Commit Graph
6 Commits
Author SHA1 Message Date
maziggy 37b73b8868 Sync 2026-02-03 13:02:36 +01:00
maziggy 3fa9ed2b91 Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.

Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
  archives, projects, settings, api_keys, groups, cloud, github_backup,
  support, notifications, notification_templates, maintenance, filaments,
  external_links, smart_plugs, discovery, firmware, kprofiles, camera,
  ams_history, pending_uploads, updates, spoolman, system, print_queue,
  printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
  streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)

Fixes: CVE-2026-25505
2026-02-03 08:44:07 +01:00
maziggy 0b3df17920 Sanitize printer serial numbers in support bundle logs (Issue #216)
The support bundle states that printer serial numbers are NOT collected,
but they were appearing in debug logs. Added regex to sanitize Bambu Lab
serial numbers (00M/01D/01S/01P/03W prefix + alphanumeric) while keeping
the prefix for debugging context.

Example: [01D00A12345678] -> [01D[SERIAL]]

Closes #216
2026-02-01 14:26:56 +01:00
maziggy 576734c897 Fixed frontend/backend tests 2026-01-20 17:50:16 +01:00
maziggy 90249d2367 Adds a live log viewer component to the Support & Troubleshooting section
that allows viewing and filtering application logs in real-time.
Features:
- Start/Stop live streaming with 2-second auto-refresh
- Filter by log level (DEBUG, INFO, WARNING, ERROR)
- Text search across messages and logger names
- Clear logs with one click
- Expandable multi-line log entries (stack traces, etc.)
- Auto-scroll to follow new entries

Closes #87
2026-01-20 16:11:45 +01:00
maziggy 50fd0c018b Add support bundle feature for issue reporting
- Add /api/v1/support/debug-logging endpoints to toggle debug log level
  - Add /api/v1/support/bundle endpoint to generate ZIP with system info and logs
  - Debug logging state persists across restarts via Settings database
  - Add debug logging indicator banner in Layout with real-time duration timer
  - Add Support & Troubleshooting section to System Information page
  - Privacy protection:
    - Filter sensitive settings (emails, keys, tokens, URLs, configs)
    - Sanitize paths to remove usernames
    - Remove hostname from collected data
    - Replace IP addresses with [IP] and emails with [EMAIL] in logs
  - Add privacy info panel explaining what data is/isn't collected
  - Require debug logging to be enabled before downloading support bundle
2026-01-05 09:54:31 +01:00