Commit Graph
2027 Commits
Author SHA1 Message Date
maziggy 2d5dd1b31f Fix AMS slot changes failing until manual reconnect (#887)
Add timeout and retry to the developer mode probe. After a keep-alive
  timeout, paho auto-reconnects but the session can be half-broken: the
  printer sends status but ignores commands. The probe had no recovery —
  one unanswered probe permanently blocked retries. Now times out after
  10s with one retry; two consecutive failures force-close the socket for
  a clean reconnect.
2026-04-04 14:08:29 +02:00
maziggy 411c165291 Updated .gitignore 2026-04-04 13:59:22 +02:00
maziggy aeb61e58d9 Fix spool manager deducting double filament after print completion (#880)
Skip AMS remain% weight sync in on_ams_change while a print session is
  active. The MQTT FINISH message triggers both the AMS weight sync (SET
  from remain%) and the usage tracker (ADD from 3MF data) in the same
  event loop cycle, causing double deduction. The active-session check is
  snapshotted before any await to prevent a race with on_print_complete
  popping the session during interleaved execution.
2026-04-04 13:38:16 +02:00
maziggy 2a6df22075 Restrict temp file permissions for camera snapshots
Camera snapshot, test, and plate detection endpoints created temporary
  JPEG files with default 0644 permissions. Switch from NamedTemporaryFile
  to mkstemp with explicit 0600 permissions.
2026-04-04 13:18:53 +02:00
maziggy 4d09b3f669 Add HTTP security headers middleware
Set X-Content-Type-Options, X-Frame-Options, and Referrer-Policy on all
  responses. CSP omitted (React inline styles would require unsafe-inline,
  negating protection). HSTS omitted (LAN app commonly accessed over HTTP).
2026-04-04 13:08:37 +02:00
maziggy 70b12e1949 Fix API key empty printer_ids granting full access
An API key with printer_ids=[] was treated the same as null (global
  access) due to a falsy check. Now None means global access and []
  means no printer access. Added a startup migration to normalize any
  existing [] rows to NULL so they retain their intended global access.

  Also fixed the webhook /queue endpoint which used the same falsy
  check, allowing []-scoped keys to see all printers.
2026-04-04 13:01:54 +02:00
maziggy 5709282200 Add authentication to bug report debug logging endpoints
The bug report endpoints (start-logging, stop-logging, submit) had no
  authentication, allowing anyone on the network to enable debug logging,
  retrieve sanitized system logs, and trigger bug report submissions when
  auth was enabled. All three now require permission when auth is enabled:
  start-logging requires settings:update, stop-logging and submit require
  settings:read. Endpoints remain open when auth is disabled (default).
2026-04-04 12:54:31 +02:00
maziggy 7fa00ed475 Fix path traversal vulnerability in file upload endpoints
Archive upload endpoints used the client-supplied filename directly
  in file paths, allowing an authenticated attacker to write files
  outside the intended directory (e.g. ../../evil.3mf bypasses the
  .3mf extension check). Added _safe_filename() helper that normalizes
  backslashes and extracts the basename before constructing paths.
2026-04-04 12:41:01 +02:00
maziggy 0ece6725bd Fix thumbnails returning 401 after backend restart
Stream tokens are stored in-memory and lost on restart. The frontend
  cached the old token for up to 50 minutes (staleTime) and never
  refetched, so all thumbnail/stream requests failed with 401 until
  a manual page reload.

  Added a global error listener in useStreamTokenSync that detects
  when img/video elements fail to load with the current stream token
  and automatically invalidates the camera-stream-token query to
  fetch a fresh one. Debounced with a 5s cooldown to avoid spamming
  when many images fail at once.
2026-04-04 12:31:39 +02:00
maziggy 42028ffc98 Fix SpoolBuddy kiosk screen blanking immediately on boot
The touchscreen display blanked right after boot, requiring a touch
  to wake. Two issues: no consoleblank=0 in cmdline.txt (kernel blanks
  the console during Plymouth→labwc transition), and the wlr-randr
  anti-blank loop slept 60s before its first run.

  - Add consoleblank=0 to kernel cmdline in install.sh
  - Move sleep after wlr-randr in labwc autostart so it fires immediately
2026-04-04 10:45:55 +02:00
maziggy 039db1217d Add shortest-job-first queue scheduling with starvation guard (#879)
New SJF toggle badge on the queue page. When enabled, the scheduler
  picks shorter print jobs before longer ones instead of FIFO. A
  starvation guard flags jobs that get skipped once, moving them to
  the front on the next cycle so long jobs can't be postponed indefinitely.

