archives.py 232 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696
  1. import asyncio
  2. import io
  3. import json
  4. import logging
  5. import re as _re
  6. import zipfile
  7. from collections import defaultdict
  8. from datetime import date, datetime, time, timedelta, timezone
  9. from decimal import ROUND_HALF_UP, Decimal
  10. from html import escape as html_escape
  11. from pathlib import Path
  12. from fastapi import APIRouter, Depends, File, Form, HTTPException, Query, Request, UploadFile
  13. from fastapi.responses import FileResponse, Response
  14. from sqlalchemy import and_, case, func, or_, select
  15. from sqlalchemy.ext.asyncio import AsyncSession
  16. from backend.app.core import database
  17. from backend.app.core.auth import (
  18. ApiKeyActor,
  19. MediaOrRequestPrinterScope,
  20. RequestActor,
  21. RequestPrinterScope,
  22. RequirePermissionIfAuthEnabled,
  23. probe_permissions_if_auth_enabled,
  24. require_media_token_ownership,
  25. require_ownership_permission,
  26. )
  27. from backend.app.core.config import settings
  28. from backend.app.core.database import get_db
  29. from backend.app.core.permissions import Permission
  30. from backend.app.core.printer_scope import PrinterScope
  31. from backend.app.models.archive import PrintArchive
  32. from backend.app.models.filament import Filament
  33. from backend.app.models.printer import Printer
  34. from backend.app.models.spool_usage_history import SpoolUsageHistory
  35. from backend.app.models.user import User
  36. from backend.app.schemas.archive import ArchiveResponse, ArchiveSlim, ArchiveStats, ArchiveUpdate
  37. from backend.app.schemas.print_log import PrintLogResponse
  38. from backend.app.schemas.slicer import SliceRequest
  39. from backend.app.services.archive import ArchiveService
  40. from backend.app.services.bambu_ftp import ftps_handshake_blocked, list_files_result_async
  41. from backend.app.services.design_settings import overrides_from_config
  42. from backend.app.services.filament_requirements import annotate_rack_groups
  43. from backend.app.services.print_confirmation import (
  44. is_one_tap_request,
  45. is_unattended_fetch,
  46. retire_confirm_token,
  47. stamp_verdict,
  48. )
  49. from backend.app.services.print_storage import (
  50. REASON_FTP_TRANSFER_FAILED,
  51. REASON_FTPS_COOLOFF,
  52. REASON_INTERNAL_HISTORY,
  53. REASON_INTERNAL_STORAGE,
  54. REASON_NO_EXTERNAL_STORAGE,
  55. )
  56. from backend.app.services.printer_media import VIDEO_SUFFIXES, match_ipcam_chunks
  57. from backend.app.utils.archive_paths import archive_photos_dir, find_archive_photo
  58. from backend.app.utils.http import build_content_disposition, download_error_response, safe_download_filename
  59. from backend.app.utils.threemf_tools import (
  60. default_plate_gcode_name,
  61. expand_to_project_slots,
  62. extract_embedded_presets_from_3mf,
  63. extract_nozzle_mapping_from_3mf,
  64. extract_project_filaments_from_3mf,
  65. names_carry_gcode,
  66. select_plate_gcode_name,
  67. )
  68. logger = logging.getLogger(__name__)
  69. router = APIRouter(prefix="/archives", tags=["archives"])
  70. _PRINTER_MEDIA_LIST_TIMEOUT_SECONDS = 8.0
  71. # Path of the embedded slicer config inside a BambuStudio/OrcaSlicer 3MF.
  72. _PROJECT_SETTINGS_PATH = "Metadata/project_settings.config"
  73. def _safe_filename(filename: str) -> str:
  74. """Extract basename from a client-supplied filename, preventing path traversal.
  75. Normalizes backslashes (Windows paths) before extracting so that
  76. '..\\\\..\\\\evil.3mf' is correctly stripped to 'evil.3mf' on Linux.
  77. """
  78. return Path(filename.replace("\\", "/")).name
  79. _TIMELAPSE_FILENAME_TS_RE = _re.compile(r"(\d{4}-\d{2}-\d{2}_\d{2}-\d{2}-\d{2})")
  80. _DEFAULT_TIMELAPSE_OFFSETS_HOURS: tuple[int, ...] = (0, 8, -8, 7, -7, 1, -1)
  81. _DEFAULT_TIMELAPSE_TOLERANCE = timedelta(hours=4)
  82. _DEFAULT_TIMELAPSE_AMBIGUITY_MARGIN = timedelta(minutes=15)
  83. def _match_timelapse_by_timestamp(
  84. video_files: list[dict],
  85. archive_start: datetime | None,
  86. *,
  87. tolerance: timedelta = _DEFAULT_TIMELAPSE_TOLERANCE,
  88. ambiguity_margin: timedelta = _DEFAULT_TIMELAPSE_AMBIGUITY_MARGIN,
  89. offsets_hours: tuple[int, ...] = _DEFAULT_TIMELAPSE_OFFSETS_HOURS,
  90. ) -> tuple[dict | None, timedelta | None]:
  91. """Pick the timelapse whose filename timestamp best matches the print start time.
  92. Bambu timelapse filenames embed the printer-local START time (e.g.
  93. "video_2026-05-08_09-41-29.mp4"). The printer's clock may be offset from the
  94. server's — especially in LAN-Only mode where NTP is unreachable — so we try a
  95. small set of common UTC offsets and keep the (video, offset) pair with the
  96. smallest absolute distance from archive_start. We deliberately do NOT consider
  97. archive_end here: the filename is start time, not end time, so comparing it to
  98. completion is not a real signal (Strategy 3 handles end via file mtime).
  99. Because the offset list densely covers a wide span, an unrelated video's
  100. filename can coincidentally land near a later print's start at some offset.
  101. To avoid that false positive, we require the best (video, offset) pair to
  102. beat the next-best pair *from a different video* by at least `ambiguity_margin`.
  103. When the top two candidates from different videos are too close to call,
  104. we return None and let the caller fall back to manual selection.
  105. """
  106. if archive_start is None:
  107. return None, None
  108. # (diff, video) for every (video, offset) pair within tolerance.
  109. candidates: list[tuple[timedelta, dict]] = []
  110. for f in video_files:
  111. fname = f.get("name", "")
  112. m = _TIMELAPSE_FILENAME_TS_RE.search(fname)
  113. if not m:
  114. continue
  115. try:
  116. file_time = datetime.strptime(m.group(1), "%Y-%m-%d_%H-%M-%S")
  117. except ValueError:
  118. continue
  119. for hour_offset in offsets_hours:
  120. adjusted = file_time - timedelta(hours=hour_offset)
  121. diff = abs(adjusted - archive_start)
  122. if diff <= tolerance:
  123. candidates.append((diff, f))
  124. if not candidates:
  125. return None, None
  126. candidates.sort(key=lambda c: c[0])
  127. best_diff, best_video = candidates[0]
  128. best_name = best_video.get("name")
  129. for diff, video in candidates[1:]:
  130. if video.get("name") != best_name and (diff - best_diff) < ambiguity_margin:
  131. # Another video matches almost as well — refuse to auto-pick.
  132. return None, None
  133. return best_video, best_diff
  134. async def _claimed_timelapse_stems(db, printer_id: int | None, exclude_archive_id: int) -> set[str]:
  135. """Video filenames already attached to another archive of this printer (#2704).
  136. Lets the baseline diff drop a previous print's late-landing video from the
  137. candidate list without ordering the candidates — ordering could only be done
  138. on mtime or the filename timestamp, and both come from a clock the printer
  139. can't sync in LAN-only mode. ``attach_timelapse`` stores the video under the
  140. printer's own filename and the MP4 conversion keeps the stem, so the stem of
  141. ``timelapse_path`` is what was claimed.
  142. """
  143. if printer_id is None:
  144. return set()
  145. rows = await db.execute(
  146. select(PrintArchive.timelapse_path).where(
  147. PrintArchive.printer_id == printer_id,
  148. PrintArchive.id != exclude_archive_id,
  149. PrintArchive.timelapse_path.is_not(None),
  150. )
  151. )
  152. return {Path(p).stem for p in rows.scalars().all() if p}
  153. def _ensure_archive_visible(
  154. archive: PrintArchive | None,
  155. user: User | None,
  156. can_read_all: bool,
  157. printer_scope: PrinterScope,
  158. ) -> PrintArchive:
  159. """Per-archive visibility gate for ownership-scoped reads (#1726-adjacent).
  160. Returns ``archive`` if the caller is allowed to see it; raises 404 otherwise.
  161. Single enforcement point used by every detail / download / sub-resource
  162. route so we can't accidentally leak a row through a less-guarded sibling.
  163. Rules:
  164. - Missing archive or soft-deleted (``deleted_at != None``) → 404.
  165. - Caller with ARCHIVES_READ_ALL or auth disabled (``can_read_all=True``,
  166. ``user`` may be None) → archive returned.
  167. - Caller without ARCHIVES_READ_ALL and ``archive.created_by_id != user.id``
  168. → 404, deliberately NOT 403. 403 leaks "this id exists but you can't
  169. see it" — enumeration-friendly. 404 is indistinguishable from a
  170. nonexistent id. Pre-GHSA fix the caller saw 200 here (the PoC vector).
  171. - Ownerless rows (``created_by_id is None``) require ALL — fail-closed
  172. per ``feedback_no_fail_open_in_auth``.
  173. - An archive whose printer is outside ``printer_scope`` → 404 (#1727).
  174. """
  175. if not archive or archive.deleted_at is not None:
  176. raise HTTPException(404, "Archive not found")
  177. # An archive from a printer the caller can't see is as missing as the
  178. # printer itself (#1727). Archives with no printer stay governed by
  179. # ownership alone.
  180. if not printer_scope.allows(archive.printer_id):
  181. raise HTTPException(404, "Archive not found")
  182. if can_read_all:
  183. return archive
  184. # Auth enabled, caller has _OWN only.
  185. if user is None:
  186. # Defensive: should be unreachable (RequirePermissionIfAuthEnabled
  187. # would have 401'd already), but never trust user identity to be
  188. # non-None when can_read_all is False.
  189. raise HTTPException(404, "Archive not found")
  190. if archive.created_by_id is None or archive.created_by_id != user.id:
  191. raise HTTPException(404, "Archive not found")
  192. return archive
  193. def _validate_user_filter_permission(current_user: User | ApiKeyActor | None, created_by_id: int | None):
  194. """Raise 403 if created_by_id filter is used without stats:filter_by_user permission."""
  195. if created_by_id is None or current_user is None:
  196. return
  197. if current_user.is_admin:
  198. return
  199. if not current_user.has_permission(Permission.STATS_FILTER_BY_USER.value):
  200. raise HTTPException(status_code=403, detail="Permission stats:filter_by_user required")
  201. def _apply_user_filter(conditions: list, created_by_id: int | None):
  202. """Append created_by_id filter to conditions list if specified."""
  203. if created_by_id is not None:
  204. if created_by_id == -1:
  205. conditions.append(PrintArchive.created_by_id.is_(None))
  206. else:
  207. conditions.append(PrintArchive.created_by_id == created_by_id)
  208. def _apply_run_user_filter(conditions: list, created_by_id: int | None):
  209. """Append created_by_id filter scoped to PrintLogEntry rows."""
  210. from backend.app.models.print_log import PrintLogEntry
  211. if created_by_id is not None:
  212. if created_by_id == -1:
  213. conditions.append(PrintLogEntry.created_by_id.is_(None))
  214. else:
  215. conditions.append(PrintLogEntry.created_by_id == created_by_id)
  216. def compute_time_accuracy(archive: PrintArchive, run_aggregate: dict | None = None) -> dict:
  217. """Compute actual print time and accuracy for an archive.
  218. Returns dict with actual_time_seconds and time_accuracy.
  219. time_accuracy = (estimated / actual) * 100
  220. - 100% = perfect estimate
  221. - >100% = print was faster than estimated
  222. - <100% = print took longer than estimated
  223. When ``run_aggregate`` indicates the archive has more than one logged
  224. run (multi-plate file printed plate-by-plate, or reprints), both
  225. fields are suppressed: ``archive.started_at / completed_at`` reflect
  226. the LATEST run only, while ``archive.print_time_seconds`` is the
  227. whole-file estimate (post-#1593 the parser sums across plates), so
  228. comparing the two describes different scopes. The card-rendering
  229. frontend falls through to ``archive.print_time_seconds`` for the
  230. time display and hides the badge when ``time_accuracy`` is null —
  231. that's the desired "show estimate, no badge" presentation for
  232. multi-run archives (#1608). Single-run archives keep the original
  233. badge behaviour verbatim.
  234. """
  235. result: dict[str, int | float | None] = {"actual_time_seconds": None, "time_accuracy": None}
  236. # Multi-run archives: the per-run actual (started_at..completed_at on
  237. # the archive row) is incommensurable with the whole-file estimate.
