Commit Graph
28 Commits
Author SHA1 Message Date
maziggy 89bf138473 Bump flatted 3.4.1 → 3.4.2 to fix prototype pollution
Fixes GHSA-rf6f-7fwh-wjgh (CWE-1321). Dev-only dependency via
  eslint → file-entry-cache → flat-cache → flatted.
2026-03-22 13:26:24 +01:00
maziggy fa6edfbcde Fix stored XSS vulnerabilities and unauthenticated auth toggle
- Sanitize project notes with DOMPurify before rendering via
    dangerouslySetInnerHTML (ProjectDetailPage.tsx)
  - Replace hand-rolled HTML sanitizer with DOMPurify in ProjectPageModal
    to prevent attribute injection via crafted 3MF href values
  - Block /api/v1/auth/setup when auth is already enabled to prevent
    unauthenticated clients from disabling authentication remotely
2026-03-15 15:31:49 +01:00
maziggy 5a8aa61f44 Bump PyJWT >=2.12.0 (CVE-2026-32597) and flatted >=3.4.0
PyJWT: fixes auth token handling vulnerability (direct dependency).
  flatted: fixes unbounded recursion DoS in parse() (transitive, ESLint only).
2026-03-14 15:47:25 +01:00
maziggy bffbac54e4 Add on-screen virtual keyboard for SpoolBuddy kiosk UI
The Raspberry Pi kiosk has no physical keyboard and system-level virtual
  keyboards (squeekboard, wvkbd) don't auto-show/hide with labwc/Chromium.
  Add a react-simple-keyboard QWERTY keyboard that auto-shows on input
  focus, with dark theme, shift/caps/backspace, email keys (@, .), and a
  two-phase close that prevents ghost-click passthrough to elements below.
  Inputs with data-vkb="false" opt out (e.g. SpoolBuddySettingsPage numpad).
2026-03-02 10:20:22 +01:00
maziggy 55c332d91a Housekeeping 2026-02-27 10:05:03 +01:00
maziggy efcb6cd74a build(deps-dev): bump ajv from 6.12.6 to 6.14.0 in /frontend in the npm_and_yarn group across 1 directory 2026-02-23 09:31:53 +01:00
maziggy 9e317bd775 Fix npm audit high-severity minimatch ReDoS (GHSA-3ppc-4f35-3m26)
by adding an npm override for minimatch@^10.2.1 in package.json.
2026-02-19 08:23:53 +01:00
maziggy bedcd0a73e 1. ajv is only used by eslint to validate config schemas during linting
2. It's a dev dependency, never reaches production
  3. The ReDoS requires crafted $data schema input — not an attack vector in a linting config
2026-02-18 09:30:29 +01:00
dependabot[bot] 2bbe7b9da2 Bump markdown-it
Bumps the npm_and_yarn group with 1 update in the /frontend directory: [markdown-it](https://github.com/markdown-it/markdown-it).


Updates `markdown-it` from 14.1.0 to 14.1.1
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](https://github.com/markdown-it/markdown-it/compare/14.1.0...14.1.1)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.1.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-13 20:52:04 +00:00
maziggy fe2f001143 package-lock-only 2026-02-10 17:24:14 +01:00
copilot-swe-agent[bot]andcadtoolbox 5fd0c43275 Add initialData to advancedAuthStatus query to prevent undefined state
Co-authored-by: cadtoolbox <12723486+cadtoolbox@users.noreply.github.com>
2026-02-09 08:57:15 +00:00
Thomas Rambach c01b5ca864 62942808254 2026-02-09 03:32:20 -05:00
copilot-swe-agent[bot]andcadtoolbox e4ca5256de Fix admin settings menu vertical scroll and user creation dialog for advanced auth
Co-authored-by: cadtoolbox <12723486+cadtoolbox@users.noreply.github.com>
2026-02-09 08:22:34 +00:00
Thomas Rambach d87aca45b8 Update package-lock.json 2026-02-08 18:37:06 -05:00
copilot-swe-agent[bot]andcadtoolbox 3231a487c9 Update email settings to match notification provider fields and rename tab to Global Email
Co-authored-by: cadtoolbox <12723486+cadtoolbox@users.noreply.github.com>
2026-02-08 23:03:28 +00:00
maziggy 8be9bc757c @renovate baseline-browser-mapping@latest 2026-01-31 15:20:47 +01:00
maziggy e74d5be4b8 @renovate
- vitest: ^2.1.0 → ^3.2.4
- @vitest/coverage-v8: upgraded to match
2026-01-29 08:17:53 +01:00
maziggy ead2bfc822 @renovate baseline-browser-mapping@latest 2026-01-28 07:18:19 +01:00
MartinNYHC a9f340f2c9 Revert "Added optional authentication and user management" 2026-01-21 15:58:24 +01:00
JesseFPV 3e1843f834 Updated checks 2026-01-21 14:41:24 +01:00
JesseFPV f8857ba666 Added optional authentication and user management 2026-01-21 14:10:06 +01:00
dependabot[bot] eb125ed378 Bump react-router and react-router-dom in /frontend
Bumps [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) to 7.12.0 and updates ancestor dependency [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom). These dependencies need to be updated together.


Updates `react-router` from 7.9.6 to 7.12.0
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router@7.12.0/packages/react-router)

Updates `react-router-dom` from 7.9.6 to 7.12.0
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.12.0/packages/react-router-dom)

---
updated-dependencies:
- dependency-name: react-router
  dependency-version: 7.12.0
  dependency-type: indirect
- dependency-name: react-router-dom
  dependency-version: 7.12.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-18 19:53:13 +00:00
maziggy c9ad09864d Minor GCode viewer improvements 2026-01-03 09:59:17 +01:00
maziggy ff53e62ef8 Add comprehensive automated testing infrastructure
Backend:
  - pytest configuration with async support and coverage
  - Unit tests for notification service (23 tests)
  - Unit tests for smart plug manager (12 tests)
  - Unit tests for archive service (16 tests)
  - Integration tests for API endpoints
  - Fix: notifications now send immediately (digest is summary only)

  Frontend:
  - Vitest configuration with jsdom and coverage
  - MSW for API mocking
  - Component tests for Toggle, Button, Card, ConfirmModal (77 tests)
  - Test utilities with custom render wrapper

  CI/CD:
  - GitHub Actions workflow for automated testing
  - Backend lint, unit tests, integration tests
  - Frontend lint, type-check, unit tests, build
2025-12-11 10:03:40 +01:00
maziggy 06bfaa3c74 Completely removed control page and all it's related code 2025-12-07 10:19:25 +00:00
Martin Ziegler f126b0a075 Added auto app update; Added maintenance module with notifications 2025-12-01 08:39:07 +01:00
Martin Ziegler 53c94deade Added project page viewer and editor 2025-11-28 12:41:28 +01:00
Martin Ziegler 09677861ba Added screenshots 2025-11-28 10:23:59 +01:00