Commit Graph
1801 Commits
Author SHA1 Message Date
maziggy deecc8b7dc Updated .github/workflows/security.yml 2026-03-20 11:07:08 +01:00
maziggy f6a85031e6 [Debug] Virtual Printer proxy: diagnostic port probing for A1 (#757)
A1/A1 Mini printers fail to connect through VP proxy mode while
    X1C/P2S/H2C work fine with identical transparent TCP proxy code.
    Root cause unknown — the proxy is model-agnostic, so the failure
    suggests BambuStudio uses a different connection flow for A1 models
    that hits ports we don't proxy.

    Add diagnostic probe listeners on ports 21, 80, and 443 on each
    proxy VP's dedicated bind IP. If the slicer connects to any of
    these un-proxied ports, a WARNING is logged so debug logs and
    tcpdump can reveal what's missing.
2026-03-20 10:52:42 +01:00
maziggy 332a7c6ac8 [Fix] Virtual Printer proxy: transparent TCP for X1C/X1 compatibility (#757)
The closed-source bambu_networking DLL validates TLS connection parameters
  and rejects connections where the certificate doesn't match the printer's
  real BBL CA certificate. The TLS-terminating proxy presented Bambuddy's
  own certificate, causing X1C/X1 prints to silently fail after verify_job.

  Switch to transparent TCP proxying for FTP, FileTransfer, Camera, and FTP
  data — only MQTT remains TLS-terminated (required for IP rewriting). The
  slicer now gets end-to-end TLS directly with the printer's real certificate.

  Changes:
  - SlicerProxyManager uses TCPProxy for FTP (990), FileTransfer (6000),
    Camera (322), and pre-listens on FTP data ports (50000-50100)
  - Only MQTT (8883) uses TLSProxy for IP rewriting
  - Remove debug logging from MQTT and FTP proxy code
  - Fix install.sh missing AmbientCapabilities=CAP_NET_BIND_SERVICE
  - Update module docstring, migration docs, README proxy description
  - Add tests verifying transparent proxy architecture
2026-03-19 15:43:11 +01:00
maziggy 94134e1861 Updated docker-publish-daily-beta.sh 2026-03-19 11:38:20 +01:00
maziggy 7a1eed2b17 [Docs] Update VP proxy docs, ports, and diagram for #757
- Add ports 6000 (file transfer) and 322 (RTSP camera) to Dockerfile
    EXPOSE and docker-compose.yml bridge mode port mapping
  - Update migration doc with new proxy mode port requirements
  - Regenerate proxy-mode-diagram.png with all proxied ports
2026-03-19 11:29:59 +01:00
maziggy 1b1f58fc88 [Fix] Virtual Printer proxy mode fails on isolated networks (#757)
When the slicer and printer are on different VLANs, Bambu Studio could
  not send prints through the proxy because the printer's real IP leaked
  through MQTT payloads, the bind protocol forwarded the real printer's
  identity, file transfer and camera ports were not proxied, and FTP
  data connections raced the TLS handshake on zero-byte uploads.

  - Rewrite IP addresses in MQTT PUBLISH payloads (string + integer)
    with proper packet framing and cross-chunk buffering
  - Respond to bind/detect with VP identity via BindServer
  - Add TLS proxies for port 6000 (file transfer) and 322 (RTSP camera)
  - Buffer slicer FTP data during printer connection setup
  - Advertise configured VP name in SSDP proxy
  - Add cross-subnet SSDP wildcard listener for VPN setups
  - Register UserEmailPreference model in models/__init__.py
  - Add 11 unit tests for MQTT rewrite, IP conversion, SSDP name
2026-03-19 11:10:22 +01:00
maziggy 0b2b81a34d [Fix] Virtual Printer proxy mode fails on isolated networks (#757)
When the slicer and printer are on different VLANs, Bambu Studio could
  not send prints through the proxy because the printer's real IP leaked
  through MQTT payloads, the bind protocol forwarded the real printer's
  identity, the port 6000 file transfer tunnel was not proxied, and FTP
  data connections raced the TLS handshake on zero-byte uploads.

