Commit Graph
2071 Commits
Author SHA1 Message Date
maziggy 60d034d40c Fix SpoolBuddy update Docker failure — asyncssh local-username lookup
Follow-up to the previous commit that swapped the `ssh`/`ssh-keygen`
  subprocesses for asyncssh. asyncssh.connect() internally calls
  getpass.getuser() to resolve the *local* username for ~/.ssh/config
  host matching, regardless of the explicit `username=` we pass for the
  remote login. Under an arbitrary Docker PUID with no /etc/passwd
  entry, getpass.getuser() tries LOGNAME/USER/LNAME/USERNAME (all unset
  in python:3.13-slim) and falls back to pwd.getpwuid(), which raises
  KeyError. asyncssh rewraps that as "Unknown local username: set one
  of LOGNAME, USER, LNAME, or USERNAME in the environment" — which
  surfaced in the UI as "ssh connection failed: no username set in the
  environment".

  Fix is two-part:

  - _ensure_local_username_env() runs at module import. If getpass
    .getuser() already works, or any of LOGNAME/USER/LNAME/USERNAME is
    set, it is a no-op. Otherwise it sets LOGNAME=bambuddy so asyncssh
    can proceed. Native installs are untouched.

  - asyncssh.connect() is now called with config=[] to skip the
    default ~/.ssh/config load, which relies on a resolvable home
    directory that may not exist under arbitrary Docker PUIDs.

  Three new unit tests cover the env-var fallback, including the case
  where the operator has set USER but the passwd lookup still fails.
2026-04-10 10:35:57 +02:00
maziggy a78a4bff2e Fix SpoolBuddy update still failing in Docker after keypair fix
Commit 67749565 eliminated ssh-keygen from the SpoolBuddy remote-update
  flow, but the update path still shelled out to the OpenSSH `ssh` client
  for every command. Like ssh-keygen, the `ssh` binary calls
  getpwuid(getuid()) during startup and aborts with "No user exists for
  uid <N>" when the container runs under an arbitrary PUID that isn't in
  /etc/passwd (python:3.13-slim only ships a root entry, so any
  `user: "1000:1000"` compose setup trips the same error).

  detect_current_branch() had a related problem: when the git repo is
  bind-mounted into the container, .git exists inside Docker, so the code
  tried to run `git rev-parse`. Git isn't in the image, so the subprocess
  silently fell back to the GIT_BRANCH env var — and if git ever were
  added, it could hit the same getpwuid trap.

  The entire update path is now subprocess-free:

  - _run_ssh_command uses asyncssh (pure-Python, built on the already
    installed cryptography library). Connection errors map to rc=255 to
    match `ssh`'s convention; asyncio.timeout handles the timeout path.
  - detect_current_branch reads .git/HEAD directly (handling git-worktree
    `gitdir:` pointer files too), keeping the same GIT_BRANCH → "main"
    fallback chain.
  - shutil and the inline `import subprocess` are gone from the module.

  Regression tests assert that neither keypair creation, branch
  detection, nor command execution spawns any subprocess. Native installs
  are unaffected.
2026-04-10 10:25:08 +02:00
maziggy d65d440cfb Fix external sidebar link icon missing when auth enabled (#878)
The sidebar <img> tag in Layout.tsx fetched custom external-link icons
  via a raw /api/v1/external-links/{id}/icon URL. That endpoint is
  protected by the shared camera-stream token (passed as ?token=xxx
  because <img> tags cannot send Authorization headers), so the request
  came back 401 with the "Valid camera stream token required" message.

  The edit dialog already routed through api.getExternalLinkIconUrl(),
  which wraps the URL via withStreamToken(); the sidebar now does the
  same in both the open-in-new-tab and NavLink branches.
2026-04-10 09:56:56 +02:00
maziggy 4d57c9cac4 Fix SJF toggle disappearing from queue page (#879)
The Shortest Job First toggle badge was rendered inside the Pending
  Queue section header, which only mounts when pendingItems.length > 0
  and the list view is selected. Clicking the toggle often lined up
  with the scheduler picking up the last pending item, which unmounted
  the whole section and took the toggle with it.