  - Add print_time_seconds and been_jumped columns to PrintQueueItem
  - Cache print duration from 3MF metadata at queue item creation
  - SJF query: printer_id, target_model, been_jumped DESC, print_time_seconds ASC, position
  - Mark jumped items in-memory after each print start
  - Toggle badge on queue page header with live state indicator
  - Frontend auto-sorts to match scheduler order when SJF enabled
  - Settings schema, boolean parsing, and migration (SQLite + PostgreSQL)
  - i18n badge keys for all 7 locales
  - 10 integration tests for SJF ordering and starvation logic
  - Wiki, website, README, and changelog updated
2026-04-04 10:25:17 +02:00
maziggy 3381f73e0f Enable AMS drying support for H2S with firmware 01.02.00.00+ (#886)
Move H2S from the drying-unsupported blocklist to the firmware-gated
  list, requiring minimum firmware 01.02.00.00 (released end of March
  2026). Both remote AMS drying and queue auto-drying now work on H2S.
2026-04-04 09:26:00 +02:00
maziggy 6d40ee561c Show plate number on printer cards and actual printer in queue (#881)
Printer cards and stream overlay now display the plate number when
  printing plate 2+ of a multi-plate 3MF (e.g. "MyModel — Plate 3").
  Queue items using model-based assignment ("Any P1S") now show the
  actual assigned printer name once the scheduler picks a printer,
  instead of continuing to show the generic target.
2026-04-04 09:19:31 +02:00
maziggy 0f0fac9b32 Show database engine and version on System Information page
Display the active database backend (SQLite or PostgreSQL) and its
  version in the Database section of the System Info page. SQLite queries
  sqlite_version(), PostgreSQL queries SELECT version() and
  pg_database_size(). Helps users verify which database is in use.
2026-04-04 09:05:35 +02:00
maziggy 15cd4cbb0a Fix queue widget ignoring plate-clear confirmation setting (#752)
The "Clear Plate & Start Next" button on printer cards appeared
  even when "Require plate-clear confirmation" was disabled in
  Settings. The backend correctly auto-dispatched without waiting,
  but the frontend widget always showed the prompt. Thread the
  require_plate_clear setting through PrinterCard → PrinterQueueWidget
  so the widget shows a passive queue link when the setting is off.
2026-04-03 11:47:18 +02:00
maziggy 610431d6b7 Add optional PostgreSQL database support
Bambuddy can now use an external PostgreSQL database via the
  DATABASE_URL environment variable. SQLite remains the default.
  Dialect-aware helpers handle upserts, PRAGMAs, FTS (FTS5 vs
  tsvector+GIN), backup/restore, and health checks. All migration
  blocks use savepoints to prevent Postgres transaction poisoning.
  Backups are always portable SQLite format regardless of backend.
  Cross-database restore imports SQLite backups into PostgreSQL
  with automatic boolean/datetime conversion, NOT NULL default
  filling, and FK constraint handling.
2026-04-03 11:33:29 +02:00
maziggy 76adf70fd4 Add separate power/energy URLs and multipliers for REST smart plugs (#472)
REST/Webhook smart plugs can now fetch power and energy data from
  individual URLs instead of requiring all values in a single status
  response. Each value falls back to the shared Status URL when no
  separate URL is set, preserving backward compatibility. Added power
  and energy multipliers for unit conversion (e.g. 0.001 for Wh→kWh).
2026-04-03 08:31:08 +02:00
maziggy d327c70006 Fix WebSocket crash on printers without fun field (#873)
Race condition in _update_state: dev mode probe released GIL via MQTT
  publish between raw_data overwrite and vt_tray list restoration, letting
  the event loop iterate over raw dict keys (strings) instead of spool
  dicts. Affects A1, P1, and X1Plus firmware that don't send the fun field.

