2 Commits
Author SHA1 Message Date
maziggy ecdf577cfc test(security-fixtures): nosec B104/B108 on new 0.2.4.6 test code
Two adversarial-input fixtures added on the 0.2.4.6 branch were
  missing the # nosec annotation that 32b3a93e established for the
  same pattern. New TestNotArmedDiagnosticLogging test for the #1429
  defensive diagnostic uses bind_address="0.0.0.0"; new
  test_queue_start_user_attribution.py (#1670 fix) uses a /tmp path
  in a PrintArchive fixture. Same annotation-only convention as the
  test_virtual_printer.py sites.
2026-06-09 13:32:15 +02:00
maziggy 47fe30c5ad fix(queue): credit user who clicks /start in print log when auth on (#1670)
The print log's User column came from printer_manager.get_current_print_user,
  but only background_dispatch (Archive Print, Library Print) ever populated
  that dict. The Queue manual-start path went straight from
  POST /queue/{id}/start into PrintScheduler._start_print, neither end
  recording the clicker — so any print started from the queue landed in
  PrintLogEntry with created_by_username NULL even with auth enabled.

  Two-sided fix: /start now writes user.id to item.created_by_id when no
  prior owner is set (preserves UI-added items' original uploader), and
  PrintScheduler gains _propagate_owner_to_printer_manager called from
  _start_print to hand the owner into set_current_print_user before the
  print command goes out.
2026-06-07 08:22:42 +02:00