  Moved the toggle into the queue page header next to the list/timeline
  view switcher so it stays visible regardless of pending-item count,
  filters, or view mode. On mobile the view-mode switcher remains
  hidden (as before) but the SJF button is visible icon-only.
2026-04-10 09:48:40 +02:00
lietschaend 11c42841f3 fix(projects): fix breadcrumb showing i18n key instead of translated text (#931)
Fixes #929. The breadcrumb in ProjectDetailPage used the non-existent key
`navigation.projects`. Changed to the correct key `nav.projects` which is
defined in all locale files and resolves to e.g. 'Projects' in English.
2026-04-10 09:26:47 +02:00
maziggy 648f7d6ba8 P2S - enable AMS drying for firmware 01.02.00.00 and later 2026-04-09 15:42:34 +02:00
maziggy 6774956565 Fix SpoolBuddy update failing in Docker with "no user exists for uid"
The SpoolBuddy remote-update flow shelled out to `ssh-keygen` to create
  its update keypair on first use. Inside the Docker container the process
  runs under an arbitrary PUID that is not listed in /etc/passwd, so
  ssh-keygen aborted at the getpwuid() home-directory lookup with
  "no user exists for uid 1001" and the update button failed.

  Generate the ed25519 keypair in-process via the `cryptography` library
  (already a dependency) and serialize it in OpenSSH format. No subprocess,
  no /etc/passwd lookup. Native installs are unaffected.

  Added a regression test that asserts no subprocess is spawned during
  keypair creation so this can't come back.
2026-04-09 12:53:20 +02:00
maziggy 39a5840f67 Fix camera reconnect counter off-by-one and ffmpeg log flood (#925)
Two bugs surfaced while investigating camera reconnect behaviour in #925.

  The camera page briefly displayed "Reconnecting attempt 6 of 5" before
  giving up, because the attempt counter could be incremented to the
  maximum while the reconnect banner was still rendering. The displayed
  value is now clamped to the configured maximum.

  Every failed ffmpeg spawn logged the full ~20-line ffmpeg version,
  configuration, and lib* banner, producing hundreds of lines of noise
  per failed camera click (one reported click produced 555 log lines
  across 30 retries). A new _summarize_ffmpeg_stderr helper strips the
  banner and caps output at the last 10 meaningful lines, applied at
  all three stderr log sites (immediate-failure, stream-ended,
  read-timeout). Covered by unit tests for empty input, banner
  stripping, line cap, blank-line filtering, and banner-only input.

  The underlying "camera service stops accepting connections after
  prolonged uptime" behaviour in the X1C firmware is still under
  investigation — these two fixes are independent of that root cause.
2026-04-09 11:29:57 +02:00
maziggy 848f558105 LDAP: POSIX primary group support and default fallback group
Two related LDAP authentication changes.

  Fix: POSIX primary group membership was ignored. authenticate_ldap_user
  only searched for posixGroup entries via memberUid (supplementary
  groups). A user's primary group — referenced by the gidNumber attribute
  on the user object matching gidNumber on a posixGroup — was never
  resolved, so users whose role came from their primary group landed
  without the expected permissions. The authenticator now runs a second
  search for posixGroup entries whose gidNumber matches the user's
  primary gidNumber, then dedupes DNs case-insensitively before passing
  the list to resolve_group_mapping (LDAP DNs are case-insensitive by
  spec).

  New feature: ldap_default_group setting. Settings → Authentication →
  LDAP → Advanced has a new "Default group" selector. When an LDAP user
  authenticates but is not listed in any mapped LDAP group, they are
  assigned to this fallback group instead of being left with no groups
  (and therefore no permissions). A warning is logged each time the
  fallback is applied so admins can spot missing group assignments.
  Empty setting preserves the old behavior.

  Tests: added 4 mocked authenticate_ldap_user tests covering primary
  gidNumber lookup, dedupe of overlapping memberUid+primary gid matches,
  case-insensitive DN dedupe, and the guard when a user entry has no
  gidNumber attribute. Also extended the existing parse_ldap_config tests
  to cover the new default_group field.

  Backend: ldap_service.py (primary group + dedupe + default_group
  field), schemas/settings.py (schema field), api/routes/auth.py
  (fallback wiring in _provision_ldap_user / _sync_ldap_user).