  Fix: normalize vt_tray dict→list before raw_data assignment, restore
  preserved fields before any GIL-releasing work, add defensive guard in
  printer_state_to_dict.
2026-04-02 13:58:42 +02:00
maziggy e5a0382dba Fix test conftest missing 4 model imports causing slot_preset_mappings table error
The test conftest.py model import list was out of sync with database.py,
  missing slot_preset, project_bom, spool_k_profile, and spoolbuddy_device.
  Base.metadata.create_all() never created those tables in the test DB.
2026-04-02 13:29:44 +02:00
maziggy 7c05b4bd0f Updated CHANGELOG 2026-04-02 13:17:13 +02:00
maziggy eec0fb51c0 Update aiohttp, cryptography, and Pygments for CVE fixes
aiohttp 3.13.3 → 3.13.4 (10 CVEs — header validation, parser fixes)
  cryptography 46.0.5 → 46.0.6 (CVE-2026-34073 — X.509 wildcard SAN bypass)
  Pygments 2.19.2 → 2.20.0 (CVE-2026-4539 — ReDoS in archetype lexer)
2026-04-02 13:16:18 +02:00
maziggy 02262472f8 Fix SpoolBuddy status bar not updating on printer switch
The bottom message bar showed stale warnings from the previous printer
  after switching via dropdown or swipe. Cached AMS data was shared across
  all printers in a single ref, so switching to a printer whose status
  hadn't loaded fell back to the wrong printer's data. The Layout also
  unconditionally cleared alerts set by child pages. Fixed by keying the
  AMS cache per printer ID and only clearing Layout-owned alerts.
2026-04-02 11:34:42 +02:00
maziggy eec1e43d6d Fix AMS history cleanup crash from naive/aware datetime mismatch
The periodic cleanup of old AMS sensor history entries (every ~24h)
  failed with "can't compare offset-naive and offset-aware datetimes".
  The cutoff used datetime.now(timezone.utc) but recorded_at stores
  naive datetimes via SQLite's func.now(). Use utcnow() instead.
2026-04-02 11:14:06 +02:00
maziggy 34ccc7b6e7 Fix bed cooled notification never firing on some firmware (#872)
Replace polling-based bed cooldown monitor with event-driven approach.
  Some firmware stops sending bed_temper after print completion, causing
  the 30-min polling loop to time out on stale cached values. Now reacts
  instantly to bed_temper MQTT data via a new on_bed_temp_update callback.
2026-04-02 10:37:48 +02:00
maziggy cb0c4b5ffe Standardize webhook notification payloads with structured event data (#871)
Thread event_type and template variables through the webhook call chain so
  all generic webhook payloads include an "event" field and event-specific
  data (printer, filename, duration, etc.) as top-level JSON fields. Existing
  title/message/timestamp/source fields are unchanged. Slack format unaffected.
2026-04-02 10:13:35 +02:00
maziggy f4df4393be Add spool inventory and print archive backup to GitHub backup (#870)
GitHub backup can now optionally include spool inventory (with usage
  history) and print archive metadata as JSON. Both toggles are off by
  default. No binary files (gcode/3MF) are included.
2026-04-02 09:59:00 +02:00
maziggy ad96337587 Fix external spool ams_mapping2 using wrong ams_id on single-nozzle printers (#859)
Single-nozzle printers (X1C, P1S, A1) report tray_now=254 for external
  spool, but BambuStudio sends ams_id=255 (VIRTUAL_TRAY_MAIN_ID) in the
  print command's ams_mapping2 field. Bambuddy was passing 254 as-is,
  causing firmware to target AMS tray 0 instead of external spool —
  resulting in 07FF_8012 "Failed to get AMS mapping table" or prints stuck
  at heatbed heating when an AMS is connected but empty.

  Map external spool to ams_id=255 for all non-H2D printers. H2D
  dual-nozzle printers retain 254 (deputy) / 255 (main) distinction.
2026-04-02 09:27:35 +02:00
maziggy c72ab43c6f Updated CHANGELOG 2026-04-01 15:29:24 +02:00
maziggy 02515d2836 Updated CHANGELOG 2026-04-01 13:39:47 +02:00
maziggy ae2a262585 Add developer mode probe for printers without fun field 2026-04-01 12:41:18 +02:00
maziggy 75fa935851 Fix filament color name and subtype inconsistencies (#857) 2026-04-01 12:20:12 +02:00
maziggy 3270179090 Add batch print quantity to print/schedule dialog (#342) 2026-04-01 11:55:30 +02:00
maziggy 9aa9fdc586 Add configurable default print options (#858) 2026-04-01 10:30:05 +02:00
maziggy 914adde5aa Add REST/Webhook smart plug type (#472) 2026-04-01 10:06:01 +02:00
maziggy f228a8b549 Fix sidebar bottom icons cut off when smart plugs enabled (#862) 2026-04-01 09:17:03 +02:00
maziggy 5a696f9fa3 ● Add prefer lowest remaining filament in auto-matching (#805)
When multiple AMS spools match the same type/color criteria, an optional
  setting now prefers the spool with the lowest remaining filament. This
  helps consume partial spools before starting new ones. Sorting applies
  to all matching paths: queue scheduler, print modal, and multi-printer
  mapping. Unknown remain values (-1) sort to end.
2026-03-31 14:14:15 +02:00
maziggy 3c887f5166 Add bulk printer actions toolbar (#825)
Select multiple printer cards and apply bulk actions (stop, pause,
  resume, clear notifications, clear bed) from a floating toolbar.
  Selection shortcuts: Select All, Select by State (printing/paused/
  finished/idle/error/offline), Select by Location. Action buttons are
  smart-enabled based on selected printers' current states. Confirmation
  modals for destructive actions. The status summary bar now shows all
  printer states.
2026-03-31 13:24:43 +02:00
maziggy ec0ae162e8 Add per-user statistics filtering (#730)
Admins can now filter the Statistics page by user via a new
  stats:filter_by_user permission. A user dropdown appears in the stats
  header showing all users plus "No User (System)" for prints without
  attribution. The filter applies to all stats widgets, failure analysis,
  and CSV/Excel exports. Backend validates the permission on all 4 stats
  endpoints, returning 403 if the filter is used without authorization.
2026-03-31 12:13:58 +02:00
maziggy 51b5781c0b Re-arranged settings 2026-03-31 11:27:06 +02:00
maziggy 046dbf3608 Add stagger to Print dialog, add plate-clear setting (#752)
Stagger option now available when printing directly to multiple printers,
  not just in queue mode. Prints are automatically queued with staggered
  start times using group size/interval from Settings. New "Require
  plate-clear confirmation" setting lets farm users disable per-printer
  plate confirmations so queued prints start automatically on finished
  printers.

