Commit Graph
3241 Commits
Author SHA1 Message Date
maziggy daecfe6ca0 fix(windows): bundle vcruntime140_1.dll so greenlet loads on fresh Win10 (#2474)
A clean Windows 10 install crashed on startup: init_db() -> SQLAlchemy async
    engine -> greenlet failed with "DLL load failed while importing _greenlet:
    The specified module could not be found", so uvicorn never bound :8000 and the
    dashboard refused all connections while the NSSM service still showed running.

    greenlet's _greenlet.pyd is C++ and needs vcruntime140_1.dll, which the
    python.org embeddable distribution does not ship (it includes only
    vcruntime140.dll, enough for the pure-C python313.dll). Machines with the VC++
    2015-2022 redistributable already installed have the DLL in System32, which
    masked the bug in testing.

    Stage vcruntime140_1.dll and msvcp140.dll next to python.exe at build time,
    from a vendored copy or the runner's System32, failing loudly if absent. The
    Inno Setup [Files] step already copies staging\python\* recursively.
2026-07-07 11:05:52 +02:00
maziggy 2119ddd4f9 fix(vp): populate bind-interface list on macOS (route non-Linux to psutil)
get_network_interfaces() only sent Windows to the psutil path; macOS fell into
    the Linux ioctl branch, whose SIOCGIFADDR/SIOCGIFNETMASK ioctls are Linux-only.
    macOS/BSD have fcntl but different ioctl numbers, so every call raised OSError
    and the function returned an empty list — the VP bind-interface dropdown showed
    nothing. Route all non-Linux platforms through the cross-platform psutil path.
2026-07-07 11:05:35 +02:00
maziggy ae7674b3c1 fix(install): make macOS native install rootless (brew + venv permission errors)
macOS mixed root-only steps (default /opt path, sudo git clone) with steps
    that must not run as root: brew refuses to run as root, and a root-owned
    venv/node_modules can't be managed by the launchd agent. The installer now
    refuses sudo on macOS, defaults to ~/bambuddy, and drops sudo from the
    download/venv/frontend/env/dir steps. A --path under a root-owned parent still
    works via a single elevate-and-chown. Linux (service user + systemd) unchanged.
2026-07-07 11:05:17 +02:00
maziggy e3fe2971db fix(camera): transcode non-JPEG external snapshots to JPEG (#1902)
External cameras in HTTP-snapshot mode failed to load with a repeating
    "connection lost" when the endpoint served PNG/WebP/BMP stills instead of
    JPEG (common on IP cameras and reverse-proxied snapshot URLs). The URL
    rendered fine directly in a browser, but Bambuddy's MJPEG stream wraps
    every part in a hard-coded Content-Type: image/jpeg boundary, so a
    non-JPEG payload labelled as JPEG made the browser reject the frame and
    tear down the whole multipart/x-mixed-replace stream.

    _capture_snapshot now transcodes non-JPEG stills to JPEG via OpenCV
    (already a dependency). Genuine JPEG snapshots keep a byte-for-byte fast
    path; truly undecodable responses (HTML error pages, auth redirects) fall
    back to the previous raw-return behaviour with a single clear warning
    instead of a per-frame log flood.
2026-07-07 11:04:58 +02:00
maziggy 33554072ed fix(ui): restore missing per-user Notifications nav item (#1901)
The sidebar-ordering refactor in #1673 accidentally dropped the
    `notifications` entry from `defaultNavItems` and its
    `notifications:user_email` permission mapping, but kept the advanced-auth
    visibility gate that references that id. With no nav entry the id never
    enters the render set, so the /notifications page (route, page, and API
    all intact) became reachable only by typing the URL — users could no
    longer opt in/out of their own print email notifications from the menu.

    Restore both the defaultNavItems entry and the permission gate, matching
    the permission the user-email-preferences API actually requires
    (notifications:user_email, held by both default groups). Add comments so
    the entry isn't dropped again in a future sidebar refactor.
2026-07-07 11:04:33 +02:00
maziggy 6e03ecdb8d fix(vp): stop uvloop from silently truncating VP FTP uploads (#1896)
Native (non-Docker) installs launched uvicorn without --loop asyncio, so
    uvicorn[standard] auto-selected uvloop. uvloop's SSL layer drops
    already-received but still-buffered data when the client closes the data
    connection without a TLS close_notify while the reader is flow-control
    paused on slow storage. cmd_STOR writes each chunk to disk inside the read
    loop, so a slow consumer falls behind, the tail is lost, read() returns a
    clean EOF, and the loop exits with no exception -- the server acked 226 for
    a file it truncated itself, then archived, queued, and forwarded the corrupt
    3MF to the real printer.

    Fix in two independent layers:

    1. Remove the trigger: add --loop asyncio to every native launch path,
       matching the Dockerfile -- deploy/bambuddy.service, install/install.sh
       (systemd + launchd), spoolbuddy/install/install.sh, the Windows NSSM
       service, README, CONTRIBUTING dev command.

    2. Defense in depth (loop-independent): cmd_STOR now validates that a
       received .3mf opens as a ZIP (reads the central directory, no
       decompression) before replying 226. A truncated/corrupt file is dropped
       and answered with 426, and on_file_received never runs -- so a broken
       upload surfaces as an immediate slicer-side send error instead of being
       archived and pushed to the printer. Scoped to .3mf; other filetypes pass
       through unchanged.
2026-07-07 11:04:04 +02:00
maziggy c5b02d9473 fix(auth): let API keys manage projects via new can_manage_projects scope (#1893)
PROJECTS_CREATE/UPDATE/DELETE were in _APIKEY_DENIED_PERMISSIONS with no
    entry in _APIKEY_SCOPE_BY_PERMISSION, so every project mutation returned a
    generic 403 for any API key regardless of granted permissions -- the same
    regression class as archives (#1888) and library (#1832).

    Add a per-key can_manage_projects scope. Project routes gate on plain
    PROJECTS_* (no OWN/ALL split), so all three CRUD permissions map to the one
    scope; membership edits (add-archives) gate on PROJECTS_UPDATE and are
    covered. PROJECTS_READ is unchanged (already under can_read_status).

    Column defaults TRUE for new keys; existing rows backfill to FALSE so the
    upgrade never silently widens scope. Migration is BOOLEAN (SQLite + Postgres
    safe), verified on fresh SQLite and Postgres 17. Bundled SpoolBuddy kiosk key
    set to False. Settings API-key UI gets a Manage Projects toggle + Projects
    badge; 11-locale i18n. RBAC scope matrix + drift guards extended.
2026-07-07 11:03:46 +02:00
maziggy 18dbe63fd5 fix(drying): don't stop a running AMS dry on an unreliable humidity re-check (#1892)
Auto-drying stopped manually started (and pre-restart) AMS drying cycles
    after exactly 30 minutes. The already-drying branch in _check_auto_drying()
    applied a humidity-based auto-stop despite its own "track but don't stop"
    comment, and the humidity re-check is unreliable: RH drops steeply in heated
    air, so the sensor reads ~15-20% within minutes of the dryer starting even
    with saturated filament. humidity <= threshold was thus effectively always
    true, and the _min_drying_seconds=1800 floor pinned the stop to the 30-minute
    mark. This also truncated Bambuddy's own preset-duration dries.