  - Rewrite IP addresses in MQTT PUBLISH payloads (string + integer)
    with proper packet framing and cross-chunk buffering
  - Respond to bind/detect with VP identity via BindServer
  - Add TLS proxy for port 6000 (file transfer tunnel)
  - Buffer slicer FTP data during printer connection setup
  - Advertise configured VP name in SSDP proxy
  - Add cross-subnet SSDP wildcard listener for VPN setups
  - Register UserEmailPreference model in models/__init__.py
  - Add 11 unit tests for MQTT rewrite, IP conversion, SSDP name
2026-03-19 11:03:10 +01:00
maziggy dfb995bfe9 [Fix] Remove incorrect "Lubricate Carbon Rods" maintenance task (#755)
Carbon rods use plain bearings — lubricating them degrades print quality.
  Removed the lubrication task from defaults; only "Clean Carbon Rods"
  remains. Existing entries are auto-removed on next startup via
  ensure_default_types(). Updated wiki link mapping and tests.
2026-03-19 08:40:24 +01:00
maziggy c5a0651172 Fix AMS slot search showing unrelated filament profiles (#681)
When searching for a non-existent profile in the AMS slot config modal,
  presets matching the current slot's tray_info_idx bypassed the search
  filter, showing e.g. all "Generic PLA" variants instead of no results.
  Narrow the search bypass to only the exact saved preset — the broader
  trayIdx match still bypasses the model filter as intended.
2026-03-19 08:29:03 +01:00
maziggy 00bc1e214a Add print command response verification for #737
After sending a print command via MQTT, monitor whether the printer's
  gcode_state changes within 15 seconds. If not, log a warning visible in
  support packages. Addresses silent command drops observed on P1S firmware
  01.09.01.00 where the printer ignores project_file commands while
  continuing to send status updates.
2026-03-19 08:14:05 +01:00
maziggy da61a1caa5 Updated CHANGELOG 2026-03-18 18:13:59 +01:00
maziggy 0e712c72a1 [Feature] Add quick print speed control to printer card (#256)
Add a speed control badge to the printer monitoring card controls row
  that lets users switch between Silent (50%), Standard (100%), Sport
  (124%), and Ludicrous (166%) presets during active prints. The badge
  displays a gauge icon with the current speed percentage, always visible
  but disabled when idle. Includes backend endpoint, optimistic UI
  updates, i18n for all 7 locales, and full test coverage.
v0.2.3b1-daily.20260318
2026-03-18 11:13:27 +01:00
maziggy 96966cd3d2 [Feature] Add spool name column and filter to filament inventory (#740)
Add a "Spool" column to the filament inventory table that displays
  the spool catalog entry name associated with each spool. The column
  is hidden by default and can be enabled via the column visibility
  menu. Also add a spool name filter dropdown next to the brand filter,
  shown when any spools have catalog entries assigned. No backend
  changes needed — catalog data is fetched and joined on the frontend.
2026-03-18 10:34:15 +01:00
maziggy e149fa23d4 [Fix] Ntfy notifications fail with non-ASCII printer names (#742)
Ntfy notifications with camera snapshots failed when the printer name
  or filename contained non-ASCII characters. httpx enforces ASCII
  encoding on string header values, but the Title and Message headers
  can contain printer names with accented letters or CJK characters.
  Encode these header values as UTF-8 bytes, which ntfy handles correctly.

  Test notifications were unaffected because they use a hardcoded ASCII
  title and no image attachment.
2026-03-18 09:39:46 +01:00
maziggy 82d329d85c [Fix] Virtual Printer FTP routed to wrong VP with different access codes (#735)
When running multiple virtual printers with different access codes on
  separate bind IPs, FTP connections were always routed to the wrong VP.

  Root cause: the iptables REDIRECT rule (990→9990) rewrites the
  destination IP to the incoming interface's primary address. With Linux's
  weak host model (arp_filter=0), packets for secondary IPs arrive on the
  primary interface, and REDIRECT sends them all to the first VP's FTP
  server. MQTT was unaffected because port 8883 had no redirect.

  Fix: FTP server now binds directly to port 990 (standard implicit FTPS),
  eliminating the iptables redirect entirely. Requires CAP_NET_BIND_SERVICE
  (already set in the systemd service file and Docker image).

  Also removed a global asyncio set_exception_handler() in the MQTT server
  that was overwritten by each VP instance, causing spurious "Unhandled
  exception in client_connected_cb" errors on startup.

  Changes:
  - FTP_PORT: 9990 → 990 (ftp_server.py)
  - Removed set_exception_handler() from MQTT server
  - Updated Dockerfile, docker-compose.yml port mappings
  - Deprecated --redirect-990 in install script
  - Updated wiki: removed iptables instructions for all platforms
  - Added migration guide (docs/migration-vp-ftp-port.md)
  - Added unit tests for port constant and no-global-state invariant
2026-03-18 09:04:31 +01:00
maziggy dcdebef9a8 [Fix] Spool assignment UI shows wrong filament preset name (#681)
After assigning a spool to an AMS slot, the Bambuddy UI could show the
  wrong filament preset (e.g. "Bambu PLA Matte" instead of "Bambu PLA
  Silk") even though the printer was configured correctly.

