Commit Graph
7 Commits
Author SHA1 Message Date
maziggy 53bd4fadb3 Fix safe security findings: hashlib, log injection, broad excepts
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
  hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
  55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
  OperationalError for DB migrations, OSError for network/file cleanup,
  (OSError, ftplib.error_reply) for FTP, and targeted tuples for
  ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
  re-raise patterns)
2026-02-06 11:37:59 +01:00
maziggyandClaude Opus 4.6 91662d9c5d Add usedforsecurity=False to non-security hashlib calls
MD5 in bambu_mqtt.py is used for AMS tray change detection fingerprinting,
and SHA1 in github_backup.py matches Git's blob hash format. Neither is
used for security purposes, so mark them explicitly to satisfy Bandit B303
and CodeQL py/weak-cryptographic-algorithm findings.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-06 11:15:26 +01:00
maziggy 819ab896bd Fix Python 3.10 compatibility (Issue #269)
Replace datetime.UTC with timezone.utc for Python 3.10 support.
datetime.UTC was added in Python 3.11, but requirements state 3.10+.

Closes #269
2026-02-05 07:46:22 +01:00
maziggy d713577863 Fixed CodeQL errors 2026-01-31 16:35:10 +01:00
maziggy 18fbd9c156 Remove timestamps from GitHub backup files for cleaner diffs
- Remove created_at from backup_metadata.json
- Remove exported_at from K-profile files
 - Remove exported_at from cloud profile files (filament, printer, process)
- Remove exported_at from app settings backup
- Git already tracks file modification history, so these were redundant
- Backups now only show changes in git diff when actual data changes
2026-01-29 08:27:20 +01:00
maziggy 14e8e512f2 Fix timezone comparison in GitHub backup scheduler
The scheduler compared timezone-aware datetime.now(UTC) with naive
datetimes from the SQLite database, causing "can't compare offset-naive
and offset-aware datetimes" error.

Fixed by adding UTC timezone to naive datetimes before comparison.
2026-01-27 15:21:32 +01:00
maziggy 4ea7f7c4aa Add GitHub profile backup feature
New feature to automatically backup K-profiles, cloud profiles, and app
settings to a GitHub repository with scheduled or on-demand execution.

Features:
- Configure GitHub repo URL and Personal Access Token
- Schedule backups hourly, daily, or weekly (background scheduler)
- Manual backup trigger with real-time progress tracking
- Skip unchanged commits (only creates commit when data changes)
- Backup history log with status and commit links
- Requires Bambu Cloud login for full profile access
- New Settings → Backup & Restore tab consolidating all backup options
- GitHub backup config included in local backup/restore (except PAT)

Backend:
- New models: GitHubBackupConfig, GitHubBackupLog
- New service: GitHubBackupService with scheduler and GitHub API client
- New routes: /github-backup/* for config, status, logs, and triggers
- Updated settings.py to include github_backup in backup/restore

Frontend:
- New GitHubBackupSettings.tsx component with auto-save
- Updated SettingsPage with Backup tab and status indicator
- Added API types and methods to client.ts

Tests:
- Backend integration tests for all GitHub backup API endpoints
- Frontend API type and endpoint tests
2026-01-27 15:01:06 +01:00