    Remove the humidity-based early-stop entirely: a running dry now runs to its
    configured duration (firmware stops it). Scheduling stops (print priority,
    queue no longer needing the dry) are unchanged via _stop_drying(). Drop the
    now-unused _min_drying_seconds.
2026-07-07 11:03:25 +02:00
maziggy c751047ed8 fix(websocket): stop the ws-token reconnect loop on auth failure
After the GHSA-r2qv gate (b7d7c825), /api/v1/ws needs a token from
    POST /api/v1/auth/ws-token (Permission.WEBSOCKET_CONNECT). When the mint
    failed, useWebSocket swallowed the error, opened a tokenless socket, the
    server closed it 4401, and ws.onclose rescheduled connect() every 3s -
    an endless loop that hammered /auth/ws-token. The dominant trigger is a
    validly-logged-in user whose group lacks WEBSOCKET_CONNECT (mint returns
    403). A secondary leak: the unmount-triggered onclose could schedule a
    post-unmount reconnect.

    Classify the mint failure: 401 (JWT expired; request() already clears it
    and dispatches auth:expired) or 403 (valid session, missing permission;
    degrade to REST polling) now stop the hook - no tokenless socket, no
    reconnect. A 4401 close is terminal. Network/5xx still reconnect. A
    disposedRef set in cleanup before close() prevents the unmount-race
    reconnect. Same 401/403 no-open guard applied to StreamOverlayPage.

    Also surface a one-line hint under the WebSocket permission in the group
    editor (all 11 locales) explaining that live updates need it and fall
    back to polling without it - rather than auto-granting the permission,
    which would partly undo the GHSA-r2qv gate.
2026-07-07 11:03:00 +02:00
maziggy 640c7daaaa fix(auth): don't discard a valid stored token on a transient load-time error (#1889)
On mount, AuthContext.checkAuthStatus restores the persisted "Remember Me"
    token from localStorage and validates it via GET /auth/me. The catch around
    that call cleared the token on ANY failure, not just a definitive 401
    invalid-token — so a brief backend-not-ready or reverse-proxy hiccup during
    page load (plausible right after a container restart, e.g. on Unraid) would
    delete a still-valid token. Because the token was deleted, a reload couldn't
    recover it and the user was bounced to the login screen.

    Token validation now retries transient failures (up to 3 attempts with short
    backoff) and only discards the token on a definitive 401 — which request()
    already handles (clears the token and dispatches auth:expired). Transient /
    5xx / network errors leave the persisted token intact so the session survives
    a slow load. "Remember Me" stays client-storage only; it does not extend the
    server-side JWT lifetime (session_max_hours, default 24h).

    Adds AuthContext tests: transient /auth/me failure keeps the token, a
    definitive 401 clears it, and a valid token loads the user. Rebuilt frontend
    bundle.
2026-07-07 11:02:40 +02:00
maziggy 1fd1825b71 fix(smart-plug): don't cut power when a print restarts, honor per-plug cooldown setting (#1890)
The print-queue "auto off after this job" trigger used a second, inline
    auto-off implementation (main.py, print_scheduler.py, print_queue.py)
    that hardcoded wait_for_cooldown(50C, 600s) — ignoring each plug's
    configured off_delay_mode / off_delay_minutes / off_temp_threshold — and
    ignored the return value, powering off on the 600s timeout regardless of
    print state. A print that failed and was reprinted from the touchscreen
    got its power cut mid-print. The inline tasks were also uncancellable, so
    a reprint couldn't abort a pending off.

    Consolidate all three into SmartPlugManager.schedule_off_after_queue_job,
    which schedules via the plug's configured strategy (shared with
    on_print_complete through _schedule_off_per_mode) and is cancellable via
    _pending_off. Add printer_manager.is_print_active() and guard the actual
    power-off in _delayed_off and _temp_based_off so no path cuts power on a
    loaded print. Move the on_print_start cancellation ahead of the auto_on
    gate so a reprint always aborts a pending off.
2026-07-07 11:02:21 +02:00
maziggy 99d06f3cd1 fix(auth): allow API keys to delete/edit archives via new can_manage_archives scope (#1888)
DELETE /api/v1/archives/{id} rejected every API key with 403
    "API keys cannot be used for administrative operations", regardless of
    the print's owner or the key's scopes. ARCHIVES_DELETE_ALL/_OWN (and the
    create/update variants) were on the denylist and absent from the scope
    allowlist, so require_ownership_permission fell through to the generic
    admin-denied 403 — the whole archive-management surface was unreachable
    for API keys. Same regression class as the #1832 library/maintenance
    carve-outs.

    Add a can_manage_archives per-key scope: ARCHIVES_CREATE, ARCHIVES_
    UPDATE_OWN/_ALL and ARCHIVES_DELETE_OWN/_ALL move from the denylist to
    the allowlist under it (OWN and ALL fold into the same scope, matching
    can_manage_library). ARCHIVES_PURGE stays admin-only — it drops the
    print's Quick Stats contribution, mirroring LIBRARY_PURGE. Column
    defaults TRUE for UI-created keys; existing rows backfill to FALSE so the
    upgrade never silently widens scope. Bundled SpoolBuddy kiosk key stays
    minimally scoped (False). Migration is dialect-agnostic and verified on
    fresh SQLite and Postgres 17.

    Adds the Settings API-key toggle + badge (11-locale i18n) and extends the
    RBAC scope matrix to cover all five archive-management permissions.
2026-07-07 11:01:57 +02:00
maziggy 11d73b0a64 fix(slicer): preserve PVA-for-support intent across re-slice of source 3MF (#1881)
Three bugs on the same PLA-model + PVA-support flow, discovered in
    sequence:

    (A) substitute_unused_plate_filaments inspected only object geometry
        (per-object extruder metadata + paint_color triangles) so a support-
        only slot was silently treated as "unused" and the user's PVA profile
        got overwritten with slot 1's PLA.

    (B) _extract_filament_info stripped filament_is_support==1 entries,
        hiding PVA from unsliced source archive cards even when the project
        explicitly configured it.

    (C) --load-settings is authoritative over the source's project_settings.
        config, and Bambu's shipped process presets ship enable_support=0
        (supports are a per-print decision, not per-quality). So even with
        (A) fixed, the sliced output had supports disabled and the PVA slot
        loaded but never consumed. Inverts BambuStudio GUI's semantics where
        the project overrides the preset.

    Fixes:
    - New extract_support_filament_slots_from_3mf reads enable_support +
      support_filament + support_interface_filament from project_settings.
      config; substitute_unused_plate_filaments unions it into the geometry-
      derived set.
    - _extract_filament_info returns all configured filament types + colours.
    - New _patch_process_support_settings overlays four fields (enable_
      support, support_filament, support_interface_filament, support_type)
      from the source 3MF onto the picked process preset JSON before
      --load-settings sees it. Deliberately targeted to what fixes #1881
      without widening to a full project-over-preset merge.
2026-07-07 11:01:25 +02:00
maziggy b6da148890 fix(vp): evict MQTT clients on drain timeout + tighten TCP keepalive (#1872)
Reporter (H2C + macOS 26.5.1 + BS 2.8.0.50): after every Mac sleep/wake
    cycle, Bambu Studio couldn't see the VP or connect to it. Only fix was
    quit BS + reboot Bambuddy. The physical printer's own cloud/LAN link
    recovered in ~5 s from the same sleep — the delta was in VP session
    handling.