  Two bugs:
  1. AssignSpoolModal (PrintersPage hover card path) never saved the slot
     preset mapping to the DB, so the display fell back to the old/stale
     mapping from a previous manual configuration.
  2. AssignToAmsModal (SpoolBuddy path) constructed the preset name from
     spool.material + spool.subtype ("PLA Silk") instead of using the
     authoritative spool.slicer_filament_name ("Bambu PLA Silk").

  Fix: the backend now saves the slot preset mapping in assign_spool()
  after successful MQTT configuration, using slicer_filament_name as the
  display name. This covers both frontend paths and ensures the correct
  name is always stored.
2026-03-18 08:12:08 +01:00
Keybored b12c51189d [Feature] Add Total cost to Projects (#733)
[Feature] Add Total cost to Projects (#733)
2026-03-18 07:52:59 +01:00
maziggy 1e7173fae6 Updated CONTRIBUTING.md 2026-03-18 07:32:31 +01:00
maziggy b2335a2592 Added VP name prefix (e.g. [Virtual - X1C]) to all FTP and MQTT
log lines so issues can be traced to a specific virtual printer, and
  demoted FTP protocol chatter from info to debug.
2026-03-17 17:36:47 +01:00
maziggy 3d09fe0cd9 [Security] Remove plaintext password logging from VP FTP server
FTP PASS commands were logged with the plaintext password visible in
  log files. Since support packages include logs and are shared publicly
  on GitHub issues, this exposed user access codes. Now redacted as
  PASS ********.
2026-03-17 17:26:10 +01:00
maziggy dbe86968b0 [Fix] Print complete notification not firing (#736)
Print complete notifications were chained behind the finish photo
  capture task with no timeout. If photo capture hung, the notification
  would never send. Added a 45-second timeout so notifications always
  fire regardless of photo outcome.

  Also added diagnostic logging to MQTT state detection and upgraded
  notification error logging to include stack traces for easier
  debugging.
2026-03-17 17:00:32 +01:00
maziggy 6be5fa6632 [Fix] Camera window overlapping modals (#738)
Floating camera viewer used z-50, same as all modals, causing it to
  render on top of dialogs like Assign Spool. Lowered to z-40 so modals
  always stack above the camera window.
2026-03-17 16:40:16 +01:00
maziggy 4f617c21e1 [Fix] X1C Virtual Printer not accepting sends (#735)
X1C and X1 virtual printers used legacy SSDP model codes
  (3DPrinter-X1-Carbon, 3DPrinter-X1) that BambuStudio doesn't
  recognize, causing "incompatible printer preset" errors when
  sending prints. Changed to the correct codes (BL-P001, BL-P002)
  that real printers report via SSDP.

  Also fixed proxy mode auto-inherit storing printer display names
  (e.g. "X1C") instead of SSDP codes, by adding a resolution layer
  that maps display names to model codes.

  DB migration auto-converts existing VPs on startup.
2026-03-17 16:25:31 +01:00
maziggy fe3c1983af Add camera image rotation option (#672)
Per-printer camera rotation (0°/90°/180°/270°) for cameras mounted
  in portrait or upside-down. CSS rotation for live views, Pillow
  rotation for notification snapshots. Setting visible in external
  camera config when enabled.
v0.2.3b1-daily.20260317
2026-03-17 13:59:01 +01:00
maziggy aeae5cfa23 Reformat AMS drying presets table (#732)
Group columns by AMS type (AMS 2 Pro, AMS-HT) with inline °C and h
  unit labels next to each input instead of separate column headers.
2026-03-17 13:36:39 +01:00
maziggy 98cb88a06b Fix beta updates shown when disabled (#731)
Daily beta build tags (e.g. v0.2.3b1-daily.20260316) were not detected
  as prereleases because parse_version() only checked the last
  dot-separated segment for letters. The daily date suffix is purely
  numeric, so it passed the stable release check. Now checks the entire
  version string for prerelease markers.
2026-03-17 13:20:25 +01:00
maziggy a4006408a2 Fix white filament color swatches invisible in light theme (#726)
Changed filament color circle borders from border-white/20 to
  border-black/20 across all views so white spools are distinguishable
  against light backgrounds.
2026-03-17 13:08:04 +01:00
maziggy 11610a5b48 Compact assign spool modal grid layout (#725)
- Change spool list from vertical to 3-column grid (2-col on small screens)
  - Widen modal from max-w-md to max-w-2xl
  - Increase scroll area from max-h-64 to max-h-96
  - Show compact cards with name, color dot, and remaining/total weight
2026-03-17 12:40:38 +01:00
maziggy 7ab9b3e39f Fix mobile sidebar scroll, lint errors, and add tests for (#724)
- Fix mobile sidebar not scrollable when nav items exceed viewport
2026-03-17 12:31:11 +01:00
maziggy a6d307d739 Post work PR #693
Add tests, docs, and ruff fixes for per-user email notifications