  238. # Both fields are cleared so the card shows estimate + no badge.
  239. if run_aggregate and (run_aggregate.get("run_count") or 0) > 1:
  240. return result
  241. if archive.started_at and archive.completed_at and archive.status == "completed":
  242. actual_seconds = int((archive.completed_at - archive.started_at).total_seconds())
  243. if actual_seconds > 0:
  244. result["actual_time_seconds"] = actual_seconds
  245. if archive.print_time_seconds and archive.print_time_seconds > 0:
  246. # Calculate accuracy as percentage
  247. accuracy = (archive.print_time_seconds / actual_seconds) * 100
  248. # Sanity check: skip unreasonable values (e.g., manually changed status)
  249. # Valid range: 5% to 500% (print took 20x longer to 5x faster than estimated)
  250. if 5 <= accuracy <= 500:
  251. result["time_accuracy"] = round(accuracy, 1)
  252. return result
  253. async def _load_run_aggregates(db: AsyncSession, archive_ids: list[int]) -> dict[int, dict]:
  254. """Batch-load per-archive run aggregates from PrintLogEntry.
  255. Returns ``{archive_id: {run_count, last_run_at, total_filament_actual_grams,
  256. successful_run_count, failed_run_count}}``. Archives with no logged runs are
  257. absent from the map; callers should treat that as zero/none.
  258. """
  259. from backend.app.models.print_log import PrintLogEntry
  260. if not archive_ids:
  261. return {}
  262. rows = await db.execute(
  263. select(
  264. PrintLogEntry.archive_id,
  265. func.count(PrintLogEntry.id).label("run_count"),
  266. func.max(PrintLogEntry.started_at).label("last_run_at"),
  267. func.coalesce(func.sum(PrintLogEntry.filament_used_grams), 0).label("total_filament"),
  268. func.sum(case((PrintLogEntry.status == "completed", 1), else_=0)).label("successful"),
  269. func.sum(case((PrintLogEntry.status == "failed", 1), else_=0)).label("failed"),
  270. )
  271. .where(PrintLogEntry.archive_id.in_(archive_ids))
  272. .group_by(PrintLogEntry.archive_id)
  273. )
  274. aggregates: dict[int, dict] = {}
  275. for archive_id, run_count, last_run_at, total_filament, successful, failed in rows.all():
  276. aggregates[archive_id] = {
  277. "run_count": int(run_count or 0),
  278. "last_run_at": last_run_at,
  279. "total_filament_actual_grams": float(total_filament) if total_filament else None,
  280. "successful_run_count": int(successful or 0),
  281. "failed_run_count": int(failed or 0),
  282. }
  283. return aggregates
  284. def archive_to_response(
  285. archive: PrintArchive,
  286. duplicates: list[dict] | None = None,
  287. duplicate_count: int = 0,
  288. duplicate_sequence: int = 0,
  289. original_archive_id: int | None = None,
  290. run_aggregate: dict | None = None,
  291. ) -> dict:
  292. """Convert archive model to response dict with computed fields."""
  293. data = {
  294. "id": archive.id,
  295. "printer_id": archive.printer_id,
  296. "project_id": archive.project_id,
  297. "project_name": archive.project.name if archive.project else None,
  298. "filename": archive.filename,
  299. "file_path": archive.file_path,
  300. "file_size": archive.file_size,
  301. "content_hash": archive.content_hash,
  302. "thumbnail_path": archive.thumbnail_path,
  303. "timelapse_path": archive.timelapse_path,
  304. "source_3mf_path": archive.source_3mf_path,
  305. "f3d_path": archive.f3d_path,
  306. "duplicates": duplicates,
  307. "duplicate_count": duplicate_count if duplicates is None else len(duplicates),
  308. "duplicate_sequence": duplicate_sequence,
  309. "original_archive_id": original_archive_id,
  310. "print_name": archive.print_name,
  311. "plate_id": archive.plate_id,
  312. "print_time_seconds": archive.print_time_seconds,
  313. "filament_used_grams": archive.filament_used_grams,
  314. "filament_type": archive.filament_type,
  315. "filament_color": archive.filament_color,
  316. "layer_height": archive.layer_height,
  317. "total_layers": archive.total_layers,
  318. "nozzle_diameter": archive.nozzle_diameter,
  319. "bed_temperature": archive.bed_temperature,
  320. "bed_type": archive.bed_type,
  321. "nozzle_temperature": archive.nozzle_temperature,
  322. "sliced_for_model": archive.sliced_for_model,
  323. "status": archive.status,
  324. "started_at": archive.started_at,
  325. "completed_at": archive.completed_at,
  326. "extra_data": archive.extra_data,
  327. "makerworld_url": archive.makerworld_url,
  328. "designer": archive.designer,
  329. "external_url": archive.external_url,
  330. "is_favorite": archive.is_favorite,
  331. "tags": archive.tags,
  332. "notes": archive.notes,
  333. "cost": archive.cost,
  334. "photos": archive.photos,
  335. "failure_reason": archive.failure_reason,
  336. # Post-print outcome confirmation (#1898). confirm_token stays
  337. # server-side — it is a capability and never belongs in a response.
  338. "user_verdict": archive.user_verdict,
  339. "user_verdict_source": archive.user_verdict_source,
  340. "user_verdict_at": archive.user_verdict_at,
  341. # bool() because the column is nullable to match the migration; the
  342. # response contract stays a strict bool either way.
  343. "confirm_requested": bool(archive.confirm_requested),
  344. "quantity": archive.quantity,
  345. "energy_kwh": archive.energy_kwh,
  346. "energy_cost": archive.energy_cost,
  347. "wear_cost": archive.wear_cost,
  348. "created_at": archive.created_at,
  349. # User tracking (Issue #206)
  350. "created_by_id": archive.created_by_id,
  351. "created_by_username": archive.created_by.username if archive.created_by else None,
  352. }
  353. # Add computed time accuracy fields. ``run_aggregate`` lets
  354. # ``compute_time_accuracy`` suppress the badge for multi-run archives
  355. # where the per-run actual / whole-file estimate scopes don't match
  356. # (#1608).
  357. accuracy_data = compute_time_accuracy(archive, run_aggregate)
  358. data.update(accuracy_data)
  359. if run_aggregate:
  360. data["run_count"] = run_aggregate.get("run_count", 0)
  361. data["last_run_at"] = run_aggregate.get("last_run_at")
  362. data["total_filament_actual_grams"] = run_aggregate.get("total_filament_actual_grams")
  363. data["successful_run_count"] = run_aggregate.get("successful_run_count", 0)
  364. data["failed_run_count"] = run_aggregate.get("failed_run_count", 0)
  365. return data
  366. @router.get("/", response_model=list[ArchiveResponse])
  367. async def list_archives(
  368. printer_id: int | None = None,
  369. project_id: int | None = None,
  370. date_from: date | None = Query(None),
  371. date_to: date | None = Query(None),
  372. limit: int = 50,
  373. offset: int = 0,
  374. db: AsyncSession = Depends(get_db),
  375. auth_result: tuple[User | None, bool] = Depends(
  376. require_ownership_permission(
  377. Permission.ARCHIVES_READ_ALL,
  378. Permission.ARCHIVES_READ_OWN,
  379. )
  380. ),
  381. printer_scope: PrinterScope = RequestPrinterScope,
  382. ):
  383. """List archived prints."""
  384. user, can_read_all = auth_result
  385. visible_to_user_id = user.id if (user is not None and not can_read_all) else None
  386. service = ArchiveService(db)
  387. archives = await service.list_archives(
  388. printer_id=printer_id,
  389. project_id=project_id,
  390. date_from=date_from,
  391. date_to=date_to,
  392. limit=limit,
  393. offset=offset,
  394. visible_to_user_id=visible_to_user_id,
  395. printer_scope=printer_scope,
  396. )
  397. # Get sets of duplicate hashes and duplicate (name, hash) pairs (efficient single queries)
  398. duplicate_hashes, duplicate_name_hash_pairs = await service.get_duplicate_hashes_and_names()
  399. # Batch-load duplicate groups once for the current page keys.
  400. duplicate_hashes_in_page = {
  401. a.content_hash for a in archives if a.content_hash and a.content_hash in duplicate_hashes
  402. }
  403. duplicate_name_hash_keys_in_page = {
  404. (a.print_name.lower(), a.content_hash)
  405. for a in archives
  406. if a.print_name and a.content_hash and (a.print_name.lower(), a.content_hash) in duplicate_name_hash_pairs
  407. }
  408. duplicate_meta_by_archive_id: dict[int, tuple[int, int, int]] = {}
  409. if duplicate_hashes_in_page or duplicate_name_hash_keys_in_page:
  410. duplicate_group_conditions = []
  411. if duplicate_hashes_in_page:
  412. duplicate_group_conditions.append(PrintArchive.content_hash.in_(duplicate_hashes_in_page))
  413. if duplicate_name_hash_keys_in_page:
  414. name_hash_conditions = [
  415. and_(func.lower(PrintArchive.print_name) == name, PrintArchive.content_hash == hash_)
  416. for name, hash_ in duplicate_name_hash_keys_in_page
  417. ]
  418. duplicate_group_conditions.extend(name_hash_conditions)
  419. duplicate_group_rows = await db.execute(
  420. select(
  421. PrintArchive.id,
  422. PrintArchive.created_at,
  423. PrintArchive.content_hash,
  424. func.lower(PrintArchive.print_name).label("print_name_lower"),
  425. ).where(or_(*duplicate_group_conditions), PrintArchive.deleted_at.is_(None))
  426. )
  427. duplicate_groups_by_hash: dict[str, list[tuple[int, datetime]]] = defaultdict(list)
  428. duplicate_groups_by_name_hash: dict[tuple[str, str], list[tuple[int, datetime]]] = defaultdict(list)
  429. for archive_id, created_at, content_hash, print_name_lower in duplicate_group_rows.all():
  430. if content_hash and content_hash in duplicate_hashes_in_page:
  431. duplicate_groups_by_hash[content_hash].append((archive_id, created_at))
  432. if (
  433. print_name_lower
  434. and content_hash
  435. and (print_name_lower, content_hash) in duplicate_name_hash_keys_in_page
  436. ):
  437. duplicate_groups_by_name_hash[(print_name_lower, content_hash)].append((archive_id, created_at))
  438. for group in duplicate_groups_by_hash.values():
  439. if len(group) < 2:
  440. continue
  441. group.sort(key=lambda x: x[1])
  442. original_id = group[0][0]
  443. duplicate_count = len(group) - 1
  444. for sequence, (archive_id, _) in enumerate(group):
  445. duplicate_meta_by_archive_id[archive_id] = (sequence, original_id, duplicate_count)
  446. # Keep hash-based grouping precedence; name/hash groups only fill missing items.
  447. for group in duplicate_groups_by_name_hash.values():
  448. if len(group) < 2:
  449. continue
  450. group.sort(key=lambda x: x[1])
  451. original_id = group[0][0]
  452. duplicate_count = len(group) - 1
  453. for sequence, (archive_id, _) in enumerate(group):
  454. duplicate_meta_by_archive_id.setdefault(archive_id, (sequence, original_id, duplicate_count))
  455. run_aggregates = await _load_run_aggregates(db, [a.id for a in archives])
  456. # Build response with duplicate sequence and original archive ID pre-computed
  457. result = []
  458. for a in archives:
  459. has_hash_dup = a.content_hash in duplicate_hashes if a.content_hash else False
  460. has_name_dup = (
  461. bool(a.print_name and a.content_hash)
  462. and (a.print_name.lower(), a.content_hash) in duplicate_name_hash_pairs
  463. )
  464. has_duplicate = has_hash_dup or has_name_dup
  465. # Pre-compute duplicate sequence and original archive ID
  466. duplicate_sequence = 0
  467. original_archive_id: int | None = None
  468. duplicate_count = 1 if has_duplicate else 0
  469. if has_duplicate and a.id in duplicate_meta_by_archive_id:
  470. duplicate_sequence, original_archive_id, duplicate_count = duplicate_meta_by_archive_id[a.id]
  471. result.append(
  472. archive_to_response(
  473. a,
  474. duplicate_count=duplicate_count,
  475. duplicate_sequence=duplicate_sequence,
  476. original_archive_id=original_archive_id,
  477. run_aggregate=run_aggregates.get(a.id),
  478. )
  479. )
  480. return result
  481. @router.get("/last-per-printer", response_model=list[ArchiveResponse])
  482. async def list_last_archive_per_printer(
  483. db: AsyncSession = Depends(get_db),
  484. auth_result: tuple[User | None, bool] = Depends(
  485. require_ownership_permission(
  486. Permission.ARCHIVES_READ_ALL,
  487. Permission.ARCHIVES_READ_OWN,
  488. )
  489. ),
  490. printer_scope: PrinterScope = RequestPrinterScope,
  491. ):
  492. """The most recent archive of every printer, for the printer cards.
