Commit Graph
748 Commits
Author SHA1 Message Date
Dennis bf75cd2527 Remove unused import statement for sqlalchemy in main.py 2026-02-04 14:36:32 +01:00
Dennis 84f1347bd0 Reorder import statement for jwt in main.py 2026-02-04 14:36:32 +01:00
MartinNYHC 2289dd6ca3 Add CI and Code Scanning badges to README 2026-02-03 17:26:42 +01:00
MartinNYHC 6e069cebf2 Merge pull request #243 from maziggy/0.1.7
Fixed backup permissions
v0.1.7
2026-02-03 14:07:30 +01:00
MartinNYHC 914c3a5c19 Merge branch 'main' into 0.1.7 2026-02-03 14:06:06 +01:00
maziggy 84d2517aa1 Fixed backup permissions 2026-02-03 14:04:36 +01:00
MartinNYHC 7a149254d5 Merge pull request #242 from maziggy/0.1.7
Fix for Information exposure through an exception #72
2026-02-03 13:50:47 +01:00
MartinNYHC 603e3ca62b Merge branch 'main' into 0.1.7 2026-02-03 13:49:18 +01:00
maziggy ababe4e3ed Fix for Information exposure through an exception #72 2026-02-03 13:48:44 +01:00
MartinNYHC 025325d9b0 Merge pull request #241 from maziggy/0.1.7
Fix for Information exposure through an exception #72
2026-02-03 13:38:31 +01:00
MartinNYHC b05f376e70 Merge branch 'main' into 0.1.7 2026-02-03 13:37:00 +01:00
maziggy 691b7e262a Fix for Information exposure through an exception #72 2026-02-03 13:36:22 +01:00
MartinNYHC a9b3dc5cca Merge pull request #240 from maziggy/0.1.7
Updated test_docker.sh
2026-02-03 13:26:38 +01:00
MartinNYHC 2fe6b04e9b Merge branch 'main' into 0.1.7 2026-02-03 13:26:26 +01:00
maziggy 78cbd58d7a Updated test_docker.sh 2026-02-03 13:14:00 +01:00
maziggy 2837455509 Updated test_docker.sh 2026-02-03 13:13:26 +01:00
MartinNYHC 230aac59a6 Merge pull request #239 from maziggy/0.1.7
v0.1.7
2026-02-03 13:04:18 +01:00
maziggy 37b73b8868 Sync 2026-02-03 13:02:36 +01:00
MartinNYHC 6872d77e1d Merge branch 'main' into 0.1.7 2026-02-03 12:59:27 +01:00
maziggy 8b2bdebb3f Sync 2026-02-03 12:42:55 +01:00
maziggy 89b19cbe4f Sync 2026-02-03 12:40:01 +01:00
maziggy e9e49768fe Sync 2026-02-03 12:30:46 +01:00
maziggy 9787400935 Sync 2026-02-03 12:27:36 +01:00
maziggy 626290d401 Sync 2026-02-03 12:09:28 +01:00
maziggy 08f2dffd75 Added new download functions to client.ts:
- downloadArchive(id, filename) - for 3MF archive downloads
  - downloadSource3mf(archiveId) - for source 3MF downloads
  - downloadF3d(archiveId) - for Fusion 360 file downloads
  - downloadLibraryFile(id, filename) - for library file downloads
  - downloadPrinterFile(printerId, path) - for printer file downloads
  - exportBackup() - fixed (already existed, just added auth header)

  Updated components to use auth-aware downloads:
  - ArchivesPage.tsx - 8 places fixed (F3D, Source 3MF, Archive downloads)
  - FileManagerPage.tsx - Library file download fixed
  - FileManagerModal.tsx - Printer file download fixed

  All fetch-based downloads now include the Authorization: Bearer ${token} header when auth is enabled.
2026-02-03 12:04:02 +01:00
MartinNYHC 794797ea0c Merge pull request #238 from maziggy/0.1.7
v0.1.7
2026-02-03 11:45:19 +01:00
MartinNYHC 7264e5fb40 Merge branch 'main' into 0.1.7 2026-02-03 11:43:37 +01:00
maziggy a0f3b02287 Bumped version 2026-02-03 11:41:31 +01:00
MartinNYHC 8765a29d12 Merge pull request #237 from maziggy/0.1.7b
v0.1.7b
2026-02-03 11:16:52 +01:00
MartinNYHC 83459128e8 Merge branch 'main' into 0.1.7b 2026-02-03 11:14:53 +01:00
maziggy 601f906339 Updated REAME 2026-02-03 11:04:46 +01:00
maziggy 583c374f01 Add Virtual Printer Proxy Mode for remote printing
Introduces a new "Proxy Mode" for the Virtual Printer that enables
remote printing from anywhere in the world without VPN, port forwarding,
or Bambu Cloud dependency.

