Commit Graph
19 Commits
Author SHA1 Message Date
maziggy 09d8e7d682 Fix external camera not used for snapshot + stream dropping (#325)
The snapshot endpoint always used the internal printer camera even when
an external camera was configured. Now checks for external camera first,
matching the stream endpoint pattern. Also added retry logic (3 attempts,
2s delay) to MJPEG and RTSP stream generators so they reconnect on
timeout instead of silently ending the stream.
2026-02-11 07:09:39 +01:00
maziggy 5b0a985da2 Add explanatory comments to 265 empty except blocks
CodeQL flags except blocks where `pass` has no comment explaining
why the exception is silently ignored (py/empty-except rule).

Added context-specific comments to all 265 instances across 31 files:
- database.py (~112): ALTER TABLE migrations — "Already applied"
- archive/library/3MF parsing (~64): "Skip unparseable metadata"
- virtual_printer network cleanup (~32): "Best-effort socket cleanup"
- discovery/SSDP (~13): "SO_REUSEPORT not available" / socket cleanup
- bambu_ftp/mqtt (~13): FTP cleanup, JSON decode, signal parsing
- remaining routes/services (~31): context-specific comments
2026-02-06 11:58:38 +01:00
maziggy 53bd4fadb3 Fix safe security findings: hashlib, log injection, broad excepts
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
  hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
  55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
  OperationalError for DB migrations, OSError for network/file cleanup,
  (OSError, ftplib.error_reply) for FTP, and targeted tuples for
  ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
  re-raise patterns)
2026-02-06 11:37:59 +01:00
maziggy 3fa9ed2b91 Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.

Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
  archives, projects, settings, api_keys, groups, cloud, github_backup,
  support, notifications, notification_templates, maintenance, filaments,
  external_links, smart_plugs, discovery, firmware, kprofiles, camera,
  ams_history, pending_uploads, updates, spoolman, system, print_queue,
  printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
  streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)

Fixes: CVE-2026-25505
2026-02-03 08:44:07 +01:00
maziggy c937e6781b Improved docker tests 2026-01-30 13:54:20 +01:00
maziggy 9d6164ab1c Add USB camera support (V4L2)
- Add USB camera type to external camera service
- Auto-detect available V4L2 devices on Linux
- New API endpoint: GET /api/v1/printers/usb-cameras
- Use ffmpeg for USB camera capture and streaming
- Add "USB Camera (V4L2)" option in Settings UI
- Debounce camera URL input to avoid saving on every keystroke

Closes #143
2026-01-27 06:40:14 +01:00
maziggy 888891fdc6 Add build plate empty detection feature
Automatically detect if objects are on the build plate before printing
and pause the print immediately if detected.

Features:
- Per-printer toggle to enable/disable plate detection
- Multi-reference calibration: store up to 5 reference images per printer
  for different plate types (textured, smooth, high-temp, etc.)
- Automatic print pause when objects detected at print start
- Push notification and WebSocket alert when print is paused
- ROI (Region of Interest) calibration UI with sliders to adjust
  detection area
- Reference management: view thumbnails, add labels, delete references
- Works with both built-in and external cameras
- Uses buffered camera frames when stream is active (no blocking)
- Split button UI: main button opens modal, chevron toggles on/off
- Green visual indicator when plate detection is enabled
- Included in backup/restore
2026-01-26 13:04:29 +01:00
maziggy 691fb133b7 Add external network camera support for printers
Add support for external network cameras (MJPEG, RTSP, HTTP snapshot)
that replace a printer's built-in camera when configured.

Features:
- Live streaming on printers page (replaces built-in camera)
- Finish photo capture from external camera on print complete
- Layer-based timelapse: captures frame on each layer change,
  stitches to MP4 video on print completion

Backend changes:
- Add external_camera_url, external_camera_type, external_camera_enabled
  fields to Printer model with database migration
- New external_camera.py service: MJPEG/RTSP/snapshot frame capture,
  connection testing, MJPEG stream generation
- New layer_timelapse.py service: TimelapseSession management,
  layer-by-layer frame capture, ffmpeg video stitching
- Add on_layer_change callback to MQTT client and printer manager
- Update camera routes with external camera streaming and tracking
- Update print lifecycle hooks for timelapse start/stitch/cancel
- Add external camera fields to backup/restore
- Rate limiting for external camera streams (prevents browser freeze)

Frontend changes:
- Add external camera configuration UI in Settings > Camera
- Per-printer enable toggle, URL input, type selector, test button
- Toast notification on save

Closes #143
2026-01-24 09:58:45 +01:00
maziggy 8639f39028 Add resizable printer cards and Queue Only mode
Features:
  - Resizable printer cards (S/M/L/XL) with toolbar controls on Printers page
  - Queue Only mode for staging prints without automatic scheduling
    - "Queue Only" option in add/edit queue modals
    - Purple "Staged" badge and Play button to release to queue
    - manual_start field in database with migration