  493. One query for the whole Printers page instead of one list request per card.
  494. Leaves out the duplicate detection the full listing does: the card shows a
  495. name and an outcome prompt, and on a farm that scan ran once per printer
  496. on every page load.
  497. """
  498. user, can_read_all = auth_result
  499. filters = [PrintArchive.deleted_at.is_(None), PrintArchive.printer_id.isnot(None)]
  500. if user is not None and not can_read_all:
  501. filters.append(PrintArchive.created_by_id == user.id)
  502. # Only printers the caller may see (#1727)
  503. if (clause := printer_scope.where(PrintArchive.printer_id)) is not None:
  504. filters.append(clause)
  505. ranked = (
  506. select(
  507. PrintArchive.id,
  508. func.row_number()
  509. .over(
  510. partition_by=PrintArchive.printer_id,
  511. # A reprint reuses its archive row, moving it to the printer it
  512. # runs on with a fresh started_at, so the latest run start, not
  513. # the row's age, tells which print a printer ran last.
  514. order_by=(
  515. func.coalesce(PrintArchive.started_at, PrintArchive.created_at).desc(),
  516. PrintArchive.id.desc(),
  517. ),
  518. )
  519. .label("rn"),
  520. )
  521. .where(*filters)
  522. .subquery()
  523. )
  524. from sqlalchemy.orm import selectinload
  525. result = await db.execute(
  526. select(PrintArchive)
  527. .options(selectinload(PrintArchive.project), selectinload(PrintArchive.created_by))
  528. .where(PrintArchive.id.in_(select(ranked.c.id).where(ranked.c.rn == 1)))
  529. .order_by(PrintArchive.printer_id)
  530. )
  531. archives = list(result.scalars().all())
  532. run_aggregates = await _load_run_aggregates(db, [a.id for a in archives])
  533. return [archive_to_response(a, run_aggregate=run_aggregates.get(a.id)) for a in archives]
  534. @router.get("/no-3mf-warning")
  535. async def no_3mf_warning(
  536. db: AsyncSession = Depends(get_db),
  537. auth_result: tuple[User | None, bool] = Depends(
  538. require_ownership_permission(
  539. Permission.ARCHIVES_READ_ALL,
  540. Permission.ARCHIVES_READ_OWN,
  541. )
  542. ),
  543. ):
  544. """Whether to nudge the user about a print that archived without its 3MF,
  545. and why. True iff any archive in the last 30 days was created via the
  546. no-3MF fallback path.
  547. Also returns ``reason``, because the advice differs and the original
  548. single-cause wording sent people the wrong way. Historically the only
  549. known cause was install step 4 ("Store sent files on external storage")
  550. being off in the slicer, so the banner said so unconditionally. On
  551. H2-series, P2S and X2D that advice is actively wrong: the setting is already
  552. on and turning it on again changes nothing, because the printer keeps the
  553. sliced file on internal storage that FTPS does not serve at all (#2780).
  554. ``reason`` is the slug from :mod:`print_storage` when we recorded one,
  555. else None for the original slicer-setting case. When archives disagree the
  556. most specific known reason wins — one printer storing internally is a real
  557. finding worth explaining, and it should not be masked by another printer's
  558. plain missing-file fallback.
  559. Complements the connection-diagnostic ``external_storage`` check, which
  560. only catches the printer-side variant of the setting. On older slicers
  561. where the toggle lives only in BambuStudio, the printer never reports it
  562. and the diagnostic passes — this endpoint surfaces the symptom instead.
  563. Dismissal is handled client-side via localStorage (one-shot): once the
  564. user has been told, no further nudge until they clear browser storage.
  565. The backend stays stateless.
  566. """
  567. user, can_read_all = auth_result
  568. cutoff = datetime.now(timezone.utc) - timedelta(days=30)
  569. conditions = [
  570. PrintArchive.created_at >= cutoff,
  571. PrintArchive.deleted_at.is_(None),
  572. PrintArchive.extra_data.isnot(None),
  573. ]
  574. if user is not None and not can_read_all:
  575. conditions.append(PrintArchive.created_by_id == user.id)
  576. result = await db.execute(select(PrintArchive.extra_data).where(*conditions))
  577. reasons: set[str] = set()
  578. has_fallback = False
  579. for (extra_data,) in result.all():
  580. if not extra_data or not extra_data.get("no_3mf_available"):
  581. continue
  582. has_fallback = True
  583. reason = extra_data.get("no_3mf_reason")
  584. if reason:
  585. reasons.add(reason)
  586. if not has_fallback:
  587. return {"has_fallback": False, "reason": None}
  588. # Most specific first. Archives predating this field carry no reason at
  589. # all, so an install with one H2C and three older printers still gets the
  590. # H2C explanation rather than the generic one.
  591. #
  592. # REASON_FTPS_COOLOFF leads, and it is the only one of these that reports a
  593. # fault rather than a choice: the printer's file service refused a TLS
  594. # handshake, so the sweep never ran and nothing about where the file went
  595. # was ever tested. The other three describe an install working as
  596. # configured, and each ends in something the operator can change. This one
  597. # ends in "your printer is doing something we cannot yet explain", which is
  598. # both the more urgent thing to say and the thing that produces a useful
  599. # report. It also has to outrank them because the banner dismisses one-shot
  600. # into localStorage: a reason ranked below another is not merely deferred,
  601. # it is never shown to that user again (#2780).
  602. #
  603. # Ranking it first cannot mask a permanent cause, because a cool-off row is
  604. # not permanent. The retry #2957 schedules clears the row's markers when it
  605. # lands, so a row still carrying this slug is one where the retry failed too
  606. # -- a printer whose file service is still refusing, days later.
  607. #
  608. # REASON_FTP_TRANSFER_FAILED sits second for the same reasons and one more:
  609. # it is the only slug here whose remedy is a Bambuddy setting rather than a
  610. # slicer one or a card. It ranks below the cool-off because a printer that
  611. # will not complete a TLS handshake is the worse fault of the two, and its
  612. # own retry (#3063) clears the row the same way, so a row still carrying
  613. # this slug is one where three later attempts also ran out of time.
  614. #
  615. # REASON_INTERNAL_HISTORY comes last on purpose, even though it is the
  616. # narrowest: it is the one cause with no remedy at all -- the file was
  617. # already on the printer, in an area port 990 does not serve. The two ahead
  618. # of it each end in something the operator can do, so when an install has
  619. # both, the actionable explanation is the one worth the banner (#1820).
  620. for candidate in (
  621. REASON_FTPS_COOLOFF,
  622. REASON_FTP_TRANSFER_FAILED,
  623. REASON_INTERNAL_STORAGE,
  624. REASON_NO_EXTERNAL_STORAGE,
  625. REASON_INTERNAL_HISTORY,
  626. ):
  627. if candidate in reasons:
  628. return {"has_fallback": True, "reason": candidate}
  629. return {"has_fallback": True, "reason": None}
  630. @router.get("/slim", response_model=list[ArchiveSlim])
  631. async def list_archives_slim(
  632. date_from: date | None = Query(None),
  633. date_to: date | None = Query(None),
  634. created_by_id: int | None = Query(None, description="Filter by user who created the print (-1 for no user)"),
  635. limit: int = Query(default=10000, le=50000),
  636. offset: int = 0,
  637. db: AsyncSession = Depends(get_db),
  638. auth_result: tuple[User | None, bool] = Depends(
  639. require_ownership_permission(
  640. Permission.ARCHIVES_READ_ALL,
  641. Permission.ARCHIVES_READ_OWN,
  642. )
  643. ),
  644. printer_scope: PrinterScope = RequestPrinterScope,
  645. ):
  646. """Per-event listing for stats/dashboard widgets.
  647. Reads from print_log_entries so reprints contribute each run and
  648. orphaned events (archive deleted, log row survived via ON DELETE
  649. SET NULL) still aggregate consistently with Quick Stats. The sliced
  650. print_time_seconds is joined from the archive when available; for
  651. orphan events it is null and downstream widgets fall back to the
  652. measured duration_seconds.
  653. """
  654. from backend.app.models.print_log import PrintLogEntry
  655. current_user, can_read_all = auth_result
  656. _validate_user_filter_permission(current_user, created_by_id)
  657. # Callers without ARCHIVES_READ_ALL can only see their own runs — pin
  658. # the filter unconditionally so a caller-supplied ?created_by_id=
  659. # can't widen the listing past their own scope. The existing
  660. # _validate_user_filter_permission rejects ?created_by_id= without
  661. # STATS_FILTER_BY_USER, so the only way to reach this is owner-self
  662. # filtering anyway, but pinning here is the fail-closed default.
  663. if current_user is not None and not can_read_all:
  664. created_by_id = current_user.id
  665. filters = []
  666. if date_from:
  667. dt_from = datetime.combine(date_from, time.min, tzinfo=timezone.utc)
  668. filters.append(PrintLogEntry.created_at >= dt_from)
  669. if date_to:
  670. dt_to = datetime.combine(date_to, time.max, tzinfo=timezone.utc)
  671. filters.append(PrintLogEntry.created_at <= dt_to)
  672. _apply_run_user_filter(filters, created_by_id)
  673. if (clause := printer_scope.where(PrintLogEntry.printer_id)) is not None:
  674. filters.append(clause)
  675. query = (
  676. select(
  677. PrintLogEntry.printer_id,
  678. PrintLogEntry.print_name,
  679. PrintArchive.print_time_seconds,
  680. PrintLogEntry.started_at,
  681. PrintLogEntry.completed_at,
  682. PrintLogEntry.duration_seconds,
  683. PrintLogEntry.filament_used_grams,
  684. PrintLogEntry.filament_type,
  685. PrintLogEntry.filament_color,
  686. PrintLogEntry.status,
  687. PrintLogEntry.cost,
  688. PrintLogEntry.energy_kwh,
  689. PrintLogEntry.energy_cost,
  690. PrintLogEntry.wear_cost,
  691. PrintLogEntry.created_at,
  692. )
  693. .outerjoin(PrintArchive, PrintArchive.id == PrintLogEntry.archive_id)
  694. .where(*filters)
  695. .order_by(PrintLogEntry.created_at.desc())
  696. .limit(limit)
  697. .offset(offset)
  698. )
  699. result = await db.execute(query)
  700. rows = result.all()
  701. return [
  702. {
  703. "printer_id": r.printer_id,
  704. "print_name": r.print_name,
  705. "print_time_seconds": r.print_time_seconds,
  706. "actual_time_seconds": (
  707. # Measured elapsed time for every status (#1390): failed /
  708. # cancelled prints still ran for some duration, and Quick
  709. # Stats already counts that. Widgets that fall back to
  710. # print_time_seconds (slicer estimate) for non-completed
  711. # events would diverge from Quick Stats — so expose the
  712. # measured value here unconditionally.
  713. #
  714. # Trust an explicit 0 (reconciled aborts store it deliberately;
  715. # their real end time is unknown) instead of recomputing the
  716. # multi-day disconnect gap from the timestamps (#2592).
  717. r.duration_seconds
  718. if r.duration_seconds is not None
  719. else (
  720. int((r.completed_at - r.started_at).total_seconds())
  721. if r.started_at and r.completed_at and (r.completed_at - r.started_at).total_seconds() > 0
  722. else None
  723. )
  724. ),
  725. "filament_used_grams": r.filament_used_grams,
  726. "filament_type": r.filament_type,
  727. "filament_color": r.filament_color,
  728. "status": r.status,
  729. "started_at": r.started_at,
  730. "completed_at": r.completed_at,
  731. "cost": r.cost,
  732. "energy_kwh": r.energy_kwh,
  733. "energy_cost": r.energy_cost,
  734. "wear_cost": r.wear_cost,
  735. "quantity": 1,
  736. "created_at": r.created_at,
  737. }
  738. for r in rows
  739. ]
  740. @router.get("/search", response_model=list[ArchiveResponse])
  741. async def search_archives(
  742. q: str = Query(..., min_length=2, description="Search query"),
  743. printer_id: int | None = None,
  744. project_id: int | None = None,
  745. status: str | None = None,
  746. limit: int = 50,
  747. offset: int = 0,
  748. db: AsyncSession = Depends(get_db),
  749. auth_result: tuple[User | None, bool] = Depends(
  750. require_ownership_permission(
  751. Permission.ARCHIVES_READ_ALL,
  752. Permission.ARCHIVES_READ_OWN,
  753. )
  754. ),
  755. printer_scope: PrinterScope = RequestPrinterScope,
  756. ):
  757. """Full-text search across archives.