    Log evidence (bug-report-assets/logs/ddf1ede75df045cd94ad223d0f08f88a):

    - 14:04:06 healthy `1Hz status push: 60 pushes/min to :54698`
    - 14:04:06 → 14:09:16: five minutes of SSDP-only, no push summary for
      :54698, no OSError, no disconnect line
    - 14:09:16: new source port :54861 connects and authenticates fine —
      the server was not rejecting reconnects
    - 14:10:17 first DEBUG line: `MQTT drain timeout for
      device/…/report — client may be busy` — smoking gun

    Root cause: `_publish_to_report:1149` caught `asyncio.wait_for(drain,
    timeout=5)` TimeoutError at DEBUG and returned silently. TimeoutError
    is not OSError, so the push loop's `except OSError` at :441 never saw
    it — the zombie writer sat in self._clients until the kernel's default
    TCP keepalive detected the dead peer (Linux default: ~2 h 11 min).

    Two hunks:

    1. `_publish_to_report`: on drain TimeoutError, close the writer (best
       effort, catch Exception so an already-broken close() doesn't mask
       the raise) and raise BrokenPipeError, which IS OSError. Push loop
       evicts on the same tick.

    2. `_handle_client`: after SO_KEEPALIVE=1, set TCP_KEEPIDLE=60,
       TCP_KEEPINTVL=15, TCP_KEEPCNT=4 — dead-peer detection in ~2 min
       instead of ~2 h. `getattr(socket, ...)` guards keep it cross-
       platform (macOS uses TCP_KEEPALIVE not TCP_KEEPIDLE, other kernels
       may not expose all three — skip whichever is missing).

    What I got wrong first pass and corrected on log-read: hypothesised
    "missing MQTT session takeover on same client_id". Wrong. _handle_connect
    parses the protocol client_id but discards it (assignment commented out
    at :762), and self._clients is keyed on `f"{addr[0]}:{addr[1]}"` (socket
    peer), so every reconnect gets a distinct key. No takeover race exists.
    The log fixed this: the "not seen" symptom is BS-side (macOS UDP
    receive after sleep + BS holding the pre-sleep socket state), but the
    server-side amplifier was the zombie writer.
2026-07-07 11:00:55 +02:00
maziggy 6d10e3ff89 fix(vp): route non-proxy camera passthrough by target model — 6000 for A1/P1 (#1868)
Non-proxy VP mode hardcoded the camera-passthrough TCPProxy to
    listen_port=322 / target_port=322 regardless of the target printer's
    model. That port is correct for RTSPS models (X1/X2/H2/P2S), but A1 /
    A1 Mini / P1P / P1S use Bambu's proprietary chamber-image protocol on
    port 6000. Result: A1/P1 targets got a 322 listener with no upstream,
    OrcaSlicer Liveview failed with [2:-10061], BambuStudio's camera button
    timed out.

    Reporter confirmed a raw socat forwarder `<VP-IP>:6000 → <P1S-IP>:6000`
    restored the stream — the target camera works, the VP just wasn't
    publishing it.

    Proxy mode was unaffected because SlicerProxyManager already opens 6000
    (nominally file-transfer; Bambu reuses the port for chamber-image), so
    the passthrough coincidentally works there.

    Fix: read the target's model from
    `printer_manager.get_client(target_id).model` at the same point we read
    target_ip, then use `get_camera_port(target_model)` — the same source of
    truth as routes/camera.py — to pick 322 or 6000. Model comes from the
    physical printer, NOT self.model (the VP's spoofed identity has no
    bearing on how the real device serves its camera).

    Renamed the log tag from "RTSP" to f"Camera-{camera_port}" so support
    bundles show which protocol the VP is fronting at a glance. Kept the
    _rtsp_proxy attribute name to keep the diff tight; the block comment
    spells out that it doubles as chamber-image passthrough on A1/P1.
2026-07-07 11:00:32 +02:00
maziggy 0c7480f9ea fix(queue): edit modal shows printer/model selection for model-assigned items
Editing a queue item that was created with "Any of model X" left the
    printer selection area completely blank — the assignmentMode was
    initialised to 'model' from queueItem.target_model, but the three
    model-mode props (onAssignmentModeChange, onTargetModelChange,
    onTargetLocationChange) were gated behind !isEditing. That flipped
    modelAssignmentAvailable to false in PrinterSelector and hid the mode
    toggle, the model dropdown, AND the location filter; combined with the
    assignmentMode === 'printer' gate on the printer list, the whole
    selector rendered empty.

    Users hit this whenever they queued something to "Any of model X" and
    then wanted to change the target model / location — the only workaround
    was delete + re-queue.

    Fix: drop the !isEditing gate on all three PrinterSelector props. The
    submit path already handles both flavours (target_model+target_location
    with printer_id=null vs. printer_id with the target fields nulled), so
    un-gating the UI just surfaces the machinery that was already there.
    Edit is still only offered on pending items, so the mode-flip can't race
    an in-flight dispatch.
2026-07-07 11:00:08 +02:00
maziggy 8b49edf811 fix(mqtt): capture finish photo on last-layer edge, not FINISH state (#1867)
A1 Mini firmware skips stg_cur=22 entirely, so the finish-photo fallback
    fires at gcode_state=FINISH — which runs AFTER Bambu Studio has already
    executed the user's End G-code. Users with SwapMod plate-swap injected
    into End G-code always got a photo of the swapped (empty) plate.

    Add a layer_num >= total_layer_num edge trigger in _parse_print_data so
    the pre-capture fires the moment the last object layer completes, on
    every printer variant. Guarded by the existing _finish_photo_captured
    one-shot so stage-22 and FINISH-state hooks become no-ops for the same
    print — no framing regression on AMS printers without custom end G-code.
2026-07-07 10:59:36 +02:00
maziggy 703dc693d7 feat(currency): add Indonesian Rupiah (IDR) support (#1869)
Adds IDR with Rp symbol to the supported currencies list, available
    in Settings → Cost Tracking.
2026-07-07 10:59:06 +02:00
maziggy 484ea9c2a4 fix(spoolman): split mid-print usage across AMS backup switch (#1793)
usage_tracker's tray-switch split has never had a Spoolman peer.
    An AMS same-material runout switch mid-print charged the whole slot
    to the origin spool via the (via tag) path and double-credited the
    backup via remain-delta — origin exceeded initial_weight.

    Extract the segment-math into utils/tray_split.compute_tray_split_grams
    and call it from both writers so the two inventory backends attribute
    mid-print switches identically. spoolman_tracking gains
    _report_spool_usage_split_by_tray_changes; the Path 2 remain-delta
    fallback now skips trays the split path covered, killing the
    double-count.
2026-07-07 10:58:24 +02:00
maziggy b8b5aaa977 feat(api-keys): can_manage_maintenance scope for HA-style automations (#1832 follow-up)
Carve MAINTENANCE_CREATE/UPDATE/DELETE out of the admin denylist so
    HA automations can log "cleaned nozzle" / reset a counter via API key
    without granting broader printer control. Follows the same shape as
    can_manage_library and can_manage_inventory: new column, allowlist
    entry, UI checkbox, wiki row, RBAC test coverage.

