mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-02 20:22:15 +02:00
Security scan (Bandit) identified vulnerable XML parsing in 3MF file processing. The standard xml.etree.ElementTree is vulnerable to XXE (XML External Entity) attacks. Changes: - Add defusedxml>=0.7.0 to requirements.txt - Replace all xml.etree.ElementTree imports with defusedxml.ElementTree in production code (6 files) Affected files: - backend/app/services/archive.py - backend/app/services/print_scheduler.py - backend/app/api/routes/print_queue.py - backend/app/api/routes/library.py - backend/app/api/routes/printers.py - backend/app/api/routes/archives.py Test files intentionally left unchanged (test XML is trusted).