  758. Searches print_name, filename, tags, notes, designer, and filament_type fields.
  759. Supports partial matches with wildcards (e.g., 'vor*' matches 'voron').
  760. """
  761. from sqlalchemy import text
  762. from sqlalchemy.orm import selectinload
  763. from backend.app.core.db_dialect import is_sqlite
  764. user, can_read_all = auth_result
  765. own_only = user is not None and not can_read_all
  766. search_term = q.strip()
  767. # Build dialect-specific full-text search query
  768. if is_sqlite():
  769. # SQLite FTS5: wildcard suffix for partial matches
  770. if not search_term.endswith("*"):
  771. search_term = f"{search_term}*"
  772. fts_query = text("""
  773. SELECT rowid FROM archive_fts
  774. WHERE archive_fts MATCH :search_term
  775. ORDER BY rank
  776. LIMIT :limit OFFSET :offset
  777. """)
  778. else:
  779. # PostgreSQL: tsvector + plainto_tsquery with prefix matching
  780. fts_query = text("""
  781. SELECT id FROM print_archives
  782. WHERE to_tsvector('simple',
  783. COALESCE(print_name, '') || ' ' ||
  784. COALESCE(filename, '') || ' ' ||
  785. COALESCE(tags, '') || ' ' ||
  786. COALESCE(notes, '') || ' ' ||
  787. COALESCE(designer, '') || ' ' ||
  788. COALESCE(filament_type, '')
  789. ) @@ to_tsquery('simple', :search_term)
  790. LIMIT :limit OFFSET :offset
  791. """)
  792. # Convert "benchy" to "benchy:*" for prefix matching in tsquery
  793. search_term = " & ".join(f"{word}:*" for word in search_term.split() if word)
  794. try:
  795. result = await db.execute(fts_query, {"search_term": search_term, "limit": limit + 100, "offset": 0})
  796. matched_ids = [row[0] for row in result.fetchall()]
  797. except Exception as e:
  798. logger.warning("FTS search failed, falling back to LIKE search: %s", e)
  799. # Fallback to LIKE search if FTS fails
  800. like_pattern = f"%{q}%"
  801. query = (
  802. select(PrintArchive)
  803. .options(selectinload(PrintArchive.project))
  804. .where(
  805. (
  806. (PrintArchive.print_name.ilike(like_pattern))
  807. | (PrintArchive.filename.ilike(like_pattern))
  808. | (PrintArchive.tags.ilike(like_pattern))
  809. | (PrintArchive.notes.ilike(like_pattern))
  810. | (PrintArchive.designer.ilike(like_pattern))
  811. | (PrintArchive.filament_type.ilike(like_pattern))
  812. ),
  813. PrintArchive.deleted_at.is_(None),
  814. )
  815. .order_by(PrintArchive.created_at.desc())
  816. )
  817. if printer_id:
  818. query = query.where(PrintArchive.printer_id == printer_id)
  819. if project_id:
  820. query = query.where(PrintArchive.project_id == project_id)
  821. if status:
  822. query = query.where(PrintArchive.status == status)
  823. if own_only:
  824. query = query.where(PrintArchive.created_by_id == user.id)
  825. if (clause := printer_scope.where(PrintArchive.printer_id)) is not None:
  826. query = query.where(clause)
  827. query = query.limit(limit).offset(offset)
  828. result = await db.execute(query)
  829. archives = result.scalars().all()
  830. # Load run aggregates so multi-run archives' time/accuracy badge is
  831. # suppressed consistently with the main list endpoint (#1608).
  832. run_aggregates = await _load_run_aggregates(db, [a.id for a in archives])
  833. return [archive_to_response(a, run_aggregate=run_aggregates.get(a.id)) for a in archives]
  834. if not matched_ids:
  835. return []
  836. # Fetch full archive records for matched IDs (excluding soft-deleted, #1343)
  837. query = (
  838. select(PrintArchive)
  839. .options(selectinload(PrintArchive.project))
  840. .where(PrintArchive.id.in_(matched_ids), PrintArchive.deleted_at.is_(None))
  841. )
  842. if own_only:
  843. query = query.where(PrintArchive.created_by_id == user.id)
  844. if (clause := printer_scope.where(PrintArchive.printer_id)) is not None:
  845. query = query.where(clause)
  846. # Apply additional filters
  847. if printer_id:
  848. query = query.where(PrintArchive.printer_id == printer_id)
  849. if project_id:
  850. query = query.where(PrintArchive.project_id == project_id)
  851. if status:
  852. query = query.where(PrintArchive.status == status)
  853. result = await db.execute(query)
  854. archives_dict = {a.id: a for a in result.scalars().all()}
  855. # Preserve FTS ranking order and apply pagination
  856. ordered_archives = [archives_dict[id] for id in matched_ids if id in archives_dict]
  857. paginated = ordered_archives[offset : offset + limit]
  858. # Load run aggregates so multi-run archives' time/accuracy badge is
  859. # suppressed consistently with the main list endpoint (#1608).
  860. run_aggregates = await _load_run_aggregates(db, [a.id for a in paginated])
  861. return [archive_to_response(a, run_aggregate=run_aggregates.get(a.id)) for a in paginated]
  862. @router.post("/search/rebuild-index")
  863. async def rebuild_search_index(
  864. db: AsyncSession = Depends(get_db),
  865. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  866. ):
  867. """Rebuild the full-text search index from existing archives.
  868. Use this if search results seem incomplete or incorrect.
  869. """
  870. from sqlalchemy import text
  871. from backend.app.core.db_dialect import is_sqlite
  872. try:
  873. if is_sqlite():
  874. # SQLite: rebuild FTS5 virtual table
  875. await db.execute(text("DELETE FROM archive_fts"))
  876. await db.execute(
  877. text("""
  878. INSERT INTO archive_fts(rowid, print_name, filename, tags, notes, designer, filament_type)
  879. SELECT id, print_name, filename, tags, notes, designer, filament_type
  880. FROM print_archives
  881. """)
  882. )
  883. await db.commit()
  884. result = await db.execute(text("SELECT COUNT(*) FROM archive_fts"))
  885. count = result.scalar() or 0
  886. else:
  887. # PostgreSQL: GIN index is auto-maintained, just reindex
  888. await db.execute(text("REINDEX INDEX idx_archives_fulltext"))
  889. await db.commit()
  890. result = await db.execute(text("SELECT COUNT(*) FROM print_archives"))
  891. count = result.scalar() or 0
  892. return {"message": f"Search index rebuilt with {count} entries"}
  893. except Exception as e:
  894. logger.error("Failed to rebuild search index: %s", e)
  895. raise HTTPException(status_code=500, detail=f"Failed to rebuild index: {str(e)}")
  896. @router.get("/analysis/failures")
  897. async def analyze_failures(
  898. days: int | None = None,
  899. date_from: date | None = Query(None),
  900. date_to: date | None = Query(None),
  901. printer_id: int | None = None,
  902. project_id: int | None = None,
  903. created_by_id: int | None = Query(None, description="Filter by user who created the print (-1 for no user)"),
  904. db: AsyncSession = Depends(get_db),
  905. auth_result: tuple[User | None, bool] = Depends(
  906. require_ownership_permission(
  907. Permission.ARCHIVES_READ_ALL,
  908. Permission.ARCHIVES_READ_OWN,
  909. )
  910. ),
  911. printer_scope: PrinterScope = RequestPrinterScope,
  912. ):
  913. """Analyze failure patterns across prints.
  914. Returns failure statistics including:
  915. - Overall failure rate
  916. - Failures by reason, filament type, printer
  917. - Time of day distribution
  918. - Recent failures
  919. - Weekly trend
  920. """
  921. current_user, can_read_all = auth_result
  922. _validate_user_filter_permission(current_user, created_by_id)
  923. # Callers without ARCHIVES_READ_ALL are scoped to their own runs (#2).
  924. if current_user is not None and not can_read_all:
  925. created_by_id = current_user.id
  926. from backend.app.services.failure_analysis import FailureAnalysisService
  927. service = FailureAnalysisService(db)
  928. return await service.analyze_failures(
  929. days=days,
  930. date_from=date_from,
  931. date_to=date_to,
  932. printer_id=printer_id,
  933. project_id=project_id,
  934. created_by_id=created_by_id,
  935. printer_scope=printer_scope,
  936. )
  937. @router.get("/compare")
  938. async def compare_archives(
  939. archive_ids: str = Query(..., description="Comma-separated archive IDs (2-5)"),
  940. db: AsyncSession = Depends(get_db),
  941. auth_result: tuple[User | None, bool] = Depends(
  942. require_ownership_permission(
  943. Permission.ARCHIVES_READ_ALL,
  944. Permission.ARCHIVES_READ_OWN,
  945. )
  946. ),
  947. printer_scope: PrinterScope = RequestPrinterScope,
  948. ):
  949. """Compare multiple archives side by side.
  950. Compares print settings, filament usage, and print times.
  951. Also analyzes correlation between settings and success/failure.
  952. Args:
  953. archive_ids: Comma-separated list of 2-5 archive IDs to compare
  954. """
  955. from backend.app.services.archive_comparison import ArchiveComparisonService
  956. user, can_read_all = auth_result
  957. # Parse and validate archive IDs
  958. try:
  959. ids = [int(id.strip()) for id in archive_ids.split(",")]
  960. except ValueError:
  961. raise HTTPException(400, "Invalid archive IDs format")
  962. if len(ids) < 2:
  963. raise HTTPException(400, "At least 2 archives required for comparison")
  964. if len(ids) > 5:
  965. raise HTTPException(400, "Maximum 5 archives can be compared at once")
  966. # Verify the caller is allowed to see every archive in the comparison —
  967. # one not-owned id in the list would otherwise leak its full detail block.
  968. # _ensure_archive_visible raises 404 on the first miss (same 404 the
  969. # single-archive endpoint would return).
  970. if user is not None and not can_read_all:
  971. existing = await db.execute(
  972. select(PrintArchive.id, PrintArchive.created_by_id, PrintArchive.deleted_at).where(PrintArchive.id.in_(ids))
  973. )
  974. owners_by_id = {row.id: row for row in existing.all()}
  975. for archive_id in ids:
  976. row = owners_by_id.get(archive_id)
  977. if row is None or row.deleted_at is not None or row.created_by_id != user.id:
  978. raise HTTPException(404, "Archive not found")
  979. # Every compared archive must come from a printer the caller can see (#1727)
  980. if not printer_scope.is_unrestricted:
  981. printer_ids = await db.execute(select(PrintArchive.printer_id).where(PrintArchive.id.in_(ids)))
  982. if not all(printer_scope.allows(pid) for (pid,) in printer_ids.all()):
  983. raise HTTPException(404, "Archive not found")
  984. service = ArchiveComparisonService(db)
  985. try:
  986. return await service.compare_archives(ids)
  987. except ValueError as e:
  988. raise HTTPException(400, str(e))
  989. @router.get("/export")
  990. async def export_archives(
  991. format: str = Query("csv", description="Export format: csv or xlsx"),
  992. fields: str | None = Query(None, description="Comma-separated field names"),
  993. printer_id: int | None = None,
  994. project_id: int | None = None,
  995. status: str | None = None,
  996. date_from: str | None = Query(None, description="Start date (ISO format)"),
  997. date_to: str | None = Query(None, description="End date (ISO format)"),
  998. search: str | None = None,
  999. db: AsyncSession = Depends(get_db),
  1000. printer_scope: PrinterScope = RequestPrinterScope,
  1001. auth_result: tuple[User | None, bool] = Depends(
  1002. require_ownership_permission(
  1003. Permission.ARCHIVES_READ_ALL,
  1004. Permission.ARCHIVES_READ_OWN,
  1005. )
  1006. ),
  1007. ):
  1008. """Export archives to CSV or Excel format.
  1009. Returns a downloadable file with archive data.
  1010. """
  1011. from datetime import datetime
  1012. from fastapi.responses import StreamingResponse
  1013. from backend.app.services.export import ExportService
  1014. user, can_read_all = auth_result
  1015. visible_to_user_id = user.id if (user is not None and not can_read_all) else None
  1016. if format not in ("csv", "xlsx"):
  1017. raise HTTPException(400, "Format must be 'csv' or 'xlsx'")
  1018. # Parse fields
  1019. field_list = None
  1020. if fields:
  1021. field_list = [f.strip() for f in fields.split(",")]
  1022. # Parse dates
  1023. date_from_dt = None
  1024. date_to_dt = None
  1025. if date_from:
  1026. try:
  1027. date_from_dt = datetime.fromisoformat(date_from)
  1028. except ValueError:
  1029. raise HTTPException(400, "Invalid date_from format")
  1030. if date_to:
  1031. try:
  1032. date_to_dt = datetime.fromisoformat(date_to)
  1033. except ValueError:
  1034. raise HTTPException(400, "Invalid date_to format")
  1035. service = ExportService(db)
  1036. try:
  1037. file_bytes, filename, content_type = await service.export_archives(
  1038. format=format,
  1039. fields=field_list,
  1040. printer_id=printer_id,
  1041. project_id=project_id,
  1042. status=status,
  1043. date_from=date_from_dt,
  1044. date_to=date_to_dt,
  1045. search=search,
  1046. visible_to_user_id=visible_to_user_id,
  1047. printer_scope=printer_scope,
  1048. )
  1049. except ImportError as e:
  1050. raise HTTPException(500, str(e))
  1051. return StreamingResponse(
  1052. io.BytesIO(file_bytes),
  1053. media_type=content_type,
  1054. headers={"Content-Disposition": build_content_disposition(filename)},
  1055. )
  1056. @router.get("/stats/export")
  1057. async def export_stats(
  1058. format: str = Query("csv", description="Export format: csv or xlsx"),
  1059. days: int = 30,
  1060. printer_id: int | None = None,
  1061. project_id: int | None = None,
  1062. created_by_id: int | None = Query(None, description="Filter by user who created the print (-1 for no user)"),
  1063. db: AsyncSession = Depends(get_db),
  1064. current_user: User | None = RequirePermissionIfAuthEnabled(Permission.STATS_READ),
  1065. printer_scope: PrinterScope = RequestPrinterScope,
  1066. actor: User | ApiKeyActor | None = RequestActor,
  1067. ):
  1068. """Export statistics summary to CSV or Excel format."""
