Files
bambuddy/backend/app/models/spoolbuddy_device.py
T
maziggy f5ecc61cda fix(spoolbuddy): lower /update permission to INVENTORY_UPDATE so kiosk's own Settings -> Update button works
The kiosk's Settings -> Update Daemon button returned "API keys cannot
  be used for administrative operations" because POST /spoolbuddy/devices/
  {id}/update was gated on Permission.SETTINGS_UPDATE, and SETTINGS_UPDATE
  is in the _APIKEY_DENIED_PERMISSIONS deny-list introduced by PR #1241.
  Every kiosk-side request tripped the deny-list before the API key's
  scope set (Read / Print Queue / Control / Legacy) was even consulted.

  Same root cause as the four QuickMenu System buttons fixed in 0.2.4b3
  (Restart Daemon / Restart Browser / Reboot / Shutdown). Missed /update
  in that audit on the reasoning "replaces the daemon binary, different
  threat surface" — but that's wrong: restart_daemon already replaces
  the running daemon process, so daemon-replacement is not a step up in
  blast radius. The SSH update is also strictly scoped to the one device
  the operator physically controls (git fetch + pip install + systemctl
  restart on that host) — same threat profile as the system commands
  already running on INVENTORY_UPDATE.

  Lower /spoolbuddy/devices/{id}/update from SETTINGS_UPDATE to
  INVENTORY_UPDATE so it aligns with the rest of the kiosk-scoped routes
  (calibration/tare, display, cancel-write, system/command,
  system/command-result, update-status). The main Bambuddy in-app updater
  at POST /api/v1/updates/apply keeps SETTINGS_UPDATE — that one runs on
  the Bambuddy host and is correctly fenced behind the deny-list.
2026-05-08 14:28:41 +02:00

43 lines
2.4 KiB
Python

from datetime import datetime
from sqlalchemy import Boolean, DateTime, Float, Integer, String, Text, func
from sqlalchemy.orm import Mapped, mapped_column
from backend.app.core.database import Base
class SpoolBuddyDevice(Base):
"""SpoolBuddy device registration for RPi-based filament management stations."""
__tablename__ = "spoolbuddy_devices"
id: Mapped[int] = mapped_column(primary_key=True)
device_id: Mapped[str] = mapped_column(String(50), unique=True, index=True)
hostname: Mapped[str] = mapped_column(String(100))
ip_address: Mapped[str] = mapped_column(String(45))
firmware_version: Mapped[str | None] = mapped_column(String(20))
has_nfc: Mapped[bool] = mapped_column(Boolean, default=True)
has_scale: Mapped[bool] = mapped_column(Boolean, default=True)
tare_offset: Mapped[int] = mapped_column(Integer, default=0)
calibration_factor: Mapped[float] = mapped_column(Float, default=1.0)
nfc_reader_type: Mapped[str | None] = mapped_column(String(20))
nfc_connection: Mapped[str | None] = mapped_column(String(20))
backend_url: Mapped[str | None] = mapped_column(String(255), nullable=True)
display_brightness: Mapped[int] = mapped_column(Integer, default=100)
display_blank_timeout: Mapped[int] = mapped_column(Integer, default=0)
has_backlight: Mapped[bool] = mapped_column(Boolean, default=False)
last_calibrated_at: Mapped[datetime | None] = mapped_column(DateTime)
last_seen: Mapped[datetime | None] = mapped_column(DateTime)
pending_command: Mapped[str | None] = mapped_column(String(50))
pending_write_payload: Mapped[str | None] = mapped_column(Text, nullable=True)
update_status: Mapped[str | None] = mapped_column(String(20), nullable=True)
update_message: Mapped[str | None] = mapped_column(String(255), nullable=True)
pending_system_payload: Mapped[str | None] = mapped_column(Text, nullable=True)
nfc_ok: Mapped[bool] = mapped_column(Boolean, default=False)
scale_ok: Mapped[bool] = mapped_column(Boolean, default=False)
uptime_s: Mapped[int] = mapped_column(Integer, default=0)
system_stats: Mapped[str | None] = mapped_column(Text, nullable=True)
ssh_host_key: Mapped[str | None] = mapped_column(Text, nullable=True)
created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.now())
updated_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.now(), onupdate=func.now())