  Frontend: LDAPSettings.tsx default-group dropdown in the Advanced
  collapsible, api/client.ts type field, new i18n keys in all 7 locales
  (defaultGroup, defaultGroupNone, defaultGroupHint).
2026-04-09 10:48:42 +02:00
maziggy da080c22d3 Improve settings menu layout - 2 2026-04-09 09:52:56 +02:00
maziggy 8813de6f80 Improve settings menu layout - 1 2026-04-09 09:32:09 +02:00
maziggy d0b91ad4d5 Fix support bundle leaking virtual printer IP address
The debug support bundle included virtual_printer_remote_interface_ip
  unmasked in support-info.json. The setting key didn't match any
  sensitive-key filter substring. Added "_ip" to the filter set so IP
  address settings are excluded. Log file content was already redacted
  by the existing IPv4 regex.
2026-04-09 08:25:40 +02:00
maziggy 813d9dde38 Fix Spoolman location not cleared on auto-sync when spool removed from AMS (#921)
The on_ams_change auto-sync callback set locations for new spools but
  never called clear_location_for_removed_spools(), leaving stale locations
  that caused double-booked slots. Also pass synced_spool_ids in the
  single-printer sync route to match the sync-all endpoint behavior.
2026-04-09 08:16:54 +02:00
maziggy 502959a0df Fix plate-clear button unclickable after second print (#912)
The clearPlateMutation.isSuccess state from React Query persisted after
  the first successful plate clear. When the next print finished, the
  stale isSuccess rendered the static confirmation instead of the clickable
  button. Reset mutation state when printer leaves FINISH/FAILED.
2026-04-09 08:00:58 +02:00
maziggy 100610a1ef Bumped version 2026-04-08 13:17:25 +02:00
maziggy 8f327c541a Fix filament hover card rendering behind sidebar
Bump FilamentHoverCard z-index from z-50 to z-[60] so it always
  renders above the sidebar (z-30 desktop, z-50 mobile). (#900)
2026-04-08 13:07:25 +02:00
maziggy 46e183cb9f Removed --bind flag from docker_install.sh 2026-04-08 12:53:04 +02:00
maziggy 329223502a Spoolbuddy - fixed horizontal swiping 2026-04-08 11:59:59 +02:00
maziggy 49f3fc2964 Spoolbuddy - fixed horizontal swiping 2026-04-08 11:47:15 +02:00
maziggy 4c55eadeb6 Add SpoolBuddy quick menu with power control and system commands (#893)
Swipe down from the top of the SpoolBuddy display to open a quick-access
  menu for toggling printer smart plugs and managing the device (restart
  daemon, restart browser, reboot, shutdown). All destructive actions
  require confirmation.

  Backend: new POST /spoolbuddy/devices/{id}/system/command endpoint
  queuing reboot/shutdown/restart_daemon/restart_browser commands.
  Daemon: handles commands via subprocess (sudo reboot, systemctl restart).
  Frontend: SpoolBuddyQuickMenu component, swipe-down gesture detection,
  i18n keys for all 7 locales.
2026-04-08 11:38:50 +02:00
maziggy b76d6210cf Add SpoolBuddy quick menu with power control and system commands (#893)
Swipe down from the top of the SpoolBuddy display to open a quick-access
  menu for toggling printer smart plugs and managing the device (restart
  daemon, restart browser, reboot, shutdown). All destructive actions
  require confirmation.

