Commit Graph
867 Commits
Author SHA1 Message Date
maziggy 9ceefc19bc Changed version 2026-02-05 18:26:20 +01:00
maziggy 4d94286e53 Fix CodeQL path injection vulnerabilities
- projects.py: Add path traversal validation to attachment endpoints
  - Reject filenames containing /, \, or ..
  - Prevents directory traversal attacks via URL parameters

- archives.py: Strengthen timelapse processing input validation
  - Validate audio suffix against whitelist (not just filename check)
  - Reject output filenames with .., empty, or dot-prefixed names
  - Fall back to safe default filename if validation fails
2026-02-05 18:09:42 +01:00
maziggy 46ba5ff417 Fix Bandit detection and update Trivy to v0.69.1
- Fix defusedxml import style in print_queue.py to be recognized by Bandit
  (use `import defusedxml.ElementTree as ET` not `from defusedxml import`)
- Update Trivy scanner version from 0.65.0 to 0.69.1
2026-02-05 17:50:16 +01:00
MartinNYHC bada186101 Merge pull request #274 from MisterBeardy/fix/print-queue-time
Fix/print-queue-time
2026-02-05 17:46:56 +01:00
Wesley Reaves f14b46b2e0 Merge branch '0.1.8b' into fix/print-queue-time 2026-02-05 11:34:21 -05:00
maziggy fc4f565eba Update Trivy scanner to v0.69.1
Pin the latest Trivy scanner version for improved vulnerability detection.
2026-02-05 17:33:51 +01:00
Wesley Reaves 0a0a0aea2f Merge branch '0.1.8b' into fix/print-queue-time 2026-02-05 11:32:04 -05:00
maziggy 4b3b615a2c Fix Bandit B314: Replace xml.etree with defusedxml
Security scan (Bandit) identified vulnerable XML parsing in 3MF file
processing. The standard xml.etree.ElementTree is vulnerable to XXE
(XML External Entity) attacks.

Changes:
- Add defusedxml>=0.7.0 to requirements.txt
- Replace all xml.etree.ElementTree imports with defusedxml.ElementTree
  in production code (6 files)

Affected files:
- backend/app/services/archive.py
- backend/app/services/print_scheduler.py
- backend/app/api/routes/print_queue.py
- backend/app/api/routes/library.py
- backend/app/api/routes/printers.py
- backend/app/api/routes/archives.py

Test files intentionally left unchanged (test XML is trusted).
2026-02-05 17:30:14 +01:00
MisterBeardy 215e750d04 Fix queue print time for plate selection 2026-02-05 11:27:41 -05:00
MartinNYHC cbb3b8c097 Merge branch '0.1.8b' into fix/print-queue-time 2026-02-05 17:07:38 +01:00
maziggy 5da769be31 Fix A1 FTP uploads by replacing storbinary with manual transfer
The A1 printer's FTP server hangs when Python's storbinary() calls
voidresp() to wait for the server's completion response. This caused
upload timeouts on A1 and A1 Mini printers.

Fix contributed by an A1 user - replaces storbinary() with manual
chunked transfer using transfercmd() + sendall():
- Uses 1MB chunks (CHUNK_SIZE constant) for better throughput
- Sets explicit 120s socket timeout on data connection
- Manually closes connection after transfer, avoiding voidresp() hang

Applied to all printer models since the manual approach is compatible
with X1C/P1S/P1P as well (transfercmd is what storbinary uses internally).
2026-02-05 17:06:15 +01:00
MisterBeardy 671685a4e2 Add print time extraction from 3MF files to print queue response 2026-02-05 11:02:03 -05:00
maziggy 8b3ea0602c Moved start_bambuddy.bat to install/ 2026-02-05 14:54:07 +01:00
maziggy 7841237d4e Fixed Trivy workflow 2026-02-05 14:05:29 +01:00
maziggy 0279961889 FTP auto-detection: try prot_p first, fall back to prot_c for A1
User feedback indicated A1 Mini with current firmware works with prot_p
(protected/SSL data channel), not prot_c as previously assumed. Different
A1 firmware versions have different FTP SSL behavior.