  1069. _validate_user_filter_permission(actor, created_by_id)
  1070. from fastapi.responses import StreamingResponse
  1071. from backend.app.services.export import ExportService
  1072. if format not in ("csv", "xlsx"):
  1073. raise HTTPException(400, "Format must be 'csv' or 'xlsx'")
  1074. service = ExportService(db)
  1075. try:
  1076. file_bytes, filename, content_type = await service.export_stats(
  1077. format=format,
  1078. days=days,
  1079. printer_id=printer_id,
  1080. project_id=project_id,
  1081. created_by_id=created_by_id,
  1082. printer_scope=printer_scope,
  1083. )
  1084. except ImportError as e:
  1085. raise HTTPException(500, str(e))
  1086. return StreamingResponse(
  1087. io.BytesIO(file_bytes),
  1088. media_type=content_type,
  1089. headers={"Content-Disposition": build_content_disposition(filename)},
  1090. )
  1091. @router.get("/stats", response_model=ArchiveStats)
  1092. async def get_archive_stats(
  1093. date_from: date | None = Query(None, description="Start date (inclusive), YYYY-MM-DD"),
  1094. date_to: date | None = Query(None, description="End date (inclusive), YYYY-MM-DD"),
  1095. created_by_id: int | None = Query(None, description="Filter by user who created the print (-1 for no user)"),
  1096. db: AsyncSession = Depends(get_db),
  1097. current_user: User | None = RequirePermissionIfAuthEnabled(Permission.STATS_READ),
  1098. printer_scope: PrinterScope = RequestPrinterScope,
  1099. actor: User | ApiKeyActor | None = RequestActor,
  1100. ):
  1101. """Get statistics across all archives.
  1102. Stats aggregate over PrintLogEntry (one row per print event), not over
  1103. PrintArchive (one row per file). A reprint contributes a new PrintLogEntry
  1104. so its filament/cost/time/energy add to the totals instead of overwriting
  1105. the source archive's first-run values (#1378).
  1106. """
  1107. from backend.app.models.print_log import PrintLogEntry
  1108. _validate_user_filter_permission(actor, created_by_id)
  1109. # Build date filter conditions scoped to PrintLogEntry (event-time).
  1110. base_conditions = []
  1111. if date_from:
  1112. dt_from = datetime.combine(date_from, time.min, tzinfo=timezone.utc)
  1113. base_conditions.append(PrintLogEntry.created_at >= dt_from)
  1114. if date_to:
  1115. dt_to = datetime.combine(date_to, time.max, tzinfo=timezone.utc)
  1116. base_conditions.append(PrintLogEntry.created_at <= dt_to)
  1117. _apply_run_user_filter(base_conditions, created_by_id)
  1118. # Only prints on printers the caller may see (#1727)
  1119. if (clause := printer_scope.where(PrintLogEntry.printer_id)) is not None:
  1120. base_conditions.append(clause)
  1121. # Total counts (one row per print event).
  1122. total_result = await db.execute(select(func.count(PrintLogEntry.id)).where(*base_conditions))
  1123. total_prints = total_result.scalar() or 0
  1124. successful_result = await db.execute(
  1125. select(func.count(PrintLogEntry.id)).where(PrintLogEntry.status == "completed", *base_conditions)
  1126. )
  1127. successful_prints = successful_result.scalar() or 0
  1128. failed_result = await db.execute(
  1129. select(func.count(PrintLogEntry.id)).where(PrintLogEntry.status.in_(("failed", "aborted")), *base_conditions)
  1130. )
  1131. failed_prints = failed_result.scalar() or 0
  1132. # User/system-stopped prints — stopped/cancelled/skipped are distinct from
  1133. # quality failures: the user (or the queue) interrupted them, the printer
  1134. # didn't detect a fault. Bucketed separately so the Success Rate gauge
  1135. # divides by completed + failed only (a cancelled print shouldn't drag
  1136. # the gauge down), while still being visible in the breakdown so they
  1137. # don't silently vanish from Total Prints (#1390).
  1138. cancelled_result = await db.execute(
  1139. select(func.count(PrintLogEntry.id)).where(
  1140. PrintLogEntry.status.in_(("stopped", "cancelled", "skipped")), *base_conditions
  1141. )
  1142. )
  1143. cancelled_prints = cancelled_result.scalar() or 0
  1144. # Total elapsed time — PrintLogEntry stores duration_seconds directly so we
  1145. # can sum it server-side. Rows missing duration fall back to the slicer
  1146. # estimate from the archive (joined for that case only).
  1147. time_rows = await db.execute(
  1148. select(
  1149. PrintLogEntry.duration_seconds,
  1150. PrintLogEntry.started_at,
  1151. PrintLogEntry.completed_at,
  1152. ).where(*base_conditions)
  1153. )
  1154. total_seconds = 0
  1155. for duration_seconds, started_at, completed_at in time_rows.all():
  1156. # Trust an explicitly stored duration, INCLUDING 0: a reconciled abort
  1157. # stores 0 on purpose because its real end time is unknown, and the
  1158. # started_at→completed_at fallback would otherwise bank the whole
  1159. # multi-day disconnect gap as print time (#2592). Only rows with a NULL
  1160. # duration (legacy entries that never recorded one) fall back.
  1161. if duration_seconds is not None:
  1162. total_seconds += duration_seconds
  1163. elif started_at and completed_at:
  1164. elapsed = (completed_at - started_at).total_seconds()
  1165. if elapsed > 0:
  1166. total_seconds += int(elapsed)
  1167. total_time = total_seconds / 3600 # Convert to hours
  1168. filament_result = await db.execute(
  1169. select(func.coalesce(func.sum(PrintLogEntry.filament_used_grams), 0)).where(*base_conditions)
  1170. )
  1171. total_filament = filament_result.scalar() or 0
  1172. cost_result = await db.execute(select(func.sum(PrintLogEntry.cost)).where(*base_conditions))
  1173. total_cost = cost_result.scalar() or 0
  1174. wear_result = await db.execute(select(func.sum(PrintLogEntry.wear_cost)).where(*base_conditions))
  1175. total_wear_cost = wear_result.scalar() or 0
  1176. # By filament type (split comma-separated values for multi-material prints)
  1177. filament_type_result = await db.execute(
  1178. select(PrintLogEntry.filament_type).where(PrintLogEntry.filament_type.isnot(None), *base_conditions)
  1179. )
  1180. prints_by_filament: dict[str, int] = {}
  1181. for (filament_types,) in filament_type_result.all():
  1182. for ftype in filament_types.split(","):
  1183. ftype = ftype.strip()
  1184. if ftype:
  1185. prints_by_filament[ftype] = prints_by_filament.get(ftype, 0) + 1
  1186. # By printer
  1187. printer_result = await db.execute(
  1188. select(PrintLogEntry.printer_id, func.count(PrintLogEntry.id))
  1189. .where(*base_conditions)
  1190. .group_by(PrintLogEntry.printer_id)
  1191. )
  1192. prints_by_printer = {str(k): v for k, v in printer_result.all()}
  1193. # Names for printers the client can no longer look up. The breakdowns above
  1194. # key on the id each run recorded, and deleting a printer while keeping its
  1195. # history leaves that id pointing at nothing, so a chart that used to read
  1196. # "Ultron" fell back to "Printer 1" (#2873). Every run also stored the name
  1197. # it printed on, so the last one recorded is what that id was called. The
  1198. # client still prefers a live printer's current name, which keeps a rename
  1199. # showing up straight away.
  1200. last_named_run = (
  1201. select(func.max(PrintLogEntry.id).label("entry_id"))
  1202. .where(
  1203. PrintLogEntry.printer_id.isnot(None),
  1204. PrintLogEntry.printer_name.isnot(None),
  1205. *base_conditions,
  1206. )
  1207. .group_by(PrintLogEntry.printer_id)
  1208. .subquery()
  1209. )
  1210. name_result = await db.execute(
  1211. select(PrintLogEntry.printer_id, PrintLogEntry.printer_name).join(
  1212. last_named_run, PrintLogEntry.id == last_named_run.c.entry_id
  1213. )
  1214. )
  1215. printer_names = {str(printer_id): name for printer_id, name in name_result.all()}
  1216. # Time accuracy — compare each completed run's actual duration to the
  1217. # slicer's estimate on the linked archive. Runs without a linked archive
  1218. # (NULL archive_id) or without an estimate are excluded.
  1219. accuracy_rows = await db.execute(
  1220. select(
  1221. PrintLogEntry.duration_seconds,
  1222. PrintLogEntry.started_at,
  1223. PrintLogEntry.completed_at,
  1224. PrintLogEntry.printer_id,
  1225. PrintArchive.print_time_seconds,
  1226. )
  1227. .join(PrintArchive, PrintArchive.id == PrintLogEntry.archive_id)
  1228. .where(
  1229. PrintLogEntry.status == "completed",
  1230. PrintArchive.print_time_seconds.isnot(None),
  1231. *base_conditions,
  1232. )
  1233. )
  1234. # Accuracy is meaningful only when the estimate roughly describes the
  1235. # work the run actually performed. Two shapes produce wildly-off ratios
  1236. # that are pure noise:
  1237. # - multi-plate ``.gcode.3mf`` printed plate-by-plate: each run's
  1238. # actual is one plate, the archive's estimate is the sum across
  1239. # plates (post-#1593 parser fix), so the ratio is roughly N×100%
  1240. # for an N-plate file. Pre-fix this shape was also broken, just
  1241. # less dramatically — the estimate was plate-1-only so the ratio
  1242. # was meaningless rather than N×.
  1243. # - manual interventions / purge waste blowing the actual far past
  1244. # the estimate.
  1245. # Clamp to the [50%, 200%] band so the printer-level average reflects
  1246. # real slicer-vs-reality drift, not multi-plate accounting or one-off
  1247. # outliers. Single-plate archives — the case the metric is actually
  1248. # designed for — stay fully included.
  1249. _ACCURACY_BAND_LO = 50.0
  1250. _ACCURACY_BAND_HI = 200.0
  1251. average_accuracy = None
  1252. accuracy_by_printer: dict[str, float] = {}
  1253. accuracies: list[float] = []
  1254. printer_accuracies: dict[str, list[float]] = {}
  1255. for duration_seconds, started_at, completed_at, run_printer_id, estimate_seconds in accuracy_rows.all():
  1256. actual_seconds = duration_seconds
  1257. if not actual_seconds and started_at and completed_at:
  1258. elapsed = (completed_at - started_at).total_seconds()
  1259. actual_seconds = int(elapsed) if elapsed > 0 else None
  1260. if not actual_seconds or not estimate_seconds:
  1261. continue
  1262. accuracy = (estimate_seconds / actual_seconds) * 100
  1263. if accuracy < _ACCURACY_BAND_LO or accuracy > _ACCURACY_BAND_HI:
  1264. continue
  1265. accuracies.append(accuracy)
  1266. printer_key = str(run_printer_id) if run_printer_id else "unknown"
  1267. printer_accuracies.setdefault(printer_key, []).append(accuracy)
  1268. if accuracies:
  1269. average_accuracy = round(sum(accuracies) / len(accuracies), 1)
  1270. for printer_key, accs in printer_accuracies.items():
  1271. accuracy_by_printer[printer_key] = round(sum(accs) / len(accs), 1)
  1272. # Energy totals - check which mode to use
  1273. from backend.app.api.routes.settings import get_setting
  1274. from backend.app.services.energy_price import (
  1275. all_time_cost,
  1276. cost_at_average_price,
  1277. snapshot_cost,
  1278. stored_price,
  1279. )
  1280. energy_tracking_mode = await get_setting(db, "energy_tracking_mode") or "total"
  1281. # The last price known. Not read from Home Assistant here: the snapshot
  1282. # loop refreshes it hourly, and it only prices the energy since then.
