Swipe down from the top of the SpoolBuddy display to open a quick-access
menu for toggling printer smart plugs and managing the device (restart
daemon, restart browser, reboot, shutdown). All destructive actions
require confirmation.
Backend: new POST /spoolbuddy/devices/{id}/system/command endpoint
queuing reboot/shutdown/restart_daemon/restart_browser commands.
Daemon: handles commands via subprocess (sudo reboot, systemctl restart).
Frontend: SpoolBuddyQuickMenu component, swipe-down gesture detection,
i18n keys for all 7 locales.
Users can authenticate against an LDAP/AD server with configurable
server URL, bind DN, search base, and user filter. Supports StartTLS
and LDAPS — plaintext is not allowed. Both Active Directory (memberOf)
and POSIX groups (memberUid) are mapped to BamBuddy groups on each
login. Auto-provisioning creates local accounts on first LDAP login.
Local admin accounts remain as fallback when LDAP is unreachable.
Password management is disabled for LDAP users.
When auto_archive was disabled but the print was dispatched by BamBuddy
(queue/reprint), on_print_start discarded the expected print entry and
returned early. The archive was never promoted to _active_prints, so at
completion archive_id and ams_mapping were both None — all tracking paths
failed silently. Now detects expected prints before the auto-archive
early-return and falls through to the normal promotion path. Also injects
the stored ams_mapping into the usage tracker session for printers where
MQTT request topic subscription fails (P1S, A1).
Spool CRUD endpoints (create, bulk create, update, delete, archive,
restore) did not emit websocket events, so SpoolBuddy Dashboard and
other tabs relying on event-driven cache invalidation never refreshed.
All inventory mutation endpoints now broadcast an `inventory_changed`
websocket event. Frontend handles it by invalidating `inventory-spools`.
When multiple smart plugs were assigned to the same printer, only the
first plug's automation triggered. All automation paths (print start
auto-on, print complete auto-off, queue auto-off, scheduler power-on)
now iterate every plug linked to the printer. Also fix queue auto-off
hardcoded to Tasmota instead of using the correct service for the plug
type.
Queue status update (printing → completed) failed silently when SQLite
was locked by another writer, leaving ghost jobs permanently stuck in
printing status. Add run_with_retry() for SQLite lock retries and split
runtime tracker into per-printer commits to reduce lock hold time.
The dev mode probe (ams_filament_setting to ext slot) fired on every
auto-reconnect, which destabilized some firmware MQTT brokers (A1/P1)
causing a reconnect-probe-disconnect feedback loop. Now caches the
probe result across reconnects and only probes once on first connect,
with a 5s delay to let the session stabilize.
When auto-archive was off, archive_id was None at print completion so
the entire 3MF tracking path was skipped. AMS remain% fallback also
failed on printers reporting remain=-1. Now searches library files and
previous archives by filename to locate the 3MF without an archive,
and captures the AMS slot-to-tray mapping at print start so it's
available at completion regardless of archive state.
Per-model start/end G-code snippets configurable in Settings (Workflow
tab). Queue items get "Inject G-code" toggle — scheduler injects
snippets into a temp 3MF copy before FTP upload. Supports Farmloop,
SwapMod, AutoClear, Printflow 3D and similar bed-clearing systems.
Original files are never modified.
Usage tracking failed silently when FTP download failed (fallback archive
with no 3MF), when printing from external spool holder (VT tray not
iterated by AMS fallback), and notifications showed "Unknown" for time
and filament. Now resolves 3MF from library/previous archives, tracks
VT tray remain% deltas, enriches notifications with usage tracker
results, and captures print time from MQTT for fallback archives.
External folder scan now mirrors disk subfolder structure into the folder
tree instead of flattening all files into root. Hidden directories are
filtered, orphaned subfolders are cleaned up on rescan. Fixes#890.
File manager delete endpoints (folder, file, bulk) now commit before
returning the response — previously relied on post-response auto-commit,
causing a race where the frontend refetch arrived before the commit.
New dedicated MQTT methods, API endpoints, and UI buttons for
loading/unloading filament from the external spool holder without
requiring an AMS. Includes state guards to prevent load when filament
is already loaded and unload when nothing is loaded.
Add timeout and retry to the developer mode probe. After a keep-alive
timeout, paho auto-reconnects but the session can be half-broken: the
printer sends status but ignores commands. The probe had no recovery —
one unanswered probe permanently blocked retries. Now times out after
10s with one retry; two consecutive failures force-close the socket for
a clean reconnect.
