maziggy
5b0a985da2
Add explanatory comments to 265 empty except blocks
...
CodeQL flags except blocks where `pass` has no comment explaining
why the exception is silently ignored (py/empty-except rule).
Added context-specific comments to all 265 instances across 31 files:
- database.py (~112): ALTER TABLE migrations — "Already applied"
- archive/library/3MF parsing (~64): "Skip unparseable metadata"
- virtual_printer network cleanup (~32): "Best-effort socket cleanup"
- discovery/SSDP (~13): "SO_REUSEPORT not available" / socket cleanup
- bambu_ftp/mqtt (~13): FTP cleanup, JSON decode, signal parsing
- remaining routes/services (~31): context-specific comments
2026-02-06 11:58:38 +01:00
maziggy
53bd4fadb3
Fix safe security findings: hashlib, log injection, broad excepts
...
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
OperationalError for DB migrations, OSError for network/file cleanup,
(OSError, ftplib.error_reply) for FTP, and targeted tuples for
ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
re-raise patterns)
2026-02-06 11:37:59 +01:00
maziggy
3fa9ed2b91
Add authentication to 200+ API endpoints (CVE-2026-25505)
...
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.
Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
archives, projects, settings, api_keys, groups, cloud, github_backup,
support, notifications, notification_templates, maintenance, filaments,
external_links, smart_plugs, discovery, firmware, kprofiles, camera,
ams_history, pending_uploads, updates, spoolman, system, print_queue,
printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)
Fixes: CVE-2026-25505
2026-02-03 08:44:07 +01:00