Bambuddy acts as a TLS relay between a remote slicer (Bambu Studio/
OrcaSlicer) and the local Bambu Lab printer:

  Remote Slicer → Internet → Bambuddy Server → Local Network → Printer

The slicer connects to Bambuddy using the real printer's serial number
and access code. Bambuddy authenticates and relays all FTP (file transfer)
and MQTT (commands/status) traffic with end-to-end TLS encryption.

- No port forwarding required - printer stays safely on local network
- No VPN needed - connect from coffee shops, hotels, work, anywhere
- No Bambu Cloud dependency - fully self-hosted solution
- End-to-end TLS encryption on FTP (port 9990) and MQTT (port 8883)
- Works with Bambu Studio and OrcaSlicer
- Uses real printer credentials for authentication
- Automatic printer selection from connected printers

- Add SlicerProxyManager class for TLS relay (tcp_proxy.py)
  - TLS termination with auto-generated certificates
  - Concurrent FTP and MQTT proxy servers
  - Connection lifecycle management with proper cleanup
- Extend VirtualPrinterManager with proxy mode support
  - New 'proxy' mode alongside archive/review/queue modes
  - Target printer selection and credential management
- Add proxy configuration endpoints to settings API
- Add permission checks for proxy endpoints

- Add Proxy Mode card to Virtual Printer settings
- Target printer dropdown for proxy destination
- Real-time proxy status display (ports, target, running state)
- Full i18n support (English, German)

- Add network architecture diagram
- Add proxy mode section to README
- Add comprehensive guide to wiki
- Add prominent feature section to website

- Backend unit tests for SlicerProxyManager
- Backend unit tests for proxy mode configuration
- Frontend tests for proxy mode UI components

Closes #207 #170
2026-02-03 11:02:13 +01:00
maziggy 158fa88b7a Fix frontend API calls missing auth tokens
Several frontend components were using raw fetch() instead of the API
client, causing 401 Unauthorized errors when authentication is enabled.

Changes:
- SpoolmanSettings: Use api.getSpoolmanSettings/updateSpoolmanSettings
- ProjectsPage: Use api.importProjectFile for ZIP imports
- ProjectDetailPage: Use api.exportProjectZip for exports
- CameraPage/EmbeddedCameraViewer: Use api.getCameraStatus

Added to API client:
- getSpoolmanSettings()
- updateSpoolmanSettings()
- importProjectFile()
- exportProjectZip()
- getCameraStatus()

Added tests for auth token handling in client.test.ts
Fixed VirtualPrinterSettings test expectations to match i18n strings

Closes #231
2026-02-03 10:19:28 +01:00
MartinNYHC 9e44692765 Merge pull request #236 from maziggy/feature/slicer-proxy
Feature/slicer proxy
2026-02-03 10:04:29 +01:00
MartinNYHC 24e35d963e Merge branch '0.1.7b' into feature/slicer-proxy 2026-02-03 10:04:18 +01:00
maziggy 5b98962938 Sync 2026-02-03 10:03:11 +01:00
maziggy 99fa902b64 Allow multiple Home Assistant entities per printer (fixes #214)
Both frontend and backend were blocking printers that already had any
smart plug linked, preventing users from adding multiple HA entities
to the same printer.

Changes:
- Frontend: Only filter out printers with existing Tasmota plugs
- Backend: Only check for duplicate Tasmota plugs on create/update
- HA entities (switches, scripts, lights, etc.) can now be linked
  multiple times to the same printer for different automations
- Tasmota plugs remain limited to one per printer (physical device)
- Restored "Show on Printer Card" toggle for HA entities
- Fixed printer card only showing script.* entities; now shows all
  HA entities with the toggle enabled
- HA entities now default to auto_on=False and auto_off=False
- Printer cards now update immediately when HA entities change

Closes #214
2026-02-03 09:13:13 +01:00
maziggy a82f9278d2 Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.

Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
  archives, projects, settings, api_keys, groups, cloud, github_backup,
  support, notifications, notification_templates, maintenance, filaments,
  external_links, smart_plugs, discovery, firmware, kprofiles, camera,
  ams_history, pending_uploads, updates, spoolman, system, print_queue,
  printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
  streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)

Fixes: CVE-2026-25505
2026-02-03 09:13:00 +01:00
maziggy 572dbf393e Fix 500 error on GET /archives/{id} endpoint
Load project relationship in ArchiveService.get_archive() alongside
created_by. Async SQLAlchemy doesn't support lazy loading, so project
must be eagerly loaded for archive_to_response() to access project.name.
2026-02-03 09:13:00 +01:00
maziggy 49daba0579 Fix date picker format issues
Issue #233: Respect user date/time format in queue scheduler
- Replace native datetime-local input with custom text inputs
- Add date parsing/formatting utilities for US, EU, ISO, and system formats
- Add calendar button that opens native picker for convenience
- Pass dateFormat and timeFormat settings to ScheduleOptionsPanel
- Show format-appropriate placeholders (MM/DD/YYYY, DD/MM/YYYY, etc.)

