The bug report endpoints (start-logging, stop-logging, submit) had no
authentication, allowing anyone on the network to enable debug logging,
retrieve sanitized system logs, and trigger bug report submissions when
auth was enabled. All three now require permission when auth is enabled:
start-logging requires settings:update, stop-logging and submit require
settings:read. Endpoints remain open when auth is disabled (default).
Replace fixed 30-second debug log collection with an interactive
3-step flow: start logging, reproduce the issue, stop & submit.
Users now control timing instead of racing a countdown.
Backend: split _collect_debug_logs() into POST /start-logging and
POST /stop-logging endpoints; add debug_logs field to submit request.
Frontend: 3-step progress indicator with elapsed timer, pulsing
active state, and 5-minute auto-stop. Updated all 7 locale files.
Floating bug report button submits issues via bambuddy.cool relay (no GitHub
token needed locally). Collects 30s debug logs with printer push_all, sanitizes
all sensitive data, uploads logs as files to GitHub. Screenshot upload/paste/drag
with JPEG compression. Translated into all 7 languages. Includes 21 tests.