    Distinct backfill: these perms were EXPLICITLY denied for every API
    key before this change (no existing integration relies on them), so
    existing rows migrate to FALSE — no silent scope widening on upgrade.
    New keys default to TRUE, matching the safe-on-by-default pattern.
    Bundled SpoolBuddy kiosk key gets False explicitly (kiosk doesn't need it).
2026-07-07 10:58:09 +02:00
maziggy 7b18bbfc1d fix(printers): drop P1S / P1P from door-sensor badge whitelist (#1866)
P1S has an enclosure door but no hall sensor for it; P1P has no
    enclosure at all. Both models were rendering a permanent green
    "Door Closed" chip driven by bit 23 of the stat field, which stays
    0 forever on that firmware. Whitelist now covers only models that
    actually ship with a door sensor: X1 family, X2D, P2S, and H2 family.
    Corrected the matching stale comments in the PrinterStatus TS
    interface (client.ts) and PrinterState dataclass (bambu_mqtt.py).

    Backend parse left as-is — cheap and future-proof if Bambu ever
    wires the P-series enclosure into a sensor.
2026-07-07 10:57:50 +02:00
maziggy 5d400d2e6e fix(cloud): send required ?version= param on singular GET/DELETE of slicer setting endpoint (#1815)
get_setting_detail and delete_setting were hitting
    /v1/iot-service/api/slicer/setting/{id} without the version query
    parameter Bambu Cloud requires — every call returned HTTP 400
    "field 'version' is not set". The sibling plural GET
    (get_slicer_settings) has always sent it; the comment above
    _SLICER_API_VERSION documents the contract for the endpoint subtree.
    Missed when the placeholder landed in the 2026-05-12 compliance rework.

    Downstream effect: slicer_filament_resolver.resolve_slicer_filament's
    PFUS branch swallowed the 400, fell through to normalize_slicer_filament,
    and caller inventory.py generic-material-fell-back tray_info_idx to
    GFL99/GFG99. BambuStudio's AMS panel reads the printer's tray_info_idx
    echo, so the user saw "Generic PLA" instead of the custom cloud preset.

    Masked for 50 days by two rescue paths in the caller: prior-slot
    tray_info_idx reuse, and stored spool_k_profile → live state.kprofiles
    realign. Reporter's spool 54 → tray 2 assign had neither.

    Adjacent surfaces also fixed by the same two-line change: the delete
    cloud preset UI route, the whole update_setting flow (get_setting_detail
    → delete_setting → POST), preset_resolver's cloud branch, and three
    UI-facing cloud.py routes that fetch setting detail.

    get_setting_detail also includes the truncated response body in the
    raised BambuCloudError so the next contract change is self-diagnostic
    from support-bundle logs.
2026-07-07 10:57:33 +02:00
maziggy ca37d1e200 ci(repo-stats): clone the github-repo-stats data branch, not gh-pages
The opaque "exit code 1" from actions/checkout was actually masking a
    "Remote branch gh-pages not found in upstream origin" — the bambuddy
    repo doesn't have a gh-pages branch. jgehrcke/github-repo-stats writes
    to a branch called `github-repo-stats` by default, and Pages is wired
    to serve from that branch. The path under it (maziggy/bambuddy/latest-
    report/report.html) is unchanged.

    Switching the clone branch and renaming the local path from `gh-pages/`
    to `data/` so the workflow reads correctly. The PAT-in-URL pattern and
    the direct git clone (vs actions/checkout) stay — both still wanted so
    the real git stderr reaches the log if anything goes wrong.

    Verified by cloning `github-repo-stats` locally and running the
    injector against its live report.html: clean patch, 30 days extracted,
    all anchor markers (TOC, section, script) present.
2026-07-07 10:57:16 +02:00
maziggy 259cf7a975 ci(repo-stats): swap actions/checkout for direct git clone on gh-pages
The PAT-token swap didn't fix the gh-pages fetch — same opaque "exit
    code 1" from actions/checkout@v4 on both attempts of the retry loop,
    with no underlying git stderr surfaced. Likely the wildcard-refspec
    + shallow fetch pattern v4 uses combined with something at the runner
    side, but the action's swallowed errors make it untriagable from logs.

    Replacing the gh-pages checkout with `git clone --branch gh-pages
    --depth 1` using the same PAT, embedded in the URL. Direct, explicit,
    and if anything goes wrong the real git error reaches the log instead
    of "exit code 1". The recorded remote keeps the PAT, so the later
    `git push` reuses it — no separate auth setup needed.

    Identity config (user.name / user.email) moved into the clone step so
    it lives on the freshly cloned repo; dropped the now-duplicate config
    calls from commit-and-push.

    Source checkout still uses actions/checkout@v4 since it never had a
    problem (the default ref is the workflow's own commit, no wildcard
    refspec required).
2026-07-07 10:56:29 +02:00
maziggy 007c694674 ci(repo-stats): use jgehrcke's PAT for gh-pages checkout
The default GITHUB_TOKEN failed at `git fetch` for the gh-pages
    checkout step with opaque "exit code 1" and no surfaced git stderr,
    even with permissions: contents: write set at workflow level.
    actions/checkout's retry loop didn't recover.

    Switching the gh-pages checkout to secrets.GHRS_GITHUB_API_TOKEN —
    the same PAT jgehrcke/github-repo-stats already writes the branch
    with one step earlier — keeps the auth chain uniform and avoids the
    mismatch. persist-credentials defaults to true, so the subsequent
    commit-and-push step in the same gh-pages directory picks up the
    PAT automatically; no separate change to the push step needed.

    fetch-depth: 1 left explicit because checkout@v4 defaults to it but
    the value's load-bearing for this workflow (we only need HEAD of
    gh-pages, not history).
2026-07-07 10:55:30 +02:00
maziggy a48afbb6e7 ci(repo-stats): chart container pulls from ghcr.io alongside clones/stars
GHCR exposes total + 30-day daily-pull counts only in the package page
    HTML (no REST or GraphQL endpoint). jgehrcke/github-repo-stats has no
    notion of container metrics, so post-process the report after it runs.

    New: .github/scripts/ghcr_inject.py
    - Scrapes Total downloads (exact integer from title="N", not the K-rounded
      display) and the 30-day sparkline (rect data-merge-count, data-date).
    - Merges per-day rows into maziggy/bambuddy/ghcr-pulls.csv on gh-pages.
      Fresh window overwrites overlapping dates, so GitHub's late revisions
      to the last 30 days self-correct; days older than 30 stay frozen at
      whatever was captured while still in-window.
    - Patches latest-report/report.html: adds a TOC entry, a Container
      pulls (ghcr.io) section at the top, and a Vega-Lite line+point chart
      whose theme/config is cloned from the existing Total clones chart so
      it inherits the report's look-and-feel.
    - Bracketed by HTML-comment markers so re-runs replace rather than
      stack (jgehrcke regenerates report.html every tick; we re-inject).
    - Hard-fails if either scrape pattern stops matching — silent fallbacks
      would let the chart freeze without notice.

