Commit Graph
6 Commits
Author SHA1 Message Date
maziggy b5ccc38e4a feat(support): include all settings (redacted) + SpoolBuddy devices in support bundle
Settings dump now retains every key from the Settings table and replaces
  sensitive values with [REDACTED] instead of dropping the row. New config
  flags automatically surface in future bundles without a code change.

  Adds integrations.spoolbuddy with per-device firmware, NFC/scale hardware,
  calibration, online state and uptime — anonymized (no hostnames, IPs or
  device IDs). Both /support/bundle and the bug-report bubble benefit, since
  they share _collect_support_info().
2026-04-14 12:22:07 +02:00
maziggy b71b721658 fix(security): stop leaking webhook tokens via httpx debug logging
Settings → Support → Debug Logging elevated httpx/httpcore to DEBUG,
  which makes httpx log every outbound request URL. For Discord and
  generic webhook notifications the bearer token is embedded in the URL
  path, so users who turned on debug logging to capture a support bundle
  were writing their webhook tokens straight into bambuddy.log.

  Pin httpx/httpcore to WARNING regardless of the debug toggle. paho.mqtt
  still honours debug. Users who enabled debug logging while notifications
  were sending must rotate any exposed Discord/webhook URLs — the token
  is the path, so the whole URL has to be regenerated in the provider UI.
2026-04-14 09:13:55 +02:00
maziggy 8843af6665 Fix support package: mask subnet IPs, detect host mode, parse top-level fun, add virtual printers
Four support package improvements:

  1. Mask first two octets of subnet IPs in support info
     (192.168.1.0/24 → x.x.1.0/24) to avoid leaking private network
     addresses.

  2. Fix Docker network_mode_hint detection. The old heuristic
     (interface count > 2) always reported "bridge" on single-NIC
     hosts because get_network_interfaces() excludes Docker
     interfaces. Now checks for docker0/br-*/veth* visibility via
     socket.if_nameindex() — these are only visible in host mode.

  3. Parse MQTT "fun" field at top level of payload (not just inside
     "print" key). Some firmware versions send it there, which
     explains why developer_mode was null for most users.

  4. Add virtual_printers section to support info with mode, model,
     enabled/running status, and pending file count.
2026-03-01 08:39:30 +01:00
maziggy 8e6a959eef Redact IP addresses from support bundle debug logs 2026-02-23 09:24:53 +01:00
maziggy caedfffa5b fix: add logging and harden archive matching for phantom print investigation (#374)
Suppress SQL/aiosqlite debug noise (~90% log volume reduction), add
caller-traced PRINT COMMAND logging to start_print(), log scheduler
queue checks, tighten stale archive ilike match to exact match, and
warn on multiple queue items in "printing" status. Includes 18 new
unit tests.
2026-02-15 11:35:24 +01:00
maziggy 8449e1c2e2 Extend support bundle with comprehensive diagnostics
Add 10 new diagnostic sections to _collect_support_info(): printer
connectivity/firmware, integration status (Spoolman, MQTT, HA),
network interfaces (subnets only), Python package versions, database
health, Docker environment, WebSocket connections, and log file info.
All data properly anonymized — no IPs, names, or serials included.
2026-02-09 10:19:48 +01:00