  1283. energy_cost_per_kwh = await stored_price(db)
  1284. total_energy_kwh: float = 0.0
  1285. total_energy_cost: float = 0.0
  1286. energy_data_warming_up = False
  1287. if energy_tracking_mode == "total" and not date_from and not date_to:
  1288. # All-time total consumption — read live lifetime counters, costed at
  1289. # the price of each hour the snapshots cover (#1251).
  1290. total_energy_kwh = await _sum_live_plug_totals(db)
  1291. total_energy_cost = await all_time_cost(db, total_energy_kwh, energy_cost_per_kwh)
  1292. elif energy_tracking_mode == "total":
  1293. # Total consumption mode with a date filter (#941): use hourly snapshots
  1294. # to compute per-plug (endpoint - baseline) deltas.
  1295. dt_from = datetime.combine(date_from, time.min, tzinfo=timezone.utc) if date_from else None
  1296. dt_to = datetime.combine(date_to, time.max, tzinfo=timezone.utc) if date_to else None
  1297. total_energy_kwh, energy_data_warming_up = await _sum_snapshot_deltas(db, dt_from=dt_from, dt_to=dt_to)
  1298. costed = await snapshot_cost(db, fallback_price=energy_cost_per_kwh, dt_from=dt_from, dt_to=dt_to)
  1299. total_energy_cost = cost_at_average_price(total_energy_kwh, costed.kwh, costed.cost, energy_cost_per_kwh)
  1300. else:
  1301. # Per-print mode: sum the per-run energy column from PrintLogEntry.
  1302. energy_kwh_result = await db.execute(select(func.sum(PrintLogEntry.energy_kwh)).where(*base_conditions))
  1303. total_energy_kwh = energy_kwh_result.scalar() or 0
  1304. energy_cost_result = await db.execute(select(func.sum(PrintLogEntry.energy_cost)).where(*base_conditions))
  1305. total_energy_cost = energy_cost_result.scalar() or 0
  1306. return ArchiveStats(
  1307. total_prints=total_prints,
  1308. successful_prints=successful_prints,
  1309. failed_prints=failed_prints,
  1310. cancelled_prints=cancelled_prints,
  1311. total_print_time_hours=round(total_time, 1),
  1312. total_filament_grams=round(total_filament, 1),
  1313. total_cost=round(total_cost, 2),
  1314. prints_by_filament_type=prints_by_filament,
  1315. prints_by_printer=prints_by_printer,
  1316. printer_names=printer_names,
  1317. average_time_accuracy=average_accuracy,
  1318. time_accuracy_by_printer=accuracy_by_printer if accuracy_by_printer else None,
  1319. total_energy_kwh=round(total_energy_kwh, 3),
  1320. total_energy_cost=round(total_energy_cost, 3),
  1321. total_wear_cost=round(total_wear_cost, 2),
  1322. energy_data_warming_up=energy_data_warming_up,
  1323. )
  1324. async def _sum_live_plug_totals(db: AsyncSession) -> float:
  1325. """Sum the live lifetime counter from every smart plug.
  1326. Used for all-time "total consumption" mode. Only the current value is
  1327. available so this can't be date-filtered — use `_sum_snapshot_deltas` for
  1328. that case.
  1329. """
  1330. from backend.app.api.routes.settings import get_setting
  1331. from backend.app.models.smart_plug import SmartPlug
  1332. from backend.app.services.homeassistant import homeassistant_service
  1333. from backend.app.services.mqtt_relay import mqtt_relay
  1334. from backend.app.services.rest_smart_plug import rest_smart_plug_service
  1335. from backend.app.services.tasmota import tasmota_service
  1336. plugs_result = await db.execute(select(SmartPlug))
  1337. plugs = list(plugs_result.scalars().all())
  1338. ha_url = await get_setting(db, "ha_url") or ""
  1339. ha_token = await get_setting(db, "ha_token") or ""
  1340. homeassistant_service.configure(ha_url, ha_token)
  1341. total = 0.0
  1342. for plug in plugs:
  1343. if plug.plug_type == "tasmota":
  1344. energy = await tasmota_service.get_energy(plug)
  1345. if energy and energy.get("total") is not None:
  1346. total += energy["total"]
  1347. elif plug.plug_type == "homeassistant":
  1348. energy = await homeassistant_service.get_energy(plug)
  1349. if energy and energy.get("total") is not None:
  1350. total += energy["total"]
  1351. elif plug.plug_type == "mqtt":
  1352. # MQTT plugs only expose today's counter, not lifetime.
  1353. mqtt_data = mqtt_relay.smart_plug_service.get_plug_data(plug.id)
  1354. if mqtt_data and mqtt_data.energy is not None:
  1355. total += mqtt_data.energy
  1356. elif plug.plug_type == "rest":
  1357. # A REST device that exposes only a lifetime counter (Shelly
  1358. # ``aenergy.total`` via ``rest_energy_total_path``) returns no
  1359. # ``today`` key, so read the lifetime total first, like the
  1360. # Tasmota/HA branches above. ``today`` stays as the fallback for
  1361. # devices that only have a daily counter.
  1362. energy = await rest_smart_plug_service.get_energy(plug)
  1363. if energy:
  1364. value = energy.get("total")
  1365. if value is None:
  1366. value = energy.get("today")
  1367. if value is not None:
  1368. total += value
  1369. return total
  1370. async def _sum_snapshot_deltas(
  1371. db: AsyncSession,
  1372. *,
  1373. dt_from: datetime | None,
  1374. dt_to: datetime | None,
  1375. ) -> tuple[float, bool]:
  1376. """Sum per-plug energy consumption over a date range using hourly snapshots.
  1377. For each plug:
  1378. * baseline = last snapshot at or before `dt_from` (ideal)
  1379. — if missing, fall back to the earliest snapshot ever
  1380. recorded for the plug and flag the result as warming up.
  1381. * endpoint = last snapshot at or before `dt_to` (or most recent overall)
  1382. * delta = max(0, endpoint - baseline) — clamp counter resets to 0.
  1383. Returns (total_kwh, warming_up). `warming_up = True` means at least one plug
  1384. had no baseline before `dt_from` (fresh install or fresh upgrade), so the
  1385. result undercounts the beginning of the range.
  1386. """
  1387. from backend.app.models.smart_plug import SmartPlug
  1388. from backend.app.models.smart_plug_energy_snapshot import SmartPlugEnergySnapshot
  1389. from backend.app.utils.local_time import to_naive_utc
  1390. # ``recorded_at`` is a naive column holding UTC. Binding an aware datetime
  1391. # against it raises DataError on asyncpg (SQLite silently drops the offset),
  1392. # which took the whole date-filtered energy figure down on Postgres.
  1393. dt_from = to_naive_utc(dt_from)
  1394. dt_to = to_naive_utc(dt_to)
  1395. plug_ids_result = await db.execute(select(SmartPlug.id))
  1396. plug_ids = [row[0] for row in plug_ids_result.all()]
  1397. if not plug_ids:
  1398. return 0.0, False
  1399. total = 0.0
  1400. warming_up = False
  1401. for plug_id in plug_ids:
  1402. baseline: float | None = None
  1403. if dt_from is not None:
  1404. baseline_q = await db.execute(
  1405. select(SmartPlugEnergySnapshot.lifetime_kwh)
  1406. .where(
  1407. SmartPlugEnergySnapshot.plug_id == plug_id,
  1408. SmartPlugEnergySnapshot.recorded_at <= dt_from,
  1409. )
  1410. .order_by(SmartPlugEnergySnapshot.recorded_at.desc())
  1411. .limit(1)
  1412. )
  1413. baseline = baseline_q.scalar()
  1414. if baseline is None:
  1415. # No snapshot before range start — fall back to the earliest
  1416. # snapshot ever recorded. Result undercounts the pre-first-snapshot
  1417. # portion of the range; signal that to the frontend.
  1418. earliest_q = await db.execute(
  1419. select(SmartPlugEnergySnapshot.lifetime_kwh)
  1420. .where(SmartPlugEnergySnapshot.plug_id == plug_id)
  1421. .order_by(SmartPlugEnergySnapshot.recorded_at.asc())
  1422. .limit(1)
  1423. )
  1424. baseline = earliest_q.scalar()
  1425. if baseline is None:
  1426. # No snapshots at all for this plug yet.
  1427. warming_up = True
  1428. continue
  1429. warming_up = True
  1430. endpoint_conditions = [SmartPlugEnergySnapshot.plug_id == plug_id]
  1431. if dt_to is not None:
  1432. endpoint_conditions.append(SmartPlugEnergySnapshot.recorded_at <= dt_to)
  1433. endpoint_q = await db.execute(
  1434. select(SmartPlugEnergySnapshot.lifetime_kwh)
  1435. .where(*endpoint_conditions)
  1436. .order_by(SmartPlugEnergySnapshot.recorded_at.desc())
  1437. .limit(1)
  1438. )
  1439. endpoint = endpoint_q.scalar()
  1440. if endpoint is None:
  1441. continue
  1442. total += max(0.0, endpoint - baseline)
  1443. return total, warming_up
  1444. @router.get("/tags")
  1445. async def get_all_tags(
  1446. db: AsyncSession = Depends(get_db),
  1447. auth_result: tuple[User | None, bool] = Depends(
  1448. require_ownership_permission(
  1449. Permission.ARCHIVES_READ_ALL,
  1450. Permission.ARCHIVES_READ_OWN,
  1451. )
  1452. ),
  1453. ):
  1454. """List all unique tags with usage counts.
  1455. Returns a list of tags sorted by count (descending), then by name.
  1456. """
  1457. user, can_read_all = auth_result
  1458. # Query all archives with non-null tags
  1459. tag_conditions = [PrintArchive.tags.isnot(None), PrintArchive.deleted_at.is_(None)]
  1460. if user is not None and not can_read_all:
  1461. tag_conditions.append(PrintArchive.created_by_id == user.id)
  1462. result = await db.execute(select(PrintArchive.tags).where(*tag_conditions))
  1463. all_tags_rows = result.all()
  1464. # Count occurrences of each tag
  1465. tag_counts: dict[str, int] = {}
  1466. for (tags_str,) in all_tags_rows:
  1467. if tags_str:
  1468. for tag in tags_str.split(","):
  1469. tag = tag.strip()
  1470. if tag:
  1471. tag_counts[tag] = tag_counts.get(tag, 0) + 1
  1472. # Convert to list and sort by count (desc), then name (asc)
  1473. tags_list = [{"name": name, "count": count} for name, count in tag_counts.items()]
  1474. tags_list.sort(key=lambda x: (-x["count"], x["name"].lower()))
  1475. return tags_list
  1476. @router.put("/tags/{tag_name}")
  1477. async def rename_tag(
  1478. tag_name: str,
  1479. request: Request,
  1480. db: AsyncSession = Depends(get_db),
  1481. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  1482. ):
  1483. """Rename a tag across all archives.
  1484. Request body should contain {"new_name": "new tag name"}.
  1485. Returns the count of affected archives.
  1486. """
  1487. body = await request.json()
  1488. new_name = body.get("new_name", "").strip()
  1489. if not new_name:
  1490. raise HTTPException(400, "new_name is required")
  1491. if new_name == tag_name:
  1492. return {"affected": 0}
  1493. # Find all archives containing the old tag
  1494. result = await db.execute(
  1495. select(PrintArchive).where(PrintArchive.tags.isnot(None), PrintArchive.deleted_at.is_(None))
  1496. )
  1497. archives = list(result.scalars().all())
  1498. affected = 0
  1499. for archive in archives:
  1500. if not archive.tags:
  1501. continue
  1502. tags = [t.strip() for t in archive.tags.split(",")]
  1503. if tag_name in tags:
  1504. # Replace old tag with new tag
  1505. new_tags = [new_name if t == tag_name else t for t in tags]
  1506. # Remove duplicates while preserving order
  1507. seen = set()
  1508. unique_tags = []
  1509. for t in new_tags:
  1510. if t not in seen:
  1511. seen.add(t)
  1512. unique_tags.append(t)
  1513. archive.tags = ", ".join(unique_tags)
  1514. affected += 1
  1515. await db.commit()
  1516. return {"affected": affected}
  1517. @router.delete("/tags/{tag_name}")
  1518. async def delete_tag(
  1519. tag_name: str,
  1520. db: AsyncSession = Depends(get_db),
  1521. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  1522. ):
  1523. """Delete a tag from all archives.
