maziggy
00251fe808
feat(orca-cloud): pair via RFC 8628 device flow, replacing the paste-based sign-in
...
OrcaSlicer shipped a first-class external-app pairing API (OAuth 2.0 Device
Authorization Grant), so the Supabase-PKCE copy-paste flow is replaced end to
end. Connecting is now: click Connect, approve a short code on the Orca Cloud
settings page, done — no redirect, no callback paste, no client secret, works
from a LAN IP / localhost / behind a proxy.
Backend: services/orca_cloud.py rewritten to device-code request + poll (the
four RFC outcomes) + refresh_token grant + introspection + external sync pull;
routes expose /device/start and /device/poll (device_code kept server-side in
the reused orca_cloud_pending_* columns, no migration). Requests sync:read
(read-only feature). Prod endpoint by default, ORCA_CLOUD_API_BASE overrides
to staging. Wired the shared httpx client (fixes a per-request socket leak).
Frontend: device-code connect UI + api client methods; all 11 locales updated.
2026-07-17 08:16:35 +02:00
maziggy
18d534c945
feat(orca-cloud): integrate Orca Cloud profile sync across UI, slicer and SpoolBuddy
...
Reads, lists, and slices with profiles from a user's Orca Cloud account
(OrcaSlicer 2.4.0-alpha's Supabase-backed sync) alongside the existing
Bambu Cloud integration. Four sign-in providers (Google / Apple / GitHub /
email+password); password defaults. Paste-flow PKCE because Orca's
Supabase project only allowlists localhost redirect_to — open feature
request at OrcaSlicer/OrcaSlicer#14028 .
Surfaces:
- Profiles tab: new "Orca Cloud" tab next to "Bambu Cloud" with the same
rich layout (search + 5 filter dropdowns + 3-column grouped grid +
read-only detail modal)
- SliceModal: 4-tier preset picker (orca_cloud > local > bambu cloud >
standard); separate status banner per cloud; metadata-aware pre-pick
scores Orca filaments above local (Orca's sync_pull returns full
content inline so filament_type / filament_colour come for free, no
per-setting fetch rate-limit dance)
- ConfigureAmsSlotModal: orca_cloud as a new preset source (prefixed
orca_<UUID> to match local_/builtin_); generic Bambu filament-ID
derivation from parsed material (printer firmware can't grok Orca
UUIDs); slot mapping persists preset_source='orca_cloud'
- SpoolForm / SpoolBuddyWriteTagPage: Orca filaments merge into the
cloud preset list via Promise.allSettled (OrcaProfileMeta is
structurally identical to SlicerSetting)
Backend:
- services/orca_cloud.py: OrcaCloudService with PKCE / token exchange /
single-use refresh rotation / get_user_info / list_profiles via the
bare /sync/pull bootstrap path
- routes/orca_cloud.py: 7 endpoints (auth/start, auth/finish,
auth/password, status, logout, profiles, profiles/{id}); router-level
_cloud_api_key_gate + per-route cloud_caller() so API-keyed callers
(SpoolBuddy kiosk) properly resolve their owner User; just-in-time
refresh with atomic persist-before-API-call
- routes/slicer_presets.py: _fetch_orca_cloud_presets mirrors the Bambu
Cloud fetcher (status vocabulary, 5min cache, permission shortcut);
_dedupe_by_name extended to 4 tiers; UnifiedPresetsResponse gains
orca_cloud + orca_cloud_status
- services/preset_resolver.py: PresetRef.source extended with
"orca_cloud"; _resolve_orca_cloud walks list + filters
- 8 columns on users table for tokens (5 persistent) + transient PKCE
handshake state with 10-min TTL (3); dialect-branched DATETIME /
TIMESTAMP; auth-disabled mode falls back to Settings table
- orca_cloud:auth permission folded into can_access_cloud API-key scope
(same trust dimension)
2026-06-04 15:50:44 +02:00