Closes #233
2026-02-03 09:13:00 +01:00
maziggy 6431a86e2f Fix monthly comparison calculation ignoring quantity multiplier (Issue #229)
The filament statistics were under-reporting totals because the quantity
field was not being multiplied with filament_used_grams. When users
printed multiple items (quantity > 1), only the base filament amount
was counted instead of the total.

Closes #229
2026-02-03 09:12:43 +01:00
maziggy bb61a1dbef Add TOTP authenticator support for Bambu Cloud login (fixes #182)
TOTP (Two-Factor Authentication):
- Detect TOTP vs email verification from Bambu API loginType response
- Use dedicated TFA endpoint on bambulab.com (not api.bambulab.com)
- Include browser-like headers to bypass Cloudflare protection
- Extract token from JSON response or cookies
- Frontend shows appropriate messages for each verification type
- Added i18n translations for TOTP UI (en, de, ja)

Closes #182
2026-02-03 09:12:31 +01:00
maziggy da457002d6 Fix authentication for download endpoints (fixes #231)
Add missing Authorization header to fetch() calls that bypass the
request() helper. These endpoints returned 401 when auth was enabled
because the JWT token wasn't being sent with the request.

Affected functions in frontend/src/api/client.ts:
- downloadSupportBundle (support bundle download)
- downloadPrinterFilesAsZip (printer file downloads)
- exportArchives (archive CSV/XLSX export)
- exportStats (statistics CSV/XLSX export)

Closes #231
2026-02-03 09:12:17 +01:00
maziggy 6916bc8ed9 Added Japanese language pack (Thanks to @nmori) 2026-02-03 09:12:17 +01:00
maziggy 24a30e2452 Allow multiple Home Assistant entities per printer (fixes #214)
Both frontend and backend were blocking printers that already had any
smart plug linked, preventing users from adding multiple HA entities
to the same printer.

Changes:
- Frontend: Only filter out printers with existing Tasmota plugs
- Backend: Only check for duplicate Tasmota plugs on create/update
- HA entities (switches, scripts, lights, etc.) can now be linked
  multiple times to the same printer for different automations
- Tasmota plugs remain limited to one per printer (physical device)
- Restored "Show on Printer Card" toggle for HA entities
- Fixed printer card only showing script.* entities; now shows all
  HA entities with the toggle enabled
- HA entities now default to auto_on=False and auto_off=False
- Printer cards now update immediately when HA entities change

Closes #214
2026-02-03 09:08:12 +01:00
maziggy 3fa9ed2b91 Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.

Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
  archives, projects, settings, api_keys, groups, cloud, github_backup,
  support, notifications, notification_templates, maintenance, filaments,
  external_links, smart_plugs, discovery, firmware, kprofiles, camera,
  ams_history, pending_uploads, updates, spoolman, system, print_queue,
  printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
  streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)

Fixes: CVE-2026-25505
2026-02-03 08:44:07 +01:00
maziggy 5b76cf3623 Fix 500 error on GET /archives/{id} endpoint
Load project relationship in ArchiveService.get_archive() alongside
created_by. Async SQLAlchemy doesn't support lazy loading, so project
must be eagerly loaded for archive_to_response() to access project.name.
2026-02-03 07:54:03 +01:00
maziggy 7e298d8b85 Fix date picker format issues
Issue #233: Respect user date/time format in queue scheduler
- Replace native datetime-local input with custom text inputs
- Add date parsing/formatting utilities for US, EU, ISO, and system formats
- Add calendar button that opens native picker for convenience
- Pass dateFormat and timeFormat settings to ScheduleOptionsPanel
- Show format-appropriate placeholders (MM/DD/YYYY, DD/MM/YYYY, etc.)

Closes #233
2026-02-03 07:47:22 +01:00
maziggy 11456c0d2a Fix monthly comparison calculation ignoring quantity multiplier (Issue #229)
The filament statistics were under-reporting totals because the quantity
field was not being multiplied with filament_used_grams. When users
printed multiple items (quantity > 1), only the base filament amount
was counted instead of the total.

Closes #229
2026-02-03 07:29:38 +01:00
maziggy ea93535bfc Add TOTP authenticator support for Bambu Cloud login (fixes #182)
TOTP (Two-Factor Authentication):
- Detect TOTP vs email verification from Bambu API loginType response
- Use dedicated TFA endpoint on bambulab.com (not api.bambulab.com)
- Include browser-like headers to bypass Cloudflare protection
- Extract token from JSON response or cookies
- Frontend shows appropriate messages for each verification type
- Added i18n translations for TOTP UI (en, de, ja)

Closes #182
2026-02-03 07:18:13 +01:00