  Also fixes settings API type parsing for require_plate_clear (boolean),
  stagger_group_size and stagger_interval_minutes (integer) — without this,
  saved values returned as strings would cause the settings toggle to
  always show enabled and trigger a permanent save loop.
2026-03-31 11:12:42 +02:00
maziggy 8816c2334e Added install/update_macos.sh 2026-03-31 10:25:57 +02:00
maziggy 8b332f638f Fix external spool print failing on printers without AMS (#854)
Printers with no AMS hardware (P1S/P1P with only external spool)
  rejected print commands with "Failed to get AMS mapping table"
  because use_ams was always sent as true. Now auto-sets use_ams=false
  when all filament slots map to external spools or are unmapped.
  H2D-series excluded since they use use_ams for nozzle routing.
2026-03-31 10:02:25 +02:00
maziggy fd9ece00d4 Post work PR #851 2026-03-31 09:11:45 +02:00
Michael Behringer 50c976d7ec Fix/wrong filament mapping (#851)
Fix/wrong filament mapping (#851)
2026-03-31 09:07:51 +02:00
maziggy c1adc63f14 Added tests for PR #851 2026-03-31 09:05:05 +02:00
maziggy 39a7898e52 Added Spoolbuddy options to Github issue template 2026-03-30 12:46:43 +02:00
maziggy f3b2a24fa0 Fix external folder scan 500 on 3MF files (#846)
scan_external_folder stored raw 3MF metadata containing _thumbnail_data
  bytes directly in the JSON column, causing a serialization error. Applied
  the same clean_metadata() pattern used by upload/zip extraction and
  removed the call to the non-existent parser.extract_thumbnail().
2026-03-30 08:36:39 +02:00
maziggy 86693b4f75 Fix archives capped at 50 items, add pagination (#843)
The archives page only fetched the 50 most recent prints due to a
  hardcoded API limit default. Added client-side pagination with
  configurable page sizes (25/50/100/200/All) and bumped the fetch
  limit to return all archives. Page size is persisted to localStorage.
2026-03-30 08:27:34 +02:00
maziggy eaf0a1c281 Add queue timeline view, visual refresh, and fix plate thumbnail auth
Queue page redesign: compact stats bar replaces summary cards, color-
  coded left borders for status scanning, collapsible history with
  condensed rows, and a new production schedule timeline view (#823)
  showing estimated completion times grouped by hour with filter tabs
  and day navigation. i18n keys added for all 7 languages.

  Fix plate thumbnails returning 401 in print modal when auth is enabled
  (missing stream token). Fix schedule calendar picker opening off-screen
  (hidden input positioned with sr-only instead of near the date field).
2026-03-28 13:45:37 +01:00
maziggy 24a5217d46 Fix filament usage not recorded when auto-archive is disabled
on_print_complete returned early when no archive_id was found (auto-
  archive off), skipping both internal inventory tracking (AMS remain%
  deltas) and Spoolman usage reporting. Moved the filament usage tracking
  block to run before the archive_id early-return so consumption is
  always recorded regardless of the auto-archive setting.
2026-03-28 12:30:45 +01:00