Commit Graph
16 Commits
Author SHA1 Message Date
maziggy dfb995bfe9 [Fix] Remove incorrect "Lubricate Carbon Rods" maintenance task (#755)
Carbon rods use plain bearings — lubricating them degrades print quality.
  Removed the lubrication task from defaults; only "Clean Carbon Rods"
  remains. Existing entries are auto-removed on next startup via
  ensure_default_types(). Updated wiki link mapping and tests.
2026-03-19 08:40:24 +01:00
maziggy d55585a73f Fix P2S showing carbon rod maintenance tasks (#640)
P2S uses hardened steel rods, not carbon fiber. Move P2S from
  carbon rod classification to new steel_rod category with its own
  "Lubricate Steel Rods" / "Clean Steel Rods" maintenance tasks.
2026-03-07 09:45:14 +01:00
maziggy 41dd80b69f Fix naive-vs-aware datetime crash from 0.2.1 timezone migration
The timezone fix (ed36eaf) replaced datetime.utcnow() with
datetime.now(timezone.utc) across ~80 call sites, but SQLAlchemy's
SQLite DateTime columns strip tzinfo on read, returning naive datetimes.
Any Python-side comparison (subtraction, <, >) between an aware "now"
and a naive DB value raises TypeError.

Add `if value.tzinfo is None: value = value.replace(tzinfo=timezone.utc)`
guards at all 9 affected comparison sites:
- maintenance.py: last_performed_at subtraction (2 code paths — days-based
  and hours-based intervals both crashed on /maintenance/overview)
- auth.py: API key expires_at check (2 locations)
- print_scheduler.py: scheduled_time comparison
- smart_plug_manager.py: auto_off_pending_since elapsed calc
- smart_plugs.py: power_alert_last_triggered cooldown
- main.py: last_runtime_update elapsed calc
- archives.py: timelapse completed_at fallback
2026-02-27 17:46:52 +01:00
maziggy fe5bb1fd90 Fix naive-vs-aware datetime crash from 0.2.1 timezone migration
The timezone fix (ed36eaf) replaced datetime.utcnow() with
datetime.now(timezone.utc) across ~80 call sites, but SQLAlchemy's
SQLite DateTime columns strip tzinfo on read, returning naive datetimes.
Any Python-side comparison (subtraction, <, >) between an aware "now"
and a naive DB value raises TypeError.

Add `if value.tzinfo is None: value = value.replace(tzinfo=timezone.utc)`
guards at all 8 affected comparison sites:
- maintenance.py: last_performed_at subtraction (500 on /maintenance/overview)
- auth.py: API key expires_at check (2 locations)
- print_scheduler.py: scheduled_time comparison
- smart_plug_manager.py: auto_off_pending_since elapsed calc
- smart_plugs.py: power_alert_last_triggered cooldown
- main.py: last_runtime_update elapsed calc
- archives.py: timelapse completed_at fallback
2026-02-27 17:39:32 +01:00
maziggy ed36eafbec Fix timestamps off by timezone offset in non-UTC containers (#504)
All backend timestamps used datetime.now() (server local time) or the
deprecated datetime.utcnow(). The frontend's parseUTCDate() assumes
timestamps without timezone indicators are UTC and appends 'Z', so
stored timestamps were off by the timezone offset when the container's
timezone wasn't UTC.

Backend: replaced datetime.now() and datetime.utcnow() with
datetime.now(timezone.utc) across 16 files (~80 call sites) for all
database fields and DB comparisons. Cosmetic timestamps (filenames,
user-facing local time formatting) intentionally left as local time.

Frontend: replaced 13 new Date(backendTimestamp) calls with
parseUTCDate() across 8 files to correctly interpret UTC timestamps.
2026-02-24 08:18:02 +01:00
Matteo Parenti 8b0895f63f Add soft-delete for system maintenance tasks 2026-02-13 15:39:52 +01:00
maziggy cffe7e62bc Fix maintenance tasks showing wrong rod type for printer models (#351)
H2/A1 series have linear rails, not carbon rods. X1/P1/P2S have carbon
rods, not linear rails. Split rod-specific maintenance into model-aware
pairs: "Lubricate/Clean Carbon Rods" for X1/P1/P2S and "Lubricate/Clean
Linear Rails" for A1/H2. Added rod type classification to printer_models
and startup cleanup for stale/duplicate system maintenance types.
2026-02-13 12:23:34 +01:00
maziggy 53bd4fadb3 Fix safe security findings: hashlib, log injection, broad excepts
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
  hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
  55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
  OperationalError for DB migrations, OSError for network/file cleanup,
  (OSError, ftplib.error_reply) for FTP, and targeted tuples for
  ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
  re-raise patterns)
2026-02-06 11:37:59 +01:00
maziggy 3fa9ed2b91 Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.

Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
  archives, projects, settings, api_keys, groups, cloud, github_backup,
  support, notifications, notification_templates, maintenance, filaments,
  external_links, smart_plugs, discovery, firmware, kprofiles, camera,
  ams_history, pending_uploads, updates, spoolman, system, print_queue,
  printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
  streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)

Fixes: CVE-2026-25505
2026-02-03 08:44:07 +01:00
maziggy 368999a234 Add MQTT publishing for external automation integration
New feature: Publish BamBuddy events to external MQTT brokers for integration
with Home Assistant, Node-RED, and other automation platforms.

Backend changes:
  - New MQTTRelayService (backend/app/services/mqtt_relay.py) with paho-mqtt
  - MQTT settings added to AppSettings schema (enabled, broker, port, auth, TLS)
  - New /settings/mqtt/status endpoint for connection status
  - Event hooks in main.py, print_queue.py, print_scheduler.py, maintenance.py, smart_plugs.py
  - PrinterInfo class and get_printer() method added to PrinterManager
  - MQTT reconfiguration added to backup/restore flow
  - Printer status throttled to 1 update/sec to avoid flooding

Frontend changes:
  - New "Network" tab in Settings (between Filament and API Keys)
  - FTP Retry settings moved from General to Network tab
  - MQTT configuration card with broker, port, TLS toggle, auth fields
  - Port auto-populates when TLS toggled (1883 ↔ 8883)
  - Connection status indicator (green/red dot) in tab and card header
  - Real-time status polling when on Network tab

Published topics:
  - bambuddy/status - Online/offline
  - bambuddy/printers/{serial}/status - Printer state (throttled)
  - bambuddy/printers/{serial}/print/* - Print lifecycle
  - bambuddy/printers/{serial}/ams/changed - AMS changes
  - bambuddy/queue/* - Queue events
  - bambuddy/maintenance/* - Maintenance alerts
  - bambuddy/smart_plugs/* - Plug state/energy
  - bambuddy/archive/* - Archive events

Tests:
  - Added MQTT settings and status endpoint tests

Closes #78
2026-01-13 12:31:45 +01:00
maziggy 4f2a45c190 Add maintenance documentation links with model-specific wiki URLs (#59)
Features:
  - Add wiki_url field to MaintenanceType for custom type documentation links
  - Add printer_model to MaintenanceStatus for model-specific URL mapping
  - Display external link icon next to maintenance item names
  - Map system maintenance types to Bambu Lab wiki pages by printer model:
    - Lubricate Linear Rails, Clean Nozzle/Hotend, Check Belt Tension
    - Clean Carbon Rods (X1/P1 only), Clean Build Plate, Check PTFE Tube
    - HEPA/Carbon Filter, Left Nozzle Rail (H2 series)
  - Add Documentation Link input to custom type create/edit forms

  Bug fix:
  - Fix 500 error when assigning maintenance type to printer (lazy loading)

  Database:
  - Add migration for wiki_url column on maintenance_types table
2026-01-07 07:53:42 +01:00
maziggy 219d26b8ab - Fixed bug in printer's hour counter 2025-12-31 12:01:17 +01:00
maziggy 929c4c8cd6 - Fix total print hours calculation in set_total_hours to include all
prints (not just completed), matching get_printer_total_hours behavior
  - Add option to keep or delete archives when deleting a printer
  - Custom maintenance types no longer auto-assign to all printers
  - Add UI to manually assign/remove custom maintenance types per printer
  - Add backend endpoints for assigning types to printers and removing items
  - Exclude static/assets from large file pre-commit check
2025-12-23 09:00:36 +01:00
maziggy 3ffe032635 - Fix total print hours to include all prints 2025-12-21 09:56:34 +01:00
maziggy 1a17b547dc - Added maintenance interval type clendar days
- Minor improvements to maintenance module
2025-12-08 14:52:16 +00:00
Martin Ziegler f126b0a075 Added auto app update; Added maintenance module with notifications 2025-12-01 08:39:07 +01:00