Skip AMS remain% weight sync in on_ams_change while a print session is
active. The MQTT FINISH message triggers both the AMS weight sync (SET
from remain%) and the usage tracker (ADD from 3MF data) in the same
event loop cycle, causing double deduction. The active-session check is
snapshotted before any await to prevent a race with on_print_complete
popping the session during interleaved execution.
Camera snapshot, test, and plate detection endpoints created temporary
JPEG files with default 0644 permissions. Switch from NamedTemporaryFile
to mkstemp with explicit 0600 permissions.
Set X-Content-Type-Options, X-Frame-Options, and Referrer-Policy on all
responses. CSP omitted (React inline styles would require unsafe-inline,
negating protection). HSTS omitted (LAN app commonly accessed over HTTP).
An API key with printer_ids=[] was treated the same as null (global
access) due to a falsy check. Now None means global access and []
means no printer access. Added a startup migration to normalize any
existing [] rows to NULL so they retain their intended global access.
Also fixed the webhook /queue endpoint which used the same falsy
check, allowing []-scoped keys to see all printers.
The bug report endpoints (start-logging, stop-logging, submit) had no
authentication, allowing anyone on the network to enable debug logging,
retrieve sanitized system logs, and trigger bug report submissions when
auth was enabled. All three now require permission when auth is enabled:
start-logging requires settings:update, stop-logging and submit require
settings:read. Endpoints remain open when auth is disabled (default).
Archive upload endpoints used the client-supplied filename directly
in file paths, allowing an authenticated attacker to write files
outside the intended directory (e.g. ../../evil.3mf bypasses the
.3mf extension check). Added _safe_filename() helper that normalizes
backslashes and extracts the basename before constructing paths.
New SJF toggle badge on the queue page. When enabled, the scheduler
picks shorter print jobs before longer ones instead of FIFO. A
starvation guard flags jobs that get skipped once, moving them to
the front on the next cycle so long jobs can't be postponed indefinitely.
- Add print_time_seconds and been_jumped columns to PrintQueueItem
- Cache print duration from 3MF metadata at queue item creation
- SJF query: printer_id, target_model, been_jumped DESC, print_time_seconds ASC, position
- Mark jumped items in-memory after each print start
- Toggle badge on queue page header with live state indicator
- Frontend auto-sorts to match scheduler order when SJF enabled
- Settings schema, boolean parsing, and migration (SQLite + PostgreSQL)
- i18n badge keys for all 7 locales
- 10 integration tests for SJF ordering and starvation logic
- Wiki, website, README, and changelog updated
Move H2S from the drying-unsupported blocklist to the firmware-gated
list, requiring minimum firmware 01.02.00.00 (released end of March
2026). Both remote AMS drying and queue auto-drying now work on H2S.
Display the active database backend (SQLite or PostgreSQL) and its
version in the Database section of the System Info page. SQLite queries
sqlite_version(), PostgreSQL queries SELECT version() and
pg_database_size(). Helps users verify which database is in use.
Bambuddy can now use an external PostgreSQL database via the
DATABASE_URL environment variable. SQLite remains the default.
Dialect-aware helpers handle upserts, PRAGMAs, FTS (FTS5 vs
tsvector+GIN), backup/restore, and health checks. All migration
blocks use savepoints to prevent Postgres transaction poisoning.
Backups are always portable SQLite format regardless of backend.
Cross-database restore imports SQLite backups into PostgreSQL
with automatic boolean/datetime conversion, NOT NULL default
filling, and FK constraint handling.
REST/Webhook smart plugs can now fetch power and energy data from
individual URLs instead of requiring all values in a single status
response. Each value falls back to the shared Status URL when no
separate URL is set, preserving backward compatibility. Added power
and energy multipliers for unit conversion (e.g. 0.001 for Wh→kWh).
Race condition in _update_state: dev mode probe released GIL via MQTT
publish between raw_data overwrite and vt_tray list restoration, letting
the event loop iterate over raw dict keys (strings) instead of spool
dicts. Affects A1, P1, and X1Plus firmware that don't send the fun field.
Fix: normalize vt_tray dict→list before raw_data assignment, restore
preserved fields before any GIL-releasing work, add defensive guard in
printer_state_to_dict.
The test conftest.py model import list was out of sync with database.py,
missing slot_preset, project_bom, spool_k_profile, and spoolbuddy_device.
Base.metadata.create_all() never created those tables in the test DB.