    Workflow: after run-ghrs, checkout source + gh-pages, run the injector,
    commit only if the diff is non-empty. Uses the existing contents: write
    permission; no new secrets.
2026-07-07 10:54:53 +02:00
maziggy c9061c2b72 fix(scheduler): cancel during queue dispatch actually cancels (#1853)
Symptom: user queued a batch of 10 prints, pressed Cancel on a pending
    row, the print started anyway. Repeated consecutively. Support bundle
    also showed 15x "sqlite3.OperationalError: database is locked" from the
    sensor history recorder in the same 8-minute window.

    Root cause is a check-then-act race in _start_print. check_queue takes
    a snapshot of pending items, then _start_print does FTP delete + FTP
    upload (5-30s) before the unconditional item.status = "printing";
    db.commit() at line 2792. /cancel commits status='cancelled' in a
    separate session during that window; the scheduler's stale in-memory
    write overwrites it and start_print ships. The lock-contention finding
    is the same shape from a different angle: _start_print did
    await db.flush() at line 2555 (after item.archive_id set + library_file
    delete) which opens the SQLite WAL writer lock and holds it through
    the FTP upload, queueing every concurrent writer behind it including
    the user's own cancel commit.

    Three guards layered:

    1) Atomic CAS at the pending->printing transition. UPDATE print_queue
       SET status='printing', started_at=NOW() WHERE id=:id AND
       status='pending'. rowcount==0 means user won; log abort, best-effort
       delete_file_async the file we just FTP'd up so it doesn't leak into
       the printer's BambuStudio file picker, send queue_item_failed WS
       event with reason="cancelled_mid_dispatch", return without calling
       printer_manager.start_print.

    2) Early db.refresh(item) + bail right after the printer connectivity
       check. Saves the wasted FTP upload when the row was already
       cancelled before _start_print resumed. Defense in depth; guard 1
       catches the same case at the CAS point.

    3) flush -> commit before the FTP block. The library-file-to-archive
       promotion's writes commit cleanly, WAL writer lock releases, sensor
       history and concurrent cancels stop queueing behind the scheduler.
       The flush-not-commit pattern was rolling back a pointer to an
       already-committed archive row, so the new behaviour matches reality
       (archive committed, pointer committed, FTP unblocked).
2026-07-07 10:53:39 +02:00
maziggy 82af3cc0fe fix(modal): gcode_injection checkbox toggles cleanly on single prints (#1852)
PrintModal carried a useEffect that reset scheduleOptions.gcodeInjection
    to false whenever mode === 'create' AND effectiveQuantity <= 1. The
    comment claimed the checkbox only renders for quantity > 1, but the
    actual render gate in ScheduleOptions is just hasGcodeSnippets — no
    quantity check. So with snippets configured + quantity = 1 (the OP
    scenario): user clicks the checkbox, React updates state to true,
    the parent's useEffect immediately sees effectiveQuantity <= 1 and
    resets to false, and the checkbox appears un-clickable. Edit-queue-
    item mode worked because mode !== 'create' short-circuited the reset.

    Drop the effectiveQuantity <= 1 clause from the reset. Keep the
    !settings?.gcode_snippets half as the legitimate cleanup for the
    "admin removes all snippets while modal is open" case. The scheduler
    reads item.gcode_injection per queue item regardless of batch size,
    so single prints can inject too.
2026-07-07 10:53:21 +02:00
maziggy 5a244661bc feat(scheduler): preheat & heat-soak before queued prints with per-filament chamber targets + airduct flap control (#1468)
New scheduler stage that heats the bed (and the chamber, on supported
    printers) and holds at temperature before each queued print starts —
    the heat-soak engineering filaments need for adhesion and warp
    control. Bambuddy waits between FTP upload and start_print, so the
    soak runs while the printer is otherwise idle. M191 is silently
    ignored by Bambu firmware, so doing this at the orchestration layer
    is the only place it works.

    Resolution order at dispatch:

    1. PrintQueueItem.preheat_override ∈ {inherit, on, off}.
       'off' skips entirely; 'inherit' falls back to the global
       preheat_enabled toggle; 'on' forces the stage even when the
       global is off.

    2. chamber_target = item.preheat_chamber_target_override
                     ?? max(filament_map[normalize(t.tray_type)] for loaded slots)
                     ?? 0.
       Mixed PA+PLA picks PA's 50 (max-across-slots — PA's chamber
       requirement is binding, PLA doesn't suffer being warm). PLA-only
       derives 0 and skips the chamber phase automatically.

    3. Three hardware tiers for chamber heat:
       - Active chamber heater (H2C/H2D/H2D Pro/H2S/X2D/X1E) → M141 +
         chamber-sensor wait
       - Chamber sensor only (X1C/P2S) → no M141, passive bed-radiation
         wait with hard max-wait cap
       - No chamber sensor (P1S/P1P/A1/A1 Mini) → bed + soak timer only

    4. Airduct flap (H2C/H2D/H2D Pro/H2S/X2D/P2S) auto-switches to
       match the chamber target — heating mode for engineering
       filaments, cooling mode for PLA. Bambu firmware does NOT
       auto-switch the flap with M141, so without this an ABS print
       on a previously-cooling flap fights the open exhaust, and a
       PLA print on a previously-hot flap recirculates ABS heat.
       Idempotent: only fires set_airduct_mode when current ≠ desired.

    Settings → Workflow → Queue & Dispatch → Preheat & Heat Soak card:
    master enable toggle (default off — disabled installs see no change),
    per-filament chamber-target editor (replaces a single global int that
    shipped in the first cut and couldn't serve PA + PLA in the same
    config), preheat_max_wait_seconds, preheat_soak_seconds. The Print
    Options panel in PrintModal gets a Preheat sub-section with the
    tri-state Inherit/On/Off control and an optional chamber-target
    override input.

    DB migration: PrintQueueItem gains preheat_override VARCHAR(10)
    DEFAULT 'inherit' and preheat_chamber_target_override INTEGER NULL.
    Idempotent via _safe_execute. Existing rows behave exactly as before
    the migration.

    Best-effort throughout: printer drops, refused M141 or set_airduct,
    missing bed temp, lost MQTT state mid-wait all log and return cleanly.
    Normal upload + start path runs after this returns regardless.
2026-07-07 10:52:50 +02:00
maziggy 2fe6982981 fix(hms): wrong-plate Ignore actually ignores + buttons read as buttons + ack-detection survives transient re-pause (#1869)
The HMS error modal had three compounding bugs that surfaced when a
    user forced a wrong-plate HMS (0500_8051) and tried to dispatch the
    per-fault actions.

    (1) IGNORE_RESUME did not ignore. Bambuddy redirected the action on
    state=PAUSE to a plain `resume` command, citing a #1830 verdict that
    BambuStudio's "err-bearing shape" was firmware-silently-rejected.
    BambuStudio source disagrees: DeviceErrorDialog.cpp:600 dispatches
    IGNORE_RESUME via command_hms_ignore, whose wire shape is
    {command:"ignore", err:"<decimal>", param:"reserve", job_id:...}.
    That's a distinct command from `resume` — the firmware suppresses
    the next re-check AND auto-resumes in one operation. Plain resume
    means "re-check normally", which is exactly why the wrong-plate
    detection re-fired 1-2 s after the user clicked Ignore. The #1830
    "err-bearing shape rejected" test almost certainly sent the err as
    a hex shortcode; BambuStudio passes std::to_string(int m_error_code)
    i.e. the DECIMAL form, which is what the firmware matches against.

