament: ""`, which some firmwares treat as an invalid-field refusal. The `/drying/start` endpoint now inspects the live `dry_sf_reason` for the target AMS unit and returns a descriptive 409 (e.g. "Plug in the external AMS power adapter to start drying") instead of silently publishing, and backfills an empty `filament` from the first loaded tray's type (defaulting to `PLA`) so the printer never rejects the command for a missing field. Thanks to @MartinNYHC for reporting. - **Webhook Tokens Leaked into Logs When Debug Logging Enabled (Security)** — Turning on Settings → Support → Debug Logging elevated the `httpx` and `httpcore` loggers to DEBUG, which caused httpx to log the full URL of every outbound HTTP request. For Discord notifications and generic webhook notifications, the URL *is* the secret — the bearer token is embedded in the path — so any user who enabled debug logging (typically to capture logs for a bug report) was writing their Discord webhook token to `bambuddy.log` and then pasting it into GitHub issues or support bundles. `httpx`/`httpcore` are now pinned to `WARNING` regardless of the debug toggle; `paho.mqtt` still honours debug. If you enabled debug logging while notifications were sending, rotate any exposed Discord/webhook URLs — the token is in the path, so the whole URL must be regenerated in the provider's UI. diff --git a/backend/app/api/routes/library.py b/backend/app/api/routes/library.py index 3b450565c..8025048ee 100644 --- a/backend/app/api/routes/library.py +++ b/backend/app/api/routes/library.py @@ -2169,7 +2169,7 @@ async def print_library_file( printer_id: int, body: FilePrintRequest | None = None, db: AsyncSession = Depends(get_db), - _: User | None = Depends(require_permission_if_auth_enabled(Permission.PRINTERS_CONTROL)), + current_user: User | None = Depends(require_permission_if_auth_enabled(Permission.PRINTERS_CONTROL)), ): """Dispatch a library file for send/start on a printer. @@ -2238,8 +2238,8 @@ async def print_library_file( printer_name=printer.name, options=body.model_dump(exclude_none=True), project_id=body.project_id, - requested_by_user_id=None, - requested_by_username=None, + requested_by_user_id=current_user.id if current_user else None, + requested_by_username=current_user.username if current_user else None, ) except DispatchEnqueueRejected as e: raise HTTPException(status_code=409, detail=str(e)) from e