  Fixes:
  - Improved camera stream stuck detection with automatic reconnection

  Tests:
  - Added 16 integration tests for print queue API endpoints
2026-01-04 09:10:06 +01:00
maziggy 3c336b0da2 Fixed bug in camera stream stuck detection 2026-01-03 11:03:00 +01:00
maziggy a308248880 Camera stream is now reconnecting if stream stucks 2026-01-03 10:51:37 +01:00
maziggy 530a7a4608 - Fix camera stream stopping after a few minutes
- Backend:
    - Increase ffmpeg stdout read timeout from 10s to 30s
    - Add ffmpeg RTSP stability options: -timeout, -buffer_size, -max_delay
  - Frontend:
    - Add auto-reconnection with exponential backoff (2s→30s max)
    - Show reconnection UI with countdown and attempt counter
    - Maximum 5 reconnection attempts before showing error
    - "Reconnect now" button to skip countdown
    - Reset reconnection state on manual refresh or mode switch
2025-12-28 13:16:14 +01:00
maziggy 11a6bb282a Key Discovery
A1/P1 printers don't support RTSP - they use a custom chamber image protocol on port 6000:
  - SSL/TLS connection
  - 80-byte binary auth payload (magic + "bblp" + access code)
  - 16-byte header with payload size + JPEG data

  Changes Made

  backend/app/services/camera.py

  - Added supports_rtsp() - detects X1/H2/P2 (RTSP) vs A1/P1 (chamber image)
  - Added is_chamber_image_model() - inverse check
  - Added _create_chamber_auth_payload() - builds 80-byte auth
  - Added _create_ssl_context() - SSL for self-signed certs
  - Added read_chamber_image_frame() - single frame capture
  - Added generate_chamber_image_stream() - persistent connection
  - Added read_next_chamber_frame() - read from stream
  - Updated capture_camera_frame() - uses correct protocol per model

  backend/app/api/routes/camera.py

  - Added generate_chamber_mjpeg_stream() - MJPEG from chamber protocol
  - Renamed generate_mjpeg_stream() → generate_rtsp_mjpeg_stream()
  - Updated camera_stream endpoint - chooses protocol based on model
  - Updated stop_camera_stream - cleans up both stream types
  - Added tracking for _active_chamber_streams

  Protocol Matrix

  | Model                       | Protocol      | Port |
  |-----------------------------|---------------|------|
  | X1, X1C, X1E, H2C, H2D, P2S | RTSP          | 322  |
  | A1, A1MINI, P1P, P1S        | Chamber Image | 6000 |
2025-12-25 07:44:53 +01:00
maziggy 01989b7182 - Fix A1/P1 camera streaming with extended timeouts and lower FPS cap
- Removed deprecated -stimeout option (renamed to -timeout in ffmpeg 5.0+).
2025-12-24 13:43:35 +01:00
maziggy 7622d2ae5c - Fix total print hours calculation in set_total_hours to include all
prints (not just completed), matching get_printer_total_hours behavior
  - Add option to keep or delete archives when deleting a printer
  - Custom maintenance types no longer auto-assign to all printers
  - Add UI to manually assign/remove custom maintenance types per printer
  - Add backend endpoints for assigning types to printers and removing items
  - Exclude static/assets from large file pre-commit check
  - Fix A1/P1 camera streaming with extended timeouts and lower FPS cap
2025-12-24 08:41:23 +01:00
maziggyandClaude Opus 4.5 a7319f0e70 Fix browser freeze on print completion with camera stream open
Root cause: When a print completed with the camera stream popup open,
spawning a second ffmpeg process for finish photo capture caused a
conflict that froze the browser tab and video window.

Solution: Buffer the last frame from active camera streams. When
capturing finish photo, use the buffered frame if a stream is active
instead of spawning a new ffmpeg process.

Backend changes:
- camera.py: Added _last_frames buffer and get_buffered_frame() helper
- main.py: Photo capture uses buffered frame when stream is active
- main.py: Moved slow operations to background tasks (energy calc,
  photo capture, smart plug, notifications, maintenance)
- archive.py: Fixed sync file write blocking event loop (asyncio.to_thread)
- printers.py: Added debug endpoint to simulate print completion

Frontend changes:
- useWebSocket.ts: Throttled printer status updates (100ms) to prevent
  UI overload from rapid WebSocket messages
- useWebSocket.ts: Debounced archive invalidations (3s) to prevent
  cascade of re-renders on print completion
- useWebSocket.test.ts: Updated tests for throttled/debounced handlers

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-16 18:45:03 +01:00
maziggy 1a4f146dd0 Notifications:
- Separate AMS and AMS-HT notification switches (one per device type)
  - Fix notification variables not showing (duration, filament, estimated_time)
  - Add fallback values for empty notification variables ("Unknown" instead of blank)

  Settings:
  - Fix API keys badge count only showing after visiting tab
  - Move External Links card to third column above Updates
  - Add Release Notes modal for viewing full notes before updating

  Statistics:
  - Fix filament usage trends not showing (wrong API parameters)
  - Move dashboard controls (Hidden, Reset Layout) to header row
  - Remove duplicate Reset Layout button

  Camera:
  - Fix ffmpeg processes not killed when closing webcam window
  - Add /camera/stop endpoint with POST support for sendBeacon
  - Track active streams and proper cleanup on disconnect
2025-12-12 09:18:59 +01:00
maziggy e688c35719 sync 2025-12-07 14:29:54 +00:00
Martin Ziegler 37caef239f Started to implement full printer control 2025-12-01 16:25:54 +01:00