  1524. Returns the count of affected archives.
  1525. """
  1526. # Find all archives containing the tag
  1527. result = await db.execute(
  1528. select(PrintArchive).where(PrintArchive.tags.isnot(None), PrintArchive.deleted_at.is_(None))
  1529. )
  1530. archives = list(result.scalars().all())
  1531. affected = 0
  1532. for archive in archives:
  1533. if not archive.tags:
  1534. continue
  1535. tags = [t.strip() for t in archive.tags.split(",")]
  1536. if tag_name in tags:
  1537. # Remove the tag
  1538. new_tags = [t for t in tags if t != tag_name]
  1539. archive.tags = ", ".join(new_tags) if new_tags else None
  1540. affected += 1
  1541. await db.commit()
  1542. return {"affected": affected}
  1543. @router.get("/{archive_id}", response_model=ArchiveResponse)
  1544. async def get_archive(
  1545. archive_id: int,
  1546. db: AsyncSession = Depends(get_db),
  1547. auth_result: tuple[User | None, bool] = Depends(
  1548. require_ownership_permission(
  1549. Permission.ARCHIVES_READ_ALL,
  1550. Permission.ARCHIVES_READ_OWN,
  1551. )
  1552. ),
  1553. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1554. ):
  1555. """Get a specific archive."""
  1556. user, can_read_all = auth_result
  1557. service = ArchiveService(db)
  1558. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  1559. # Find duplicates
  1560. makerworld_id = archive.extra_data.get("makerworld_model_id") if archive.extra_data else None
  1561. duplicates = await service.find_duplicates(
  1562. archive_id=archive.id,
  1563. content_hash=archive.content_hash,
  1564. print_name=archive.print_name,
  1565. makerworld_model_id=makerworld_id,
  1566. )
  1567. run_aggregates = await _load_run_aggregates(db, [archive.id])
  1568. return archive_to_response(archive, duplicates, run_aggregate=run_aggregates.get(archive.id))
  1569. @router.get("/{archive_id}/delete-impact")
  1570. async def get_archive_delete_impact(
  1571. archive_id: int,
  1572. db: AsyncSession = Depends(get_db),
  1573. auth_result: tuple[User | None, bool] = Depends(
  1574. require_ownership_permission(
  1575. Permission.ARCHIVES_READ_ALL,
  1576. Permission.ARCHIVES_READ_OWN,
  1577. )
  1578. ),
  1579. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1580. ):
  1581. """Pre-flight for the delete-confirm modal (#1734).
  1582. Returns the number of related queue items the user is about to remove
  1583. AND whether any of them are currently printing (which would block the
  1584. delete with a 409 — surfaced to the modal so it can disable the
  1585. confirm button instead of failing on submit). Cheap, single endpoint —
  1586. not folded into the archive GET response so the much larger list
  1587. endpoint isn't forced to run the same query per row.
  1588. """
  1589. user, can_read_all = auth_result
  1590. service = ArchiveService(db)
  1591. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  1592. from backend.app.services.archive import _count_related_queue_items
  1593. total, printing = await _count_related_queue_items(db, archive.id)
  1594. return {"related_queue_items": total, "currently_printing": printing}
  1595. @router.get("/{archive_id}/runs", response_model=PrintLogResponse)
  1596. async def list_archive_runs(
  1597. archive_id: int,
  1598. db: AsyncSession = Depends(get_db),
  1599. auth_result: tuple[User | None, bool] = Depends(
  1600. require_ownership_permission(
  1601. Permission.ARCHIVES_READ_ALL,
  1602. Permission.ARCHIVES_READ_OWN,
  1603. )
  1604. ),
  1605. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1606. ):
  1607. """List PrintLogEntry rows for this archive — one per print event.
  1608. Newest first. Drives the per-archive "Print Log" view (#1378).
  1609. """
  1610. from backend.app.models.print_log import PrintLogEntry
  1611. from backend.app.schemas.print_log import PrintLogEntrySchema
  1612. user, can_read_all = auth_result
  1613. _ensure_archive_visible(await db.get(PrintArchive, archive_id), user, can_read_all, printer_scope)
  1614. rows = await db.execute(
  1615. select(PrintLogEntry)
  1616. .where(PrintLogEntry.archive_id == archive_id)
  1617. .order_by(PrintLogEntry.started_at.desc().nulls_last(), PrintLogEntry.id.desc())
  1618. )
  1619. entries = list(rows.scalars().all())
  1620. items = [PrintLogEntrySchema.model_validate(e, from_attributes=True) for e in entries]
  1621. return PrintLogResponse(items=items, total=len(items))
  1622. @router.get("/{archive_id}/similar")
  1623. async def find_similar_archives(
  1624. archive_id: int,
  1625. limit: int = 10,
  1626. db: AsyncSession = Depends(get_db),
  1627. auth_result: tuple[User | None, bool] = Depends(
  1628. require_ownership_permission(
  1629. Permission.ARCHIVES_READ_ALL,
  1630. Permission.ARCHIVES_READ_OWN,
  1631. )
  1632. ),
  1633. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1634. ):
  1635. """Find archives with similar settings for comparison.
  1636. Returns archives that match by:
  1637. - Same print name (highest priority)
  1638. - Same file content hash
  1639. - Same filament type
  1640. """
  1641. from backend.app.services.archive_comparison import ArchiveComparisonService
  1642. user, can_read_all = auth_result
  1643. _ensure_archive_visible(await db.get(PrintArchive, archive_id), user, can_read_all, printer_scope)
  1644. service = ArchiveComparisonService(db)
  1645. try:
  1646. return await service.find_similar_archives(archive_id, limit=limit)
  1647. except ValueError as e:
  1648. raise HTTPException(404, str(e))
  1649. @router.patch("/{archive_id}", response_model=ArchiveResponse)
  1650. async def update_archive(
  1651. archive_id: int,
  1652. update_data: ArchiveUpdate,
  1653. db: AsyncSession = Depends(get_db),
  1654. auth_result: tuple[User | None, bool] = Depends(
  1655. require_ownership_permission(
  1656. Permission.ARCHIVES_UPDATE_ALL,
  1657. Permission.ARCHIVES_UPDATE_OWN,
  1658. )
  1659. ),
  1660. printer_scope: PrinterScope = RequestPrinterScope,
  1661. ):
  1662. """Update archive metadata (tags, notes, cost, filament grams, is_favorite, project_id)."""
  1663. from sqlalchemy.orm import selectinload
  1664. user, can_modify_all = auth_result
  1665. result = await db.execute(
  1666. select(PrintArchive)
  1667. .options(selectinload(PrintArchive.project), selectinload(PrintArchive.created_by))
  1668. .where(PrintArchive.id == archive_id)
  1669. )
  1670. archive = result.scalar_one_or_none()
  1671. if not archive or not printer_scope.allows(archive.printer_id):
  1672. raise HTTPException(404, "Archive not found")
  1673. # Ownership check
  1674. if not can_modify_all:
  1675. if archive.created_by_id != user.id:
  1676. raise HTTPException(403, "You can only update your own archives")
  1677. # Read before the writes below: the mirror needs to know whether the run's
  1678. # figure was inherited from this archive or measured on its own (#1820).
  1679. previous_filament_grams = archive.filament_used_grams
  1680. update_payload = update_data.model_dump(exclude_unset=True)
  1681. # #1898: how the verdict arrived is recorded with it, never on its own.
  1682. verdict_source = update_payload.pop("user_verdict_source", None)
  1683. for field, value in update_payload.items():
  1684. setattr(archive, field, value)
  1685. # #1898: a landed verdict retires the one-tap capability token from the
  1686. # push notification — the links stop changing anything once someone
  1687. # decided, and report the recorded verdict instead. Clearing the verdict
  1688. # drops the provenance but leaves the token spent: it was used.
  1689. if "user_verdict" in update_payload:
  1690. if update_payload["user_verdict"] is None:
  1691. archive.user_verdict_source = None
  1692. archive.user_verdict_at = None
  1693. else:
  1694. stamp_verdict(archive, verdict_source or "api")
  1695. retire_confirm_token(archive)
  1696. # #1444: Mirror per-run classification fields to the most recent
  1697. # PrintLogEntry for this archive. PrintLogEntry.failure_reason is captured
  1698. # once at print-completion time from archive.failure_reason — which is
  1699. # NULL until the user classifies the failure via the Edit Archive modal.
  1700. # Without this mirror the Failure Analysis widget (which groups by
  1701. # print_log_entries.failure_reason) keeps showing "Unknown" forever.
  1702. # Same desync hits status: flipping it in the modal wouldn't update the
  1703. # entry either. Only the latest entry is touched because that's the run
  1704. # the modal is implicitly showing (archive.failure_reason / status are
  1705. # overwritten on each reprint to reflect the latest run's outcome).
  1706. # filament_used_grams rides along for the same reason (#1820): the filament
  1707. # totals on the Projects page and in the Prometheus metrics sum the LOG
  1708. # ENTRY's grams, not the archive's, so correcting only the archive would fix
  1709. # the card and leave every aggregate reading the old figure -- or, for a
  1710. # print that archived without its 3MF, no figure at all.
  1711. mirror_fields = {"failure_reason", "status", "filament_used_grams", "user_verdict"}
  1712. to_mirror = {k: v for k, v in update_payload.items() if k in mirror_fields}
  1713. if to_mirror:
  1714. from backend.app.models.print_log import PrintLogEntry
  1715. latest_entry = await db.scalar(
  1716. select(PrintLogEntry)
  1717. .where(PrintLogEntry.archive_id == archive_id)
  1718. .order_by(PrintLogEntry.id.desc())
  1719. .limit(1)
  1720. )
  1721. if latest_entry is not None:
  1722. # ...but never over a figure the run measured for itself. A run's
  1723. # grams come from the tracked spool delta when there is one, and
  1724. # only fall back to copying the archive's estimate when there is
  1725. # not (see _compute_run_filament_grams). Overwriting a measurement
  1726. # with a typed estimate would lose the better number; the case this
  1727. # edit exists for -- a print archived with no 3MF -- leaves the run
  1728. # with nothing at all, so it is covered by the None arm.
  1729. if "filament_used_grams" in to_mirror and not (
  1730. latest_entry.filament_used_grams is None or latest_entry.filament_used_grams == previous_filament_grams
  1731. ):
  1732. del to_mirror["filament_used_grams"]
  1733. for field, value in to_mirror.items():
  1734. setattr(latest_entry, field, value)
  1735. await db.commit()
  1736. # Re-fetch with relationships loaded after commit
  1737. result = await db.execute(
  1738. select(PrintArchive)
  1739. .options(selectinload(PrintArchive.project), selectinload(PrintArchive.created_by))
  1740. .where(PrintArchive.id == archive_id)
  1741. )
  1742. archive = result.scalar_one_or_none()
  1743. # Load run aggregate so the time/accuracy badge stays consistent with
  1744. # the list / detail endpoints when the frontend re-renders the card
  1745. # after a PATCH (#1608).
  1746. run_aggregates = await _load_run_aggregates(db, [archive.id]) if archive else {}
  1747. return archive_to_response(archive, run_aggregate=run_aggregates.get(archive.id) if archive else None)
  1748. @router.post("/{archive_id}/favorite", response_model=ArchiveResponse)
  1749. async def toggle_favorite(
  1750. archive_id: int,
  1751. db: AsyncSession = Depends(get_db),
  1752. auth_result: tuple[User | None, bool] = Depends(
  1753. require_ownership_permission(
  1754. Permission.ARCHIVES_UPDATE_ALL,
  1755. Permission.ARCHIVES_UPDATE_OWN,
  1756. )
  1757. ),
  1758. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1759. ):
  1760. """Toggle favorite status for an archive."""
  1761. user, can_modify_all = auth_result
  1762. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  1763. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  1764. archive.is_favorite = not archive.is_favorite
  1765. await db.commit()
  1766. await db.refresh(archive)
  1767. return archive
  1768. async def _spoolman_owns_cost(db: AsyncSession) -> bool:
  1769. """True when per-spool pricing lives in Spoolman rather than in our tables.
  1770. Both cost recalculations below rebuild a print's cost from
  1771. ``SpoolUsageHistory``, and fall back to the built-in Filament catalogue or
  1772. the global default rate when there are no rows for it. In Spoolman mode
  1773. there are never any rows -- the built-in usage tracker is handed
  1774. ``spoolman_owns_usage`` at print start and writes none -- so that fallback
  1775. is not a recalculation, it is a downgrade: it would overwrite the
  1776. Spoolman-priced figure ``spoolman_tracking`` recorded at completion with a
  1777. default-rate one, and the per-slot spool resolution it came from is
  1778. transient and cannot be rebuilt here (#2591).
  1779. """
  1780. from backend.app.api.routes.settings import get_setting
  1781. setting = await get_setting(db, "spoolman_enabled")
  1782. return bool(setting) and setting.lower() == "true"
  1783. @router.post("/{archive_id}/rescan", response_model=ArchiveResponse)
  1784. async def rescan_archive(
  1785. archive_id: int,
  1786. db: AsyncSession = Depends(get_db),
  1787. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  1788. printer_scope: PrinterScope = RequestPrinterScope,
  1789. ):
  1790. """Rescan the 3MF file and update metadata."""