  Backend: new POST /spoolbuddy/devices/{id}/system/command endpoint
  queuing reboot/shutdown/restart_daemon/restart_browser commands.
  Daemon: handles commands via subprocess (sudo reboot, systemctl restart).
  Frontend: SpoolBuddyQuickMenu component, swipe-down gesture detection,
  i18n keys for all 7 locales.
2026-04-08 11:29:44 +02:00
maziggy b6599dd419 Add LDAP/Active Directory authentication (#794)
Users can authenticate against an LDAP/AD server with configurable
  server URL, bind DN, search base, and user filter. Supports StartTLS
  and LDAPS — plaintext is not allowed. Both Active Directory (memberOf)
  and POSIX groups (memberUid) are mapped to BamBuddy groups on each
  login. Auto-provisioning creates local accounts on first LDAP login.
  Local admin accounts remain as fallback when LDAP is unreachable.
  Password management is disabled for LDAP users.
2026-04-08 10:41:27 +02:00
maziggy f3a8d5db20 Post work PR #889 2026-04-08 08:30:13 +02:00
Keybored d4913ef0df [Feature] Improve AssignSpoolModal filtering logic (#889)
[Feature] Improve AssignSpoolModal filtering logic (#889)
2026-04-08 08:28:25 +02:00
maziggy 42b1653f52 Fix spool weight tracking when auto-archive disabled for queue/reprint prints (#839)
When auto_archive was disabled but the print was dispatched by BamBuddy
  (queue/reprint), on_print_start discarded the expected print entry and
  returned early. The archive was never promoted to _active_prints, so at
  completion archive_id and ams_mapping were both None — all tracking paths
  failed silently. Now detects expected prints before the auto-archive
  early-return and falls through to the normal promotion path. Also injects
  the stored ams_mapping into the usage tracker session for printers where
  MQTT request topic subscription fails (P1S, A1).
2026-04-08 08:17:42 +02:00
maziggy d29688000f Updated CI 2026-04-07 17:16:48 +02:00
maziggy 0b0ab23052 Added stats CI 2026-04-07 16:19:42 +02:00
maziggy 240b6cb408 Added stats CI 2026-04-07 16:11:43 +02:00
maziggy fd140e3c64 Added stats CI 2026-04-07 16:08:54 +02:00
maziggy 4c052e04e1 Fix SpoolBuddy inventory not updating on spool changes (#905)
Spool CRUD endpoints (create, bulk create, update, delete, archive,
  restore) did not emit websocket events, so SpoolBuddy Dashboard and
  other tabs relying on event-driven cache invalidation never refreshed.

  All inventory mutation endpoints now broadcast an `inventory_changed`
  websocket event. Frontend handles it by invalidating `inventory-spools`.
v0.2.3b1-daily.20260407
2026-04-07 12:32:44 +02:00
dependabot[bot] ed61e756a6 Bump vite in /frontend in the npm_and_yarn group across 1 directory (#909)
Bump vite in /frontend in the npm_and_yarn group across 1 directory (#909)
2026-04-07 09:53:10 +02:00
maziggy 8c00b1b75f Fix multi-plug automation only working for first plug (#903)
When multiple smart plugs were assigned to the same printer, only the
  first plug's automation triggered. All automation paths (print start
  auto-on, print complete auto-off, queue auto-off, scheduler power-on)
  now iterate every plug linked to the printer. Also fix queue auto-off
  hardcoded to Tasmota instead of using the correct service for the plug
  type.
2026-04-07 09:44:48 +02:00
maziggy 2d9a56b3d0 Fix ghost jobs from SQLite lock on print completion (#897)
Queue status update (printing → completed) failed silently when SQLite
  was locked by another writer, leaving ghost jobs permanently stuck in
  printing status. Add run_with_retry() for SQLite lock retries and split
  runtime tracker into per-printer commits to reduce lock hold time.
2026-04-07 09:20:58 +02:00
maziggy 113bae4c63 Fix developer mode probe destabilizing MQTT on auto-reconnect (#887)
The dev mode probe (ams_filament_setting to ext slot) fired on every
  auto-reconnect, which destabilized some firmware MQTT brokers (A1/P1)
  causing a reconnect-probe-disconnect feedback loop. Now caches the
  probe result across reconnects and only probes once on first connect,
  with a 5s delay to let the session stabilize.
2026-04-07 09:00:37 +02:00
maziggy 4df0349310 Fix spool weight tracking when auto-archive is disabled (#839)
When auto-archive was off, archive_id was None at print completion so
  the entire 3MF tracking path was skipped. AMS remain% fallback also
  failed on printers reporting remain=-1. Now searches library files and
  previous archives by filename to locate the 3MF without an archive,
  and captures the AMS slot-to-tray mapping at print start so it's
  available at completion regardless of archive state.
2026-04-07 08:31:14 +02:00
maziggy af8f7a01d9 Updated CONTRIBUTING.md 2026-04-05 12:15:12 +02:00
maziggy f006472f79 Add auto-print G-code injection for queue items (#422)
Per-model start/end G-code snippets configurable in Settings (Workflow
  tab). Queue items get "Inject G-code" toggle — scheduler injects
  snippets into a temp 3MF copy before FTP upload. Supports Farmloop,
  SwapMod, AutoClear, Printflow 3D and similar bed-clearing systems.
  Original files are never modified.
2026-04-05 11:14:26 +02:00
maziggy aa9b60a265 Fix spool weight tracking for fallback archives, VT trays, and notifications (#839)
Usage tracking failed silently when FTP download failed (fallback archive
  with no 3MF), when printing from external spool holder (VT tray not
  iterated by AMS fallback), and notifications showed "Unknown" for time
  and filament. Now resolves 3MF from library/previous archives, tracks
  VT tray remain% deltas, enriches notifications with usage tracker
  results, and captures print time from MQTT for fallback archives.
2026-04-05 09:59:05 +02:00
maziggy 1645b51dad Add external folder subfolder preservation and fix file manager stale UI after delete
External folder scan now mirrors disk subfolder structure into the folder
  tree instead of flattening all files into root. Hidden directories are
  filtered, orphaned subfolders are cleaned up on rescan. Fixes #890.