  - Fix missing timezone import in email_service.py (F821)
  - Fix unused lambda arg in main.py asyncio done_callback (ARG005)
  - Fix E302 blank line spacing for mark_printer_stopped_by_user
  - Fix F821/UP037 forward reference in user_email_pref model
  - Fix SettingsPage test for duplicate "Notifications" text
  - Add backend unit tests for permissions, schemas, and templates
  - Add backend integration tests for user-notifications API
  - Add frontend tests for NotificationsPage
  - Add user_email_pref model import to test conftest
  - Update CHANGELOG and README
2026-03-17 12:24:36 +01:00
Thomas Rambach 9562d66b6b Feature: Advanced Authentication User Email Notifications (#693)
Feature: Advanced Authentication User Email Notifications (#693)
2026-03-17 12:01:18 +01:00
maziggy 5a8dd8cd69 sync v0.2.3b1-daily.20260316 2026-03-16 15:49:49 +01:00
Dakota G ac7cfe2930 [Fix]: Send Bambu RFID Tags to Spoolman, Allow Unlink in Manual Mode, Stop Location Clearing for Generic Spools (#719)
[Fix]: Send Bambu RFID Tags to Spoolman, Allow Unlink in Manual Mode, Stop Location Clearing for Generic Spools (#719)
2026-03-16 15:45:06 +01:00
Keybored 92c3ce3993 [Feature] Rework Archive duplicates tagging (#718)
[Feature] Rework Archive duplicates tagging (#718)
2026-03-16 15:40:24 +01:00
Keybored 3ca91eb6d1 [Feature] Add material mismatch and insufficient filament checks (#720)
[Feature] Add material mismatch and insufficient filament checks (#720)
2026-03-16 15:30:36 +01:00
maziggy 446da087a0 Fix webhook notifications missing camera snapshot (#679)
Webhook providers did not include image data (e.g. camera snapshots
  from first layer complete notifications) even though other providers
  like Telegram, Pushover, and Discord already attached them. The webhook
  payload now includes a base64-encoded "image" field when a snapshot is
  available (generic format only, excluded from Slack format).
2026-03-16 15:10:39 +01:00
maziggy 105ed7b50a Updated .trivyignore 2026-03-16 13:38:17 +01:00
maziggy aa5df7a4ac Updated CHANGELOG.md 2026-03-16 13:30:24 +01:00
maziggy 63a905daf2 Bumped version 2026-03-16 12:46:25 +01:00
maziggy b889de91ba Allow spool assignment to empty AMS slots and fix profile label (#717)
Previously the "Assign Spool" button only appeared on configured slots,
  forcing users to manually configure first — redundant since assignment
  auto-configures the slot. Now shows on empty slots too. Also fixed the
  AMS hover card showing generic material type instead of the spool's
  slicer preset name after assignment.
2026-03-16 09:24:04 +01:00
maziggy a388ab791f Deleted broken install/start_bambuddy.bat 2026-03-15 16:50:49 +01:00
maziggy d9049e65b1 Updated CONTRIBUTING.md 2026-03-15 16:02:43 +01:00
maziggy fa6edfbcde Fix stored XSS vulnerabilities and unauthenticated auth toggle
- Sanitize project notes with DOMPurify before rendering via
    dangerouslySetInnerHTML (ProjectDetailPage.tsx)
  - Replace hand-rolled HTML sanitizer with DOMPurify in ProjectPageModal
    to prevent attribute injection via crafted 3MF href values
  - Block /api/v1/auth/setup when auth is already enabled to prevent
    unauthenticated clients from disabling authentication remotely
2026-03-15 15:31:49 +01:00
maziggy 0feed83ce4 Fix P2S camera TLS compatibility via OpenSSL proxy (#661)
The Debian ffmpeg package uses GnuTLS, whose hardened defaults reject
  TLS renegotiation and legacy ciphers that some Bambu printer firmwares
  (notably P2S) rely on — causing RTSP sessions to drop after a few
  seconds.