    (2) Action buttons read as inert badges. The button className used
    `hover:${buttonHoverColor}` — a template-literal interpolation
    Tailwind's JIT scanner can't see as a literal string, so the
    per-severity hover utility never reached the compiled CSS. Same
    bg/text color as the severity badge above and no border made it
    read as another label. No disabled state and no spinner during the
    2.5 s ack wait left clicks sitting silently inert.

    (3) Ack-detection 502'd on legitimate ack. The route compared
    (gcode_state, hms_errors-len) before vs after publish; wrong-plate
    re-pause round-tripped both fields to their pre-publish values
    inside the 2.5 s window → false 502 even though the firmware fully
    ack'd. PROBLEM_SOLVED_RESUME working but IGNORE_RESUME 502'ing on
    the same fault was the same race resolving differently.

    Fixes:

    bambu_mqtt.py — new hms_ignore_command() publishes the BambuStudio
    shape; existing hms_ignore(persistent) renamed to hms_idle_ignore
    (unchanged shape, used by NO_REMINDER_NEXT_TIME per
    DeviceErrorDialog.cpp:588). Dispatch routes IGNORE_RESUME,
    IGNORE_NO_REMINDER_NEXT_TIME, and DONT_REMIND_NEXT_TIME to
    hms_ignore_command (BambuStudio routes all three to the same
    command_hms_ignore — the "don't remind" half is the firmware's
    job). NO_REMINDER_NEXT_TIME stays on hms_idle_ignore type=0. Hex →
    decimal err conversion at the helper layer with a defensive
    fallback. job_id=None → empty string (matches BambuStudio's
    std::string default).

    HMSErrorModal.tsx — getSeverityInfo loses the dead buttonHoverColor
    field. Action button uses static
    `bg-white/10 hover:bg-white/20 active:bg-white/30 text-white
    border border-white/20`, wires
    `disabled={!hasPermission||mutation.isPending}`, and renders
    `<Loader2/>` only on the button whose (action,print_error) matches
    mutation.variables.

    printers.py — ack-detection probes `client._last_message_time`
    (bumped on every MQTT push regardless of payload) rather than
    diffing state fields. The pushall that follows every command
    guarantees a fresh push lands inside the 2.5 s window on any
    healthy printer; only firmware-silent-drop leaves the timestamp
    untouched, which is the 502 path #1830 wanted.
2026-07-07 10:52:19 +02:00
maziggy 6507fbcc40 fix(slicer): surface real CLI rejections + hard-skip mismatched filaments in auto-pick (#1851)
Two compounding bugs let an H2C-bound filament land in slot 1 of an A1
    slice silently. (1) `_slicer_rejection_message` discarded the actual CLI
    diagnostic - `filament preset Generic PLA @BBL H2C (slot 1) is not
    compatible with printer Bambu Lab A1 0.4 nozzle.` - when the sidecar's
    headline error_string was Bambu Studio's catch-all
    `The input preset file is invalid and can not be parsed.` placeholder.
    The real reason was in the stdout `[error] run NNNN:` line, trimmed off
    before reaching the SliceJob's error_detail. (2) `pickFilamentForSlot`
    used a soft `-100` mismatch penalty rather than a hard skip, leaving
    the "never auto-fill an incompatible preset while a compatible one
    exists" contract implicit. The unused-slot substitution in
    `substitute_unused_plate_filaments` then propagated whatever slot 1
    held across every unused slot - one bad pick poisoned the array.

    (1) Mine `[error] <msg>` (with or without `run NNNN:`) from the full
    pre-trim response; substitute the placeholder, keep meaningful
    headlines. (2) Partition candidates into compatible/unknown vs
    mismatch; prefer compatible whenever the bucket is non-empty, fall
    back to mismatch only on graceful-degrade. Picker helpers moved out
    of `SliceModal.tsx` into `utils/slicePresetPicker.ts` so the modal
    file stays component-only (react-refresh lint).
2026-07-07 10:51:51 +02:00
maziggy 7f661be941 fix(frontend/hms): surface uncataloged HMS faults that carry firmware actions (#1840)
filterKnownHMSErrors and the modal-local copy gated visibility on
    ERROR_DESCRIPTIONS membership. H2C 0500_809C carries IGNORE_RESUME /
    PROBLEM_SOLVED_RESUME but is missing from the bundled 853-entry catalog,
    so the entire error — pip, count, panel, action buttons — never rendered
    even though backend captured + dispatched it correctly.

    The gate isn't dead code: PrintersPageBucketing pins the post-cancel
    0C00_001B junk-echo regression to it. Widen the predicate to keep
    (cataloged) OR (actions.length > 0) so noise is still filtered out
    while user-actionable faults always surface.

    Replace the modal's inline filter with the shared helper so badge
    counts and modal contents agree by construction. Fall back to
    hmsErrors.unknownCode ("Unknown HMS code — see the Bambu Lab wiki
    for details.") when the catalog has no entry. New key translated in
    all 11 locales.

    New bucketing test pins PAUSE + uncataloged-with-actions = error;
    existing FAILED + uncataloged-without-actions = finished stays green.
2026-07-07 10:51:17 +02:00
maziggy a57b752e3a fix(notifications): defer first-layer photo until printer is actually printing (#1837)
P1S and other Bambu printers tick layer_num during the pre-print calibration
    sequence (homing -> auto bed leveling -> bed-surface scan -> nozzle clean ->
    purge / wipe), so a bare `2 <= layer_num <= 5` gate fires the first-layer
    notification minutes before the first real extrusion. The attached photo
    shows a lowered bed, parked toolhead, and a clean plate -- exactly the
    state during PREPARE, not after layer 1.

    The reporter's log timeline made it explicit:
    - 13:54:27  PRINT START detected
    - 14:10:13  [SNAPSHOT] Capturing fresh frame  (notification fires here)
    - 14:44:28  gcode_state: RUNNING (debug log, only visible because they
                enabled debug logging mid-print)

    So the notification went out ~30 minutes before the print actually started.

    Fix in main.py:6043 -- the on_layer_change first-layer block now requires
    both:

      - state.state == "RUNNING" (gcode_state is RUNNING, not PREPARE)
      - state.mc_print_sub_stage in (None, 0)
        (0 = "Printing" in the canonical STAGE_NAMES at bambu_mqtt.py:376;
        None preserved as a no-opinion fall-through for any firmware that
        doesn't push the sub-stage so unknown-firmware installs keep
        their existing behaviour)

    _first_layer_notified is only set after the gate passes, so calibration
    ticks are non-consuming -- the next on_layer_change edge fires the
    notification once the printer is actually printing.