  File manager delete endpoints (folder, file, bulk) now commit before
  returning the response — previously relied on post-response auto-commit,
  causing a race where the frontend refetch arrived before the commit.
2026-04-05 09:33:46 +02:00
maziggy edfd2e77c0 Revert "Add Load/Unload External filament buttons to printer controls"
This reverts commit e3cde14a0b.
2026-04-05 08:21:37 +02:00
NNeerr00 e3cde14a0b Add Load/Unload External filament buttons to printer controls
New dedicated MQTT methods, API endpoints, and UI buttons for
loading/unloading filament from the external spool holder without
requiring an AMS. Includes state guards to prevent load when filament
is already loaded and unload when nothing is loaded.
2026-04-05 00:04:26 +02:00
maziggy f20beae6cc Hosekeeping 2026-04-04 15:46:23 +02:00
maziggy 2e818b588a Housekeeping 2026-04-04 15:46:06 +02:00
Keybored 4a2a0b1a10 [Feature] Spoolbuddy spool detail card and UI improvements (#866)
[Feature] Spoolbuddy spool detail card and UI improvements (#866)
2026-04-04 15:34:09 +02:00
maziggy 2d5dd1b31f Fix AMS slot changes failing until manual reconnect (#887)
Add timeout and retry to the developer mode probe. After a keep-alive
  timeout, paho auto-reconnects but the session can be half-broken: the
  printer sends status but ignores commands. The probe had no recovery —
  one unanswered probe permanently blocked retries. Now times out after
  10s with one retry; two consecutive failures force-close the socket for
  a clean reconnect.
2026-04-04 14:08:29 +02:00
maziggy 411c165291 Updated .gitignore 2026-04-04 13:59:22 +02:00
maziggy aeb61e58d9 Fix spool manager deducting double filament after print completion (#880)
Skip AMS remain% weight sync in on_ams_change while a print session is
  active. The MQTT FINISH message triggers both the AMS weight sync (SET
  from remain%) and the usage tracker (ADD from 3MF data) in the same
  event loop cycle, causing double deduction. The active-session check is
  snapshotted before any await to prevent a race with on_print_complete
  popping the session during interleaved execution.
2026-04-04 13:38:16 +02:00
maziggy 2a6df22075 Restrict temp file permissions for camera snapshots
Camera snapshot, test, and plate detection endpoints created temporary
  JPEG files with default 0644 permissions. Switch from NamedTemporaryFile
  to mkstemp with explicit 0600 permissions.
2026-04-04 13:18:53 +02:00
maziggy 4d09b3f669 Add HTTP security headers middleware
Set X-Content-Type-Options, X-Frame-Options, and Referrer-Policy on all
  responses. CSP omitted (React inline styles would require unsafe-inline,
  negating protection). HSTS omitted (LAN app commonly accessed over HTTP).
2026-04-04 13:08:37 +02:00
maziggy 70b12e1949 Fix API key empty printer_ids granting full access
An API key with printer_ids=[] was treated the same as null (global
  access) due to a falsy check. Now None means global access and []
  means no printer access. Added a startup migration to normalize any
  existing [] rows to NULL so they retain their intended global access.

  Also fixed the webhook /queue endpoint which used the same falsy
  check, allowing []-scoped keys to see all printers.
2026-04-04 13:01:54 +02:00