Changes:
- Remove hardcoded assumption that A1 models need prot_c
- Try prot_p first for all models (including A1/A1 Mini)
- If upload/download fails on A1 models, automatically retry with prot_c
- Cache working mode per printer IP for subsequent operations
- Add force_prot_c parameter for explicit mode control

This makes FTP work across A1 firmware versions:
- New firmware: prot_p succeeds, cached
- Old firmware: prot_p fails → prot_c fallback succeeds, cached
2026-02-05 13:50:45 +01:00
maziggy 45e08b023a Updated CI 2026-02-05 12:34:06 +01:00
maziggy f9431ced0c Updated CI 2026-02-05 12:24:52 +01:00
maziggy c01839b2ce Added Bandit and Trivy to CI 2026-02-05 12:18:00 +01:00
maziggy ff55e63caa Docker permissions fix:
- Add user directive to docker-compose.yml using PUID/PGID env vars
- Allows container to run as host user, fixing permission issues with
  bind-mounted volumes (e.g., ./virtual_printer)
- Add chmod 777 to /app/data and /app/logs in Dockerfile for non-root compatibility
- Usage: PUID=$(id -u) PGID=$(id -g) docker compose up -d

Note: Existing named volumes (bambuddy_logs, bambuddy_data) created by previous
root containers may need to be removed or have permissions fixed manually.
2026-02-05 11:33:05 +01:00
maziggy 2cac34795e Fix Safari camera stream failing with Service Worker error
Camera streams on macOS Safari were failing with "FetchEvent.respondWith
received an error: Load failed" because the Service Worker was intercepting
MJPEG streaming responses. Safari has known issues handling continuous
streaming responses through Service Workers.

- Add exclusion for /camera/stream and /camera/snapshot URLs in SW fetch handler
- Bump cache version to v24 to force SW update on clients

The camera components already have robust error handling with reconnect logic,
so bypassing the SW for these endpoints is safe and improves performance.
2026-02-05 11:05:46 +01:00
maziggy 964be0eb26 Improved Docker tests 2026-02-05 10:28:06 +01:00
maziggy 62804d764f Housekeeping 2026-02-05 09:17:39 +01:00
maziggy 861cc006d4 Changed issue templates 2026-02-05 09:05:25 +01:00
maziggy d950b48023 Only show plate detection popup to users with control permission
The plate detection alert popup (shown when objects are detected on
build plate and print is paused) was visible to all users. Now it
only shows to users who have the printers:control permission.

- Added hasPermission('printers:control') check before showing alert
- When auth disabled: all users see it (backward compatible)
- When auth enabled: only users with printers:control permission see it

Addresses #244
2026-02-05 08:21:55 +01:00
maziggy 379ba726e1 Fix A1/A1 Mini FTP upload EOFError (#271)
The FTP code called prot_p() (protected data channel) for all printers,
but for A1/A1 Mini it didn't wrap the data connection in SSL. This
mismatch caused an immediate EOFError - server expected encrypted data
but received plain data.

Fix:
- Use prot_c() (clear/unencrypted data channel) for A1/A1 Mini
- Use prot_p() (protected/encrypted data channel) for X1C/P1S/etc
- Removed non-functional ftplib._SSLSocket = None workaround

A1/A1 Mini: control channel encrypted (implicit TLS), data channel clear
X1C/P1S/etc: both channels encrypted with SSL session reuse

Closes #271
2026-02-05 08:13:13 +01:00
maziggy 00caf3ee1a Fix date format parsing for queue scheduling (#233)
Date input for scheduled prints was swapping month and day for European
users because:
1. EU format only accepted "/" separator, not "." which is common in
   European locales (e.g., "5.2.2026" for Feb 5th)
2. System format fell back to new Date() which interprets ambiguous
   dates in US format

Changes:
- Added splitDateParts() helper to accept /, ., and - separators
- Updated parseDateInput() to use proper locale detection for system
  format instead of relying on Date constructor
- All explicit formats (us, eu, iso) now accept any of the three
  separators

Closes #233
2026-02-05 08:00:34 +01:00
maziggy f8ca38cd5b Fix API keys failing when authentication is enabled (#270)
When auth was enabled, API keys were not accepted by the permission
checking functions. Only JWT tokens were validated.

API keys are accepted via two methods:
- X-API-Key header with the key value
- Authorization: Bearer header (keys starting with "bb_" are treated
  as API keys, others as JWT tokens)

Closes #270
2026-02-05 07:52:39 +01:00
maziggy 819ab896bd Fix Python 3.10 compatibility (Issue #269)
Replace datetime.UTC with timezone.utc for Python 3.10 support.
datetime.UTC was added in Python 3.11, but requirements state 3.10+.

Closes #269
2026-02-05 07:46:22 +01:00
maziggy 87cf0e83e9 Fix H2D print commands and HMS notification issues
Issue #245: H2D Pro print errors (extrusion motor overloaded)
- H2D series requires integer format (0/1) for boolean fields
- Other printers (X1C, P1S, A1) require actual booleans (true/false)
- Added model detection to use correct format per printer type
- Affected fields: timelapse, bed_leveling, flow_cali, vibration_cali,
  layer_inspect, use_ams

Closes #245
2026-02-05 07:26:30 +01:00
maziggy 6890c16efd Fix HMS notification display and filtering for H2D
- Mask HMS error codes to 16 bits to fix malformed display
  (H2D sends code 0x2001B which displayed as "0C00_2001B" instead of "0C00_001B")
- Filter notifications to severity >= 2, skipping informational messages
  (H2D sends severity 1 camera status that isn't a real error)
2026-02-05 07:10:18 +01:00
maziggy 33d002e1af Fix P1S/P1P FTP upload failures
Removed P1S and P1P from SKIP_SESSION_REUSE_MODELS
- These printers use vsFTPd which requires SSL session reuse on data channel
- Only A1/A1 Mini should skip session reuse (they have issues with SSL on data channel)
- P1S/P1P were incorrectly added in commit 9969005, causing EOFError on FTP upload

Closes #266
2026-02-04 17:05:39 +01:00
maziggy a92db92a0c Issue #265 Summary:
- Problem: Skip objects icon (z-10) overlays the 3-dot menu dropdown (z-10)
  - Fix: Increased menu dropdown z-index from z-10 to z-20
  - File: frontend/src/pages/PrintersPage.tsx:1606

Closes #265
2026-02-04 17:00:26 +01:00
MartinNYHC b7520cdf66 Merge pull request #253 from sbcrumb/feature/pushover-image-attachments
Add camera image attachments to Pushover notifications
2026-02-04 16:27:20 +01:00
MartinNYHC 925cc13669 Merge branch '0.1.8b' into feature/pushover-image-attachments 2026-02-04 16:18:13 +01:00
maziggy 39f90616f3 Post work #2 PR #262 2026-02-04 16:12:57 +01:00
MartinNYHC a91a9eacbf Delete .github/workflows/codeql.yml 2026-02-04 16:07:37 +01:00
maziggy 6a35e945ce Post work PR #262 2026-02-04 15:54:34 +01:00
MartinNYHC 6420e9d7ad Merge pull request #262 from MisterBeardy/feature/updated_plate_view_v2
Feature/updated_plate_view_v2
2026-02-04 15:27:28 +01:00
MartinNYHC 2833270e29 Merge branch '0.1.8b' into feature/updated_plate_view_v2 2026-02-04 15:27:02 +01:00
SBCrumb 6aa7a560d8 Add camera image attachments to Pushover notifications 2026-02-04 09:21:59 -05:00
MisterBeardy 008fc702fa fixed lint error 2026-02-04 09:15:00 -05:00
maziggy 6577295cc2 Cleanup for PR #258 2026-02-04 14:58:38 +01:00
MartinNYHC 2526728223 Merge pull request #258 from cadtoolbox/cadtoolbox/248
Cadtoolbox - Issue# 248 Files Manager Print/Schedule Consistency with Archives
2026-02-04 14:53:15 +01:00
MartinNYHC cf286407fb Merge branch '0.1.8b' into cadtoolbox/248 2026-02-04 14:53:05 +01:00
maziggy bff7da2861 Updated all CodeQL actions to v4 2026-02-04 14:48:15 +01:00
maziggy 8bdd64e54d Fixed ruff errors 2026-02-04 14:47:15 +01:00
maziggy ab63fed637 Updated CI 2026-02-04 14:43:36 +01:00
MartinNYHC d0d520b64d Merge pull request #260 from karaktaka/fix/virtual_printer_proxy_error
Fix/virtual printer proxy error
2026-02-04 14:39:15 +01:00
MartinNYHC 31a8016c80 Merge branch '0.1.8b' into fix/virtual_printer_proxy_error 2026-02-04 14:38:53 +01:00
Dennis bf75cd2527 Remove unused import statement for sqlalchemy in main.py 2026-02-04 14:36:32 +01:00