The periodic cleanup of old AMS sensor history entries (every ~24h)
failed with "can't compare offset-naive and offset-aware datetimes".
The cutoff used datetime.now(timezone.utc) but recorded_at stores
naive datetimes via SQLite's func.now(). Use utcnow() instead.
Replace polling-based bed cooldown monitor with event-driven approach.
Some firmware stops sending bed_temper after print completion, causing
the 30-min polling loop to time out on stale cached values. Now reacts
instantly to bed_temper MQTT data via a new on_bed_temp_update callback.
Thread event_type and template variables through the webhook call chain so
all generic webhook payloads include an "event" field and event-specific
data (printer, filename, duration, etc.) as top-level JSON fields. Existing
title/message/timestamp/source fields are unchanged. Slack format unaffected.
GitHub backup can now optionally include spool inventory (with usage
history) and print archive metadata as JSON. Both toggles are off by
default. No binary files (gcode/3MF) are included.
Single-nozzle printers (X1C, P1S, A1) report tray_now=254 for external
spool, but BambuStudio sends ams_id=255 (VIRTUAL_TRAY_MAIN_ID) in the
print command's ams_mapping2 field. Bambuddy was passing 254 as-is,
causing firmware to target AMS tray 0 instead of external spool —
resulting in 07FF_8012 "Failed to get AMS mapping table" or prints stuck
at heatbed heating when an AMS is connected but empty.
Map external spool to ams_id=255 for all non-H2D printers. H2D
dual-nozzle printers retain 254 (deputy) / 255 (main) distinction.
When multiple AMS spools match the same type/color criteria, an optional
setting now prefers the spool with the lowest remaining filament. This
helps consume partial spools before starting new ones. Sorting applies
to all matching paths: queue scheduler, print modal, and multi-printer
mapping. Unknown remain values (-1) sort to end.
Admins can now filter the Statistics page by user via a new
stats:filter_by_user permission. A user dropdown appears in the stats
header showing all users plus "No User (System)" for prints without
attribution. The filter applies to all stats widgets, failure analysis,
and CSV/Excel exports. Backend validates the permission on all 4 stats
endpoints, returning 403 if the filter is used without authorization.
Stagger option now available when printing directly to multiple printers,
not just in queue mode. Prints are automatically queued with staggered
start times using group size/interval from Settings. New "Require
plate-clear confirmation" setting lets farm users disable per-printer
plate confirmations so queued prints start automatically on finished
printers.
Also fixes settings API type parsing for require_plate_clear (boolean),
stagger_group_size and stagger_interval_minutes (integer) — without this,
saved values returned as strings would cause the settings toggle to
always show enabled and trigger a permanent save loop.
Printers with no AMS hardware (P1S/P1P with only external spool)
rejected print commands with "Failed to get AMS mapping table"
because use_ams was always sent as true. Now auto-sets use_ams=false
when all filament slots map to external spools or are unmapped.
H2D-series excluded since they use use_ams for nozzle routing.
scan_external_folder stored raw 3MF metadata containing _thumbnail_data
bytes directly in the JSON column, causing a serialization error. Applied
the same clean_metadata() pattern used by upload/zip extraction and
removed the call to the non-existent parser.extract_thumbnail().
The archives page only fetched the 50 most recent prints due to a
hardcoded API limit default. Added client-side pagination with
configurable page sizes (25/50/100/200/All) and bumped the fetch
limit to return all archives. Page size is persisted to localStorage.
on_print_complete returned early when no archive_id was found (auto-
archive off), skipping both internal inventory tracking (AMS remain%
deltas) and Spoolman usage reporting. Moved the filament usage tracking
block to run before the archive_id early-return so consumption is
always recorded regardless of the auto-archive setting.
When adding a print to the queue for multiple printers, users can now
enable "Stagger printer starts" to avoid power spikes from simultaneous
bed heating. Configurable group size and interval — first group starts
immediately (ASAP) or at scheduled time, subsequent groups get offset
scheduled_time values. No backend queue/scheduler changes — leverages
existing scheduled_time field.
Also adds a dedicated Queue tab in Settings (stagger defaults + auto-
drying moved from Filament tab), i18n keys for all 7 locales, frontend
and backend tests.
Corrected left/right nozzle labels in ams_mapping2 comment
(255=main/right, 254=deputy/left). Added [0.2.2.2] release header
and #836 changelog entry noting the nozzle routing fix was already
included via the #797 ams_mapping2 format change.