  Add a local TLS termination proxy (Python ssl/OpenSSL) that handles
  the TLS connection to the printer and exposes a plain RTSP port to
  ffmpeg. The proxy rewrites RTSP request-line URLs (rtsp://proxy →
  rtsps://printer) while preserving Authorization headers so Digest
  auth hashes remain valid.

  Also:
  - Reduce RTSP reconnect delay from 1.0s to 0.2s
  - Add ffmpeg fast-start flags (-probesize 32, -analyzeduration 0,
    -fflags nobuffer, -flags low_delay)
  - Fix external camera double rate-limiting causing choppy streams
  - Apply TLS proxy to external camera rtsps:// URLs and snapshot capture
  - Update orphan ffmpeg cleanup to match rtsp:// (proxied) URLs
  - Add unit tests for RTSP URL rewriting and proxy lifecycle
2026-03-15 11:52:32 +01:00
maziggy c5791e0b54 Fix spool assignment applying wrong filament profile (#681)
The Bambu Cloud API returns the base filament_id for versioned
  setting IDs (e.g. GFSL99 → GFL99 for all "Generic PLA" variants),
  so assigning a spool with a specific variant like "Generic PLA Silk"
  (GFSL99_01) would configure the AMS slot with the base "Generic PLA"
  profile (GFL99) instead of the correct one (GFL96).

  Added a post-resolution cross-check: if the resolved filament_id maps
  to a different name than the spool's stored preset name, reverse-lookup
  the correct filament_id from the built-in filament table.
2026-03-15 09:54:57 +01:00
Dakota G c52505cd3a [Fix]: Ensures AMS-HT devices are properly identified in Spoolman (#711)
[Fix]: Ensures AMS-HT devices are properly identified in Spoolman (#711)
2026-03-15 09:28:30 +01:00
maziggy bbc5ccb982 Library Upload Doesn't Show New File Until Page Reload ([#704](https://github.com/maziggy/bambuddy/issues/704)) — After uploading a file in the Library file manager, the file list didn't update until the user reloaded the browser. The upload endpoint used db.flush() instead of db.commit(), so the new row was only written to the database *after* the response was sent to the client. The frontend immediately refetched the file list upon receiving the response, but a new database session couldn't see the uncommitted row — resulting in stale data. Fixed by committing before the response is returned. Also fixed the same race condition in folder create, folder update, and file update endpoints. Reported by @shadowjig.
Printer File Manager Doesn't Auto-Refresh ([#704](https://github.com/maziggy/bambuddy/issues/704)) — The printer file manager (SD card browser) only fetched the file list once when opened. Files uploaded from BambuStudio/OrcaSlicer while the modal was open wouldn't appear until the user clicked the refresh button or reopened the modal. Now auto-refreshes every 30 seconds while open. Reported by @shadowjig.

Database Connection Pool Exhaustion Under Load ([#704](https://github.com/maziggy/bambuddy/issues/704)) — Background tasks (print scheduler FTP uploads, camera captures, notification sends, timelapse stitching) held database sessions open during slow network I/O, consuming connection pool slots for seconds at a time. With the default pool of 15 connections (size 5 + overflow 10), concurrent operations during print start/complete events could exhaust the pool, causing `QueuePool limit reached` errors and `greenlet_spawn` failures in RFID spool auto-assignment. Doubled the pool to 30 connections (size 10 + overflow 20). Reported by @shadowjig.
2026-03-15 09:15:18 +01:00
Dakota G 30b34bc255 [Fix]: Changes SMTP testing to use saved settings in the database (#710)
[Fix]: Changes SMTP testing to use saved settings in the database (#710)
2026-03-15 09:13:47 +01:00
maziggy 79f4a62308 Redact printer access codes from support bundle logs
RTSP stream URLs (rtsps://bblp:<code>@<ip>:322/...) were not covered
  by the credential sanitizer, leaking access codes in support bundles
  and bug report logs. Extended the URL regex to match rtsps:// and added
  access codes to the sensitive string collection for exact-match
  redaction in both export paths.
2026-03-15 08:42:17 +01:00
maziggy 5a8aa61f44 Bump PyJWT >=2.12.0 (CVE-2026-32597) and flatted >=3.4.0
PyJWT: fixes auth token handling vulnerability (direct dependency).
  flatted: fixes unbounded recursion DoS in parse() (transitive, ESLint only).
v0.2.2b4-daily.20260314
2026-03-14 15:47:25 +01:00