    The trigger window widens from [2, 5] to [2, 10] so that if calibration
    consumed several layer_num slots before RUNNING, the deferred edge
    still falls inside. The RUNNING + sub-stage gate ensures we don't fire
    on a stale layer count.
2026-07-07 10:50:15 +02:00
maziggy b26b68c236 fix(permissions): self-heal Administrators to ALL_PERMISSIONS on upgrade + Pipelines runs dashboard polish
Administrators system group sync
    - Fresh installs already bootstrap with ALL_PERMISSIONS, so they always have
      every permission. Upgrades previously only got what one-off backfill blocks
      in seed_default_groups() explicitly listed (library:purge, archives:purge,
      the OWN/ALL read-flag block, orca_cloud:auth, pipelines:*). Any Permission
      enum member added without a matching block silently stayed missing on
      existing admin rows. The most recent gap was printer_sensor_history:read
      (Sensor History charts returned 403 for upgraded admins).
    - seed_default_groups() now syncs Administrators to ALL_PERMISSIONS on every
      startup: append every Permission value that isn't already on the row.
      Additive only -- hand-added custom permissions are preserved.
    - The pure-admin one-off backfills (library:purge / archives:purge block,
      the OWN/ALL + orca_cloud:auth + legacy-read-flag block, the Administrators
      branch of the pipeline backfill) are retired since the sync subsumes
      them. Non-admin backfills (Operators / Viewers OWN-tier reads, Operators
      orca_cloud:auth, pipelines for non-admin groups, makerworld:*, clear_plate
      cross-group adders) are untouched.
    - Tests: test_administrators_printer_sensor_history_read_backfilled
      (regression for the reported gap),
      test_administrators_sync_covers_every_current_permission (generic
      invariant -- any future new permission lands on admin without needing
      a one-off test), test_administrators_sync_is_additive_only (custom
      permissions preserved). 12/12 backfill-migration + 102/102 broader
      permission tests green; ruff clean.

    Pipelines runs dashboard
    - PipelineRunsPage.tsx: the Pipeline / Status / Target filter row's three
      native <select> elements are replaced with a bambu-themed FilterDropdown
      (button trigger, floating menu, optgroup-style headers for the Target
      picker, hover + selected states with a check mark, closes on outside
      click and Escape). Same value/onChange contract -- visual only.
    - SlicerPipelinesPanel.tsx: wrap list?.pipelines ?? [] in useMemo so the
      reference is stable when the data is stable. Fixes the
      react-hooks/exhaustive-deps warning where the inline fallback returned
      a fresh empty array every render, invalidating both downstream useMemo
      caches (target-options + filtered-pipelines list).
2026-07-07 10:49:40 +02:00
maziggy 90a7d68d4a fix(windows): bundle vcruntime140_1.dll so greenlet loads on fresh Win10 (#2474)
A clean Windows 10 install crashed on startup: init_db() -> SQLAlchemy async
engine -> greenlet failed with "DLL load failed while importing _greenlet:
The specified module could not be found", so uvicorn never bound :8000 and the
dashboard refused all connections while the NSSM service still showed running.

greenlet's _greenlet.pyd is C++ and needs vcruntime140_1.dll, which the
python.org embeddable distribution does not ship (it includes only
vcruntime140.dll, enough for the pure-C python313.dll). Machines with the VC++
2015-2022 redistributable already installed have the DLL in System32, which
masked the bug in testing.

Stage vcruntime140_1.dll and msvcp140.dll next to python.exe at build time,
from a vendored copy or the runner's System32, failing loudly if absent. The
Inno Setup [Files] step already copies staging\python\* recursively.
2026-07-07 07:50:08 +02:00
maziggy af867c0392 fix(vp): populate bind-interface list on macOS (route non-Linux to psutil)
get_network_interfaces() only sent Windows to the psutil path; macOS fell into
the Linux ioctl branch, whose SIOCGIFADDR/SIOCGIFNETMASK ioctls are Linux-only.
macOS/BSD have fcntl but different ioctl numbers, so every call raised OSError
and the function returned an empty list — the VP bind-interface dropdown showed
nothing. Route all non-Linux platforms through the cross-platform psutil path.
2026-07-06 13:03:22 +02:00
maziggy 2527a9820d fix(install): make macOS native install rootless (brew + venv permission errors)
macOS mixed root-only steps (default /opt path, sudo git clone) with steps
that must not run as root: brew refuses to run as root, and a root-owned
venv/node_modules can't be managed by the launchd agent. The installer now
refuses sudo on macOS, defaults to ~/bambuddy, and drops sudo from the
download/venv/frontend/env/dir steps. A --path under a root-owned parent still
works via a single elevate-and-chown. Linux (service user + systemd) unchanged.
2026-07-06 12:59:22 +02:00
maziggy 379765a46a fix(camera): transcode non-JPEG external snapshots to JPEG (#1902)
External cameras in HTTP-snapshot mode failed to load with a repeating
"connection lost" when the endpoint served PNG/WebP/BMP stills instead of
JPEG (common on IP cameras and reverse-proxied snapshot URLs). The URL
rendered fine directly in a browser, but Bambuddy's MJPEG stream wraps
every part in a hard-coded Content-Type: image/jpeg boundary, so a
non-JPEG payload labelled as JPEG made the browser reject the frame and
tear down the whole multipart/x-mixed-replace stream.

_capture_snapshot now transcodes non-JPEG stills to JPEG via OpenCV
(already a dependency). Genuine JPEG snapshots keep a byte-for-byte fast
path; truly undecodable responses (HTML error pages, auth redirects) fall
back to the previous raw-return behaviour with a single clear warning
instead of a per-frame log flood.
2026-07-06 07:54:30 +02:00
maziggy a82eeff483 fix(ui): restore missing per-user Notifications nav item (#1901)
The sidebar-ordering refactor in #1673 accidentally dropped the
`notifications` entry from `defaultNavItems` and its
`notifications:user_email` permission mapping, but kept the advanced-auth
visibility gate that references that id. With no nav entry the id never
enters the render set, so the /notifications page (route, page, and API
all intact) became reachable only by typing the URL — users could no
longer opt in/out of their own print email notifications from the menu.

Restore both the defaultNavItems entry and the permission gate, matching
the permission the user-email-preferences API actually requires
(notifications:user_email, held by both default groups). Add comments so
the entry isn't dropped again in a future sidebar refactor.
2026-07-06 07:38:44 +02:00
maziggy deb58b4ff1 Updated BACKERS 2026-07-05 10:45:05 +02:00
maziggy f3450e60fd Updated BACKERS 2026-07-05 10:44:31 +02:00
maziggy 7d4dfd5a7d fix(vp): stop uvloop from silently truncating VP FTP uploads (#1896)
Native (non-Docker) installs launched uvicorn without --loop asyncio, so
uvicorn[standard] auto-selected uvloop. uvloop's SSL layer drops
already-received but still-buffered data when the client closes the data
connection without a TLS close_notify while the reader is flow-control
paused on slow storage. cmd_STOR writes each chunk to disk inside the read
loop, so a slow consumer falls behind, the tail is lost, read() returns a
clean EOF, and the loop exits with no exception -- the server acked 226 for
a file it truncated itself, then archived, queued, and forwarded the corrupt
3MF to the real printer.

Fix in two independent layers:

1. Remove the trigger: add --loop asyncio to every native launch path,
   matching the Dockerfile -- deploy/bambuddy.service, install/install.sh
   (systemd + launchd), spoolbuddy/install/install.sh, the Windows NSSM
   service, README, CONTRIBUTING dev command.

2. Defense in depth (loop-independent): cmd_STOR now validates that a
   received .3mf opens as a ZIP (reads the central directory, no
   decompression) before replying 226. A truncated/corrupt file is dropped
   and answered with 426, and on_file_received never runs -- so a broken
   upload surfaces as an immediate slicer-side send error instead of being
   archived and pushed to the printer. Scoped to .3mf; other filetypes pass
   through unchanged.
2026-07-05 10:32:13 +02:00
maziggy 168d9d8f8e fix(auth): let API keys manage projects via new can_manage_projects scope (#1893)
PROJECTS_CREATE/UPDATE/DELETE were in _APIKEY_DENIED_PERMISSIONS with no
entry in _APIKEY_SCOPE_BY_PERMISSION, so every project mutation returned a
generic 403 for any API key regardless of granted permissions -- the same
regression class as archives (#1888) and library (#1832).

