The frame an external link opens in can't navigate the Bambuddy
window, so links like Bambuddy Orders' "In Bambuddy" did nothing.
The framed page can now post bambuddy:navigate with a path; it is
accepted only from the frame, from the link's origin, and for a path
inside Bambuddy. The theme message announces canNavigate.
OrcaSlicer's Sync filaments finds a slot's preset by the slot's filament
ID alone. The Configure dialog looked up an Orca profile's ID in the
browser and quietly sent the generic for the material when that came back
empty, so Orca custom filaments reached the slicer as Generic and the log
showed nothing. configure now resolves the ID on the server from
orca_profile_id, follows inherits to the parent profile or the Bambu
filament it was copied from, logs the outcome and reports a fallback,
which the dialog shows as a warning.
Slot presets also store the filament ID they were written with, so the
slot card and the Configure dialog stop showing a preset once the slot is
changed from OrcaSlicer's Device tab or the printer.
Re-configuring a slot for another filament no longer carries over the old
filament's active K-profile, which switched the slot back to the old
filament.
The File Manager and G-code viewer were sized to 100vh-64px on lg+,
subtracting a top bar that only exists in the compact layout, which
left a 64px empty band under both pages. Use lg:h-screen instead.
- Expired messages stay readable under a collapsed "Earlier" section, as
long as the feed keeps them (12 months, at most 50). They never count as
unread or raise a banner; withdrawn ones are gone everywhere.
- Each message is one row (level, date, title) that opens in place.
Unread ones carry a dot and a New chip, and opening one is what marks
it read; the banner's Read more opens the panel on its message.
- A fetch that brings a newer feed broadcasts an empty
announcements_changed event, so open pages show the new dot and banner
without a reload.
- The sidebar entry is a megaphone icon with an unread badge, in the
footer row left of System. Footer icons are 32px with no gap so seven
fit an expanded sidebar; with authentication on, logout used to wrap
onto a line of its own.
Fetch a signed feed.json from the public bambuddy-notifications repo on
GitHub at startup and every 6 hours. Nothing about the install is sent;
targeting (version, beta channel, install type) is decided locally.
- Ed25519 against a key built into the app; an older serial is refused so a
withdrawn message can't come back. The feed replaces the stored list, and
a failed or rejected fetch keeps the last good one.
- Sidebar entry above System with an unread count, a slide-over list, and a
banner for unread important/critical messages. Read state per user.
- Admins by default; Settings > General > Updates can show them to all
users or switch them off, which also stops the fetch.
- Plain text only; links to github.com and bambuddy.cool only.
Raise the brace-expansion override from ^5.0.9 to ^5.0.12. Earlier
versions can run out of stack on deeply nested brace groups and take
quadratic time on the {a},b} rewrite. brace-expansion is a dev-only
transitive dependency of eslint (through minimatch) and only expands
the fixed globs in eslint.config.js.
Raise the js-yaml override from ^5.2.3 to ^5.4.1. Versions up to 5.4.0
do not count empty mappings towards maxTotalMergeKeys, so a small YAML
file can keep the CPU busy for a long time. js-yaml is a dev-only
transitive dependency of eslint and only parses our own ESLint configs.
C11 is the P1P, C12 the P1S, C13 the X1E and N7 the P2S, as the virtual
printer and a real P1P 3MF already say. The frontend map had them shifted,
so discovery pre-filled a P1S as a P1P and an X1E as a P2S. The backend
map read C11/C12 as X1C/X1 and lacked N7, the firmware check sent C13 to
the P2S line, and the capability lists never matched BL-P001 because
their lookup strips the dash.
-----
Post work PR #3134
POST /notifications/app-message delivers an app's message to every channel
with the new "Messages from connected apps" switch on (off by default),
through quiet hours, the digest and the log. API keys need the new "Send
notifications" permission, and their owner notifications:update; plain text,
http(s) links, 20 messages a minute per key. The electricity-price door and
this one now share one scoped-key check. /queue?batch=<id> opens and
highlights one batch order.
fix(#1898): keep Telegram link previews, and keep the outcome prompt's failures its own
Four follow-ups to the post-print outcome confirmation merged in #3047.
Telegram: link previews were switched off for every message rather than
only for the outcome prompt, so a print_complete template carrying
{finish_photo_url} lost its photo preview whenever the photo was too
large to attach. _send_telegram now takes link_preview, and only the
prompt turns it off, as the Slack unfurl change already did.
Archives: Reset left the new Unconfirmed filter on, so the list stayed
narrowed and the button seemed to do nothing.
Print start: when the external-print check hit a failed statement, it
rolled back the caller's whole transaction, which expired the printer
and the just-created archive; on an async session the next read of
either raises, and the start notification, energy reading and timelapse
baseline were skipped. The check's reads now run in a savepoint, and a
failed flag write reloads the archive and printer after its rollback.
Print complete: a failed outcome prompt left the notification session
needing a rollback, so the per-user print email sent on it next failed
too. The dispatch now rolls back on failure.
Minimal OAuth 2.0 authorization-code flow with PKCE (S256): admins register
an app with one exact callback URL (Settings > API Keys > Connected Apps);
/connect/authorize asks for consent once and returns a single-use, 60 s code
bound to app, callback and challenge; POST /api/v1/connect/token swaps it,
with the client secret, for the user's identity and permissions. Codes and
secrets stored hashed, exchanges rate-limited per client and IP, no redirect
before the callback is validated, API keys cannot authorize, refused while
auth is disabled. i18n for all 15 locales.
-----
fix(db): upgrading from 0.2.4.0 or older no longer crashes at startup
The #2974 failure-reason conversion ran before the #1378 migration that adds
print_log_entries.failure_reason, so older databases stopped with "no such
column: failure_reason". It now skips a table without the column, only runs
where a legacy label exists, and on SQLite rebuilds archive_fts first, since
archives created before that index existed trip "database disk image is
malformed" when updated.
POST /queue/batches accepts external_source + external_ref; both are
returned on every batch and filterable on GET /queue/batches. The pair is
unique (index uq_print_batches_external), so a retried create answers 409
instead of queueing the same order twice. Migration covers SQLite and
PostgreSQL.