mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-04 21:21:54 +02:00
DELETE /api/v1/archives/{id} rejected every API key with 403
"API keys cannot be used for administrative operations", regardless of
the print's owner or the key's scopes. ARCHIVES_DELETE_ALL/_OWN (and the
create/update variants) were on the denylist and absent from the scope
allowlist, so require_ownership_permission fell through to the generic
admin-denied 403 — the whole archive-management surface was unreachable
for API keys. Same regression class as the #1832 library/maintenance
carve-outs.
Add a can_manage_archives per-key scope: ARCHIVES_CREATE, ARCHIVES_
UPDATE_OWN/_ALL and ARCHIVES_DELETE_OWN/_ALL move from the denylist to
the allowlist under it (OWN and ALL fold into the same scope, matching
can_manage_library). ARCHIVES_PURGE stays admin-only — it drops the
print's Quick Stats contribution, mirroring LIBRARY_PURGE. Column
defaults TRUE for UI-created keys; existing rows backfill to FALSE so the
upgrade never silently widens scope. Bundled SpoolBuddy kiosk key stays
minimally scoped (False). Migration is dialect-agnostic and verified on
fresh SQLite and Postgres 17.
Adds the Settings API-key toggle + badge (11-locale i18n) and extends the
RBAC scope matrix to cover all five archive-management permissions.
59 lines
2.8 KiB
Python
59 lines
2.8 KiB
Python
from datetime import datetime
|
|
|
|
from sqlalchemy import JSON, Boolean, DateTime, ForeignKey, Integer, String, func
|
|
from sqlalchemy.orm import Mapped, mapped_column
|
|
|
|
from backend.app.core.database import Base
|
|
|
|
|
|
class APIKey(Base):
|
|
"""API key for external webhook access."""
|
|
|
|
__tablename__ = "api_keys"
|
|
|
|
id: Mapped[int] = mapped_column(primary_key=True)
|
|
name: Mapped[str] = mapped_column(String(100)) # User-friendly name
|
|
key_hash: Mapped[str] = mapped_column(String(255)) # bcrypt hash of the key
|
|
key_prefix: Mapped[str] = mapped_column(String(20)) # First 8 chars + "..." for display
|
|
|
|
# Owner — required for new keys, NULL only on legacy rows that predate per-user
|
|
# ownership. Cloud routes reject calls from keys without an owner so callers are
|
|
# forced to recreate them. CASCADE so deleting a user removes their keys.
|
|
user_id: Mapped[int | None] = mapped_column(
|
|
Integer,
|
|
ForeignKey("users.id", ondelete="CASCADE"),
|
|
nullable=True,
|
|
index=True,
|
|
)
|
|
|
|
# Permissions
|
|
can_queue: Mapped[bool] = mapped_column(Boolean, default=True) # Add to queue
|
|
can_control_printer: Mapped[bool] = mapped_column(Boolean, default=False) # Start/stop/cancel
|
|
can_read_status: Mapped[bool] = mapped_column(Boolean, default=True) # Query status
|
|
can_manage_library: Mapped[bool] = mapped_column(
|
|
Boolean, default=True
|
|
) # Upload/rename/delete own library files + MakerWorld import
|
|
can_manage_inventory: Mapped[bool] = mapped_column(
|
|
Boolean, default=True
|
|
) # Inventory write ops (incl. SpoolBuddy kiosk NFC/scale/system)
|
|
can_manage_maintenance: Mapped[bool] = mapped_column(
|
|
Boolean, default=True
|
|
) # Log/reset per-printer maintenance, edit intervals, manage the type catalog (#1832 follow-up)
|
|
can_manage_archives: Mapped[bool] = mapped_column(
|
|
Boolean, default=True
|
|
) # Create/update/delete print archives (not purge) (#1888)
|
|
can_access_cloud: Mapped[bool] = mapped_column(Boolean, default=False) # Read /cloud/* on the owner's behalf
|
|
# Narrowly-scoped settings write: only POST /settings/electricity-price.
|
|
# Lets HA/Tibber-style automations push dynamic tariff updates without
|
|
# granting full SETTINGS_UPDATE (which is denied for API keys because it
|
|
# could rewrite SMTP/LDAP/MQTT credentials).
|
|
can_update_energy_cost: Mapped[bool] = mapped_column(Boolean, default=False)
|
|
|
|
# Optional scope limits
|
|
printer_ids: Mapped[list | None] = mapped_column(JSON, nullable=True) # null = all printers
|
|
|
|
enabled: Mapped[bool] = mapped_column(Boolean, default=True)
|
|
last_used: Mapped[datetime | None] = mapped_column(DateTime, nullable=True)
|
|
created_at: Mapped[datetime] = mapped_column(DateTime, server_default=func.now())
|
|
expires_at: Mapped[datetime | None] = mapped_column(DateTime, nullable=True) # Optional expiry
|