Add a per-key can_manage_projects scope. Project routes gate on plain
PROJECTS_* (no OWN/ALL split), so all three CRUD permissions map to the one
scope; membership edits (add-archives) gate on PROJECTS_UPDATE and are
covered. PROJECTS_READ is unchanged (already under can_read_status).

Column defaults TRUE for new keys; existing rows backfill to FALSE so the
upgrade never silently widens scope. Migration is BOOLEAN (SQLite + Postgres
safe), verified on fresh SQLite and Postgres 17. Bundled SpoolBuddy kiosk key
set to False. Settings API-key UI gets a Manage Projects toggle + Projects
badge; 11-locale i18n. RBAC scope matrix + drift guards extended.
2026-07-05 09:58:16 +02:00
maziggy 53ae5fb620 fix(drying): don't stop a running AMS dry on an unreliable humidity re-check (#1892)
Auto-drying stopped manually started (and pre-restart) AMS drying cycles
after exactly 30 minutes. The already-drying branch in _check_auto_drying()
applied a humidity-based auto-stop despite its own "track but don't stop"
comment, and the humidity re-check is unreliable: RH drops steeply in heated
air, so the sensor reads ~15-20% within minutes of the dryer starting even
with saturated filament. humidity <= threshold was thus effectively always
true, and the _min_drying_seconds=1800 floor pinned the stop to the 30-minute
mark. This also truncated Bambuddy's own preset-duration dries.

Remove the humidity-based early-stop entirely: a running dry now runs to its
configured duration (firmware stops it). Scheduling stops (print priority,
queue no longer needing the dry) are unchanged via _stop_drying(). Drop the
now-unused _min_drying_seconds.
2026-07-05 09:32:02 +02:00
maziggy e9cddc544a fix(websocket): stop the ws-token reconnect loop on auth failure
After the GHSA-r2qv gate (b7d7c825), /api/v1/ws needs a token from
POST /api/v1/auth/ws-token (Permission.WEBSOCKET_CONNECT). When the mint
failed, useWebSocket swallowed the error, opened a tokenless socket, the
server closed it 4401, and ws.onclose rescheduled connect() every 3s -
an endless loop that hammered /auth/ws-token. The dominant trigger is a
validly-logged-in user whose group lacks WEBSOCKET_CONNECT (mint returns
403). A secondary leak: the unmount-triggered onclose could schedule a
post-unmount reconnect.

Classify the mint failure: 401 (JWT expired; request() already clears it
and dispatches auth:expired) or 403 (valid session, missing permission;
degrade to REST polling) now stop the hook - no tokenless socket, no
reconnect. A 4401 close is terminal. Network/5xx still reconnect. A
disposedRef set in cleanup before close() prevents the unmount-race
reconnect. Same 401/403 no-open guard applied to StreamOverlayPage.

Also surface a one-line hint under the WebSocket permission in the group
editor (all 11 locales) explaining that live updates need it and fall
back to polling without it - rather than auto-granting the permission,
which would partly undo the GHSA-r2qv gate.
2026-07-05 09:12:42 +02:00
maziggy 646a8b13fd fix(auth): don't discard a valid stored token on a transient load-time error (#1889)
On mount, AuthContext.checkAuthStatus restores the persisted "Remember Me"
token from localStorage and validates it via GET /auth/me. The catch around
that call cleared the token on ANY failure, not just a definitive 401
invalid-token — so a brief backend-not-ready or reverse-proxy hiccup during
page load (plausible right after a container restart, e.g. on Unraid) would
delete a still-valid token. Because the token was deleted, a reload couldn't
recover it and the user was bounced to the login screen.

Token validation now retries transient failures (up to 3 attempts with short
backoff) and only discards the token on a definitive 401 — which request()
already handles (clears the token and dispatches auth:expired). Transient /
5xx / network errors leave the persisted token intact so the session survives
a slow load. "Remember Me" stays client-storage only; it does not extend the
server-side JWT lifetime (session_max_hours, default 24h).

Adds AuthContext tests: transient /auth/me failure keeps the token, a
definitive 401 clears it, and a valid token loads the user. Rebuilt frontend
bundle.
2026-07-03 08:57:20 +02:00
maziggy d568307eac fix(smart-plug): don't cut power when a print restarts, honor per-plug cooldown setting (#1890)
The print-queue "auto off after this job" trigger used a second, inline
auto-off implementation (main.py, print_scheduler.py, print_queue.py)
that hardcoded wait_for_cooldown(50C, 600s) — ignoring each plug's
configured off_delay_mode / off_delay_minutes / off_temp_threshold — and
ignored the return value, powering off on the 600s timeout regardless of
print state. A print that failed and was reprinted from the touchscreen
got its power cut mid-print. The inline tasks were also uncancellable, so
a reprint couldn't abort a pending off.

Consolidate all three into SmartPlugManager.schedule_off_after_queue_job,
which schedules via the plug's configured strategy (shared with
on_print_complete through _schedule_off_per_mode) and is cancellable via
_pending_off. Add printer_manager.is_print_active() and guard the actual
power-off in _delayed_off and _temp_based_off so no path cuts power on a
loaded print. Move the on_print_start cancellation ahead of the auto_on
gate so a reprint always aborts a pending off.
2026-07-03 08:32:51 +02:00
maziggy 6358e9544e fix(auth): allow API keys to delete/edit archives via new can_manage_archives scope (#1888)
DELETE /api/v1/archives/{id} rejected every API key with 403
"API keys cannot be used for administrative operations", regardless of
the print's owner or the key's scopes. ARCHIVES_DELETE_ALL/_OWN (and the
create/update variants) were on the denylist and absent from the scope
allowlist, so require_ownership_permission fell through to the generic
admin-denied 403 — the whole archive-management surface was unreachable
for API keys. Same regression class as the #1832 library/maintenance
carve-outs.

Add a can_manage_archives per-key scope: ARCHIVES_CREATE, ARCHIVES_
UPDATE_OWN/_ALL and ARCHIVES_DELETE_OWN/_ALL move from the denylist to
the allowlist under it (OWN and ALL fold into the same scope, matching
can_manage_library). ARCHIVES_PURGE stays admin-only — it drops the
print's Quick Stats contribution, mirroring LIBRARY_PURGE. Column
defaults TRUE for UI-created keys; existing rows backfill to FALSE so the
upgrade never silently widens scope. Bundled SpoolBuddy kiosk key stays
minimally scoped (False). Migration is dialect-agnostic and verified on
fresh SQLite and Postgres 17.

Adds the Settings API-key toggle + badge (11-locale i18n) and extends the
RBAC scope matrix to cover all five archive-management permissions.
2026-07-03 08:01:54 +02:00
maziggy b91be51208 Updated BACKERS 2026-07-03 07:44:32 +02:00
maziggy 0452b25750 Updated BACKERS 2026-07-03 07:44:00 +02:00