  1791. from backend.app.api.routes.settings import get_setting
  1792. from backend.app.services.archive import ThreeMFParser
  1793. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  1794. archive = result.scalar_one_or_none()
  1795. if not archive or not printer_scope.allows(archive.printer_id):
  1796. raise HTTPException(404, "Archive not found")
  1797. file_path = settings.base_dir / archive.file_path
  1798. if not file_path.is_file():
  1799. raise HTTPException(404, "Archive file not found")
  1800. # Parse the 3MF file
  1801. parser = ThreeMFParser(file_path)
  1802. metadata = parser.parse()
  1803. # Update fields from metadata
  1804. if metadata.get("filament_type"):
  1805. archive.filament_type = metadata["filament_type"]
  1806. if metadata.get("filament_color"):
  1807. archive.filament_color = metadata["filament_color"]
  1808. if metadata.get("print_time_seconds"):
  1809. archive.print_time_seconds = metadata["print_time_seconds"]
  1810. if metadata.get("filament_used_grams"):
  1811. archive.filament_used_grams = metadata["filament_used_grams"]
  1812. if metadata.get("layer_height"):
  1813. archive.layer_height = metadata["layer_height"]
  1814. if metadata.get("nozzle_diameter"):
  1815. archive.nozzle_diameter = metadata["nozzle_diameter"]
  1816. if metadata.get("bed_temperature"):
  1817. archive.bed_temperature = metadata["bed_temperature"]
  1818. if metadata.get("bed_type"):
  1819. archive.bed_type = metadata["bed_type"]
  1820. if metadata.get("nozzle_temperature"):
  1821. archive.nozzle_temperature = metadata["nozzle_temperature"]
  1822. if metadata.get("makerworld_url"):
  1823. archive.makerworld_url = metadata["makerworld_url"]
  1824. if metadata.get("designer"):
  1825. archive.designer = metadata["designer"]
  1826. # Calculate cost: prefer spool-based cost if available, else catalog-based.
  1827. # When spool-based costs exist but don't cover every filament gram used
  1828. # (#1344), fall back to the global default rate for the untracked weight
  1829. # so the displayed cost still reflects the whole print.
  1830. if archive.filament_used_grams and archive.filament_type:
  1831. default_cost_setting = await get_setting(db, "default_filament_cost")
  1832. default_cost_per_kg = float(default_cost_setting) if default_cost_setting else 25.0
  1833. usage_result = await db.execute(
  1834. select(
  1835. func.sum(SpoolUsageHistory.cost),
  1836. func.sum(SpoolUsageHistory.weight_used),
  1837. ).where(SpoolUsageHistory.archive_id == archive.id)
  1838. )
  1839. usage_cost_row = usage_result.one()
  1840. usage_cost = usage_cost_row[0]
  1841. tracked_grams = float(usage_cost_row[1] or 0)
  1842. if usage_cost is not None and usage_cost > 0:
  1843. total_cost = float(usage_cost)
  1844. untracked_grams = max(0.0, archive.filament_used_grams - tracked_grams)
  1845. if untracked_grams > 0 and default_cost_per_kg > 0:
  1846. total_cost += (untracked_grams / 1000.0) * default_cost_per_kg
  1847. archive.cost = float(Decimal(str(total_cost)).quantize(Decimal("0.01"), rounding=ROUND_HALF_UP))
  1848. elif await _spoolman_owns_cost(db) and archive.cost is not None:
  1849. # Keep what completion priced from the linked spools. A rescan
  1850. # re-reads the 3MF's metadata; it learns nothing about spools.
  1851. pass
  1852. else:
  1853. primary_type = archive.filament_type.split(",")[0].strip()
  1854. filament_result = await db.execute(select(Filament).where(Filament.type == primary_type).limit(1))
  1855. filament = filament_result.scalar_one_or_none()
  1856. if filament:
  1857. archive.cost = float(
  1858. Decimal(str((archive.filament_used_grams / 1000) * filament.cost_per_kg)).quantize(
  1859. Decimal("0.01"), rounding=ROUND_HALF_UP
  1860. )
  1861. )
  1862. else:
  1863. archive.cost = float(
  1864. Decimal(str((archive.filament_used_grams / 1000) * default_cost_per_kg)).quantize(
  1865. Decimal("0.01"), rounding=ROUND_HALF_UP
  1866. )
  1867. )
  1868. await db.commit()
  1869. await db.refresh(archive)
  1870. return archive
  1871. @router.post("/recalculate-costs")
  1872. async def recalculate_all_costs(
  1873. db: AsyncSession = Depends(get_db),
  1874. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  1875. ):
  1876. """Recalculate costs for all archives based on filament usage and prices."""
  1877. from backend.app.api.routes.settings import get_setting
  1878. result = await db.execute(select(PrintArchive))
  1879. archives = list(result.scalars().all())
  1880. # Load all filaments for lookup
  1881. filament_result = await db.execute(select(Filament))
  1882. filaments = {f.type: f.cost_per_kg for f in filament_result.scalars().all()}
  1883. # Get default filament cost from settings
  1884. default_cost_setting = await get_setting(db, "default_filament_cost")
  1885. default_cost_per_kg = float(default_cost_setting) if default_cost_setting else 25.0
  1886. # Pre-fetch all usage costs and tracked weight by archive_id.
  1887. # Tracked weight is used to top-up the cost at the default rate for any
  1888. # filament grams not covered by an inventory spool (#1344).
  1889. usage_costs_result = await db.execute(
  1890. select(
  1891. SpoolUsageHistory.archive_id,
  1892. func.sum(SpoolUsageHistory.cost),
  1893. func.sum(SpoolUsageHistory.weight_used),
  1894. ).group_by(SpoolUsageHistory.archive_id)
  1895. )
  1896. usage_costs = usage_costs_result.fetchall()
  1897. cost_map = {
  1898. row[0]: (row[1], float(row[2] or 0))
  1899. for row in usage_costs
  1900. if row[0] is not None and row[1] is not None and row[1] > 0
  1901. }
  1902. spoolman_owns = await _spoolman_owns_cost(db)
  1903. updated = 0
  1904. preserved = 0
  1905. for archive in archives:
  1906. usage = cost_map.get(archive.id)
  1907. if usage is not None:
  1908. usage_cost, tracked_grams = usage
  1909. total_cost = float(usage_cost)
  1910. archive_grams = float(archive.filament_used_grams or 0)
  1911. untracked_grams = max(0.0, archive_grams - tracked_grams)
  1912. if untracked_grams > 0 and default_cost_per_kg > 0:
  1913. total_cost += (untracked_grams / 1000.0) * default_cost_per_kg
  1914. new_cost = round(total_cost, 2)
  1915. else:
  1916. # Fallback: sum costs for old records by print_name
  1917. usage_result = await db.execute(
  1918. select(func.sum(SpoolUsageHistory.cost)).where(
  1919. SpoolUsageHistory.print_name == archive.print_name,
  1920. SpoolUsageHistory.archive_id.is_(None),
  1921. )
  1922. )
  1923. fallback_cost = usage_result.scalar()
  1924. if fallback_cost is not None and fallback_cost > 0:
  1925. new_cost = round(fallback_cost, 2)
  1926. elif spoolman_owns and archive.cost is not None:
  1927. # Priced from the linked Spoolman spools at completion; there is
  1928. # nothing better to recompute it from here (#2591).
  1929. new_cost = None
  1930. preserved += 1
  1931. elif archive.filament_used_grams and archive.filament_type:
  1932. primary_type = archive.filament_type.split(",")[0].strip()
  1933. cost_per_kg = filaments.get(primary_type, default_cost_per_kg)
  1934. new_cost = round((archive.filament_used_grams / 1000) * cost_per_kg, 2)
  1935. else:
  1936. new_cost = None
  1937. if new_cost is not None and archive.cost != new_cost:
  1938. archive.cost = new_cost
  1939. updated += 1
  1940. await db.commit()
  1941. message = f"Recalculated costs for {updated} archives"
  1942. if preserved:
  1943. message += f"; kept {preserved} priced from Spoolman"
  1944. return {"message": message, "updated": updated, "preserved": preserved}
  1945. @router.post("/rescan-all")
  1946. async def rescan_all_archives(
  1947. db: AsyncSession = Depends(get_db),
  1948. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  1949. ):
  1950. """Rescan all archives and update their metadata."""
  1951. from backend.app.services.archive import ThreeMFParser
  1952. result = await db.execute(select(PrintArchive))
  1953. archives = list(result.scalars().all())
  1954. updated = 0
  1955. errors = []
  1956. for archive in archives:
  1957. try:
  1958. file_path = settings.base_dir / archive.file_path
  1959. if not file_path.is_file():
  1960. errors.append({"id": archive.id, "error": "File not found"})
  1961. continue
  1962. parser = ThreeMFParser(file_path)
  1963. metadata = parser.parse()
  1964. if metadata.get("filament_type"):
  1965. archive.filament_type = metadata["filament_type"]
  1966. if metadata.get("filament_color"):
  1967. archive.filament_color = metadata["filament_color"]
  1968. if metadata.get("print_time_seconds"):
  1969. archive.print_time_seconds = metadata["print_time_seconds"]
  1970. if metadata.get("filament_used_grams"):
  1971. archive.filament_used_grams = metadata["filament_used_grams"]
  1972. if metadata.get("layer_height"):
  1973. archive.layer_height = metadata["layer_height"]
  1974. if metadata.get("nozzle_diameter"):
  1975. archive.nozzle_diameter = metadata["nozzle_diameter"]
  1976. if metadata.get("makerworld_url"):
  1977. archive.makerworld_url = metadata["makerworld_url"]
  1978. if metadata.get("designer"):
  1979. archive.designer = metadata["designer"]
  1980. updated += 1
  1981. except Exception as e:
  1982. logger.exception("Failed to rescan archive %s: %s", archive.id, e)
  1983. errors.append({"id": archive.id, "error": "Failed to parse 3MF file"})
  1984. await db.commit()
  1985. return {"updated": updated, "errors": errors}
  1986. @router.get("/{archive_id}/duplicates")
  1987. async def get_archive_duplicates(
  1988. archive_id: int,
  1989. db: AsyncSession = Depends(get_db),
  1990. auth_result: tuple[User | None, bool] = Depends(
  1991. require_ownership_permission(
  1992. Permission.ARCHIVES_READ_ALL,
  1993. Permission.ARCHIVES_READ_OWN,
  1994. )
  1995. ),
  1996. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  1997. ):
  1998. """Get duplicates for a specific archive."""
  1999. user, can_read_all = auth_result
  2000. service = ArchiveService(db)
  2001. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2002. makerworld_id = archive.extra_data.get("makerworld_model_id") if archive.extra_data else None
  2003. duplicates = await service.find_duplicates(
  2004. archive_id=archive.id,
  2005. content_hash=archive.content_hash,
  2006. print_name=archive.print_name,
  2007. makerworld_model_id=makerworld_id,
  2008. )
  2009. return {"duplicates": duplicates, "count": len(duplicates)}
  2010. @router.post("/backfill-hashes")
  2011. async def backfill_content_hashes(
  2012. db: AsyncSession = Depends(get_db),
  2013. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  2014. ):
  2015. """Compute and store content hashes for all archives missing them."""
  2016. result = await db.execute(select(PrintArchive).where(PrintArchive.content_hash.is_(None)))
  2017. archives = list(result.scalars().all())
  2018. updated = 0
  2019. errors = []
  2020. for archive in archives:
  2021. try:
  2022. file_path = settings.base_dir / archive.file_path
  2023. if not file_path.is_file():
  2024. errors.append({"id": archive.id, "error": "File not found"})
  2025. continue
  2026. archive.content_hash = ArchiveService.compute_file_hash(file_path)
  2027. updated += 1
  2028. except Exception as e:
  2029. logger.exception("Failed to compute hash for archive %s: %s", archive.id, e)
  2030. errors.append({"id": archive.id, "error": "Failed to compute hash"})
  2031. await db.commit()
  2032. return {"updated": updated, "errors": errors}
  2033. @router.delete("/{archive_id}")
  2034. async def delete_archive(
  2035. archive_id: int,
  2036. purge_stats: bool = Query(
  2037. False,
  2038. description=(
  2039. "When false (default) the archive is soft-deleted — files removed "
  2040. "from disk, row hidden from listings, but its filament / energy / "
  2041. "time / cost contribution stays in Quick Stats. Set true to also "
  2042. "drop the row from statistics (#1343)."
  2043. ),
  2044. ),
  2045. db: AsyncSession = Depends(get_db),
  2046. auth_result: tuple[User | None, bool] = Depends(
  2047. require_ownership_permission(
  2048. Permission.ARCHIVES_DELETE_ALL,
  2049. Permission.ARCHIVES_DELETE_OWN,
  2050. )
  2051. ),
  2052. printer_scope: PrinterScope = RequestPrinterScope,
  2053. ):
  2054. """Delete an archive (soