The makerworld /status, /resolve, and /import handlers passed
current_user directly into get_stored_token / _build_service.
require_permission_if_auth_enabled returns None for API-keyed
callers by design (core/auth.py:1414), so the lookup always
missed even when the key's owner had a stored Bambu Cloud session.
Result: a "requires a Bambu Cloud login" 400 on every API-keyed
import, regardless of the owning account's actual cloud state.
Wire resolve_api_key_cloud_owner (already used by the slice path
in #1182 — slicer_presets.py:491 and library.py:3871) into the
three makerworld routes that read the cloud token. The handler
falls back to the API-key owner via cloud_token_user =
current_user or api_key_cloud_owner, then passes that through.
import_instance also propagates the resolved user to the
owner_id arg on save_3mf_bytes_to_library, so the resulting
LibraryFile.created_by_id reflects the key's owner instead of
NULL.
Fail-closed semantics preserved: resolve_api_key_cloud_owner
already fences on api_key.can_access_cloud, so keys with only
the per-route scope (can_read_status / can_manage_library) still
take the existing "requires Bambu Cloud login" path — no auth
widening.
/recent-imports is unchanged — it only uses current_user as a
permission gate (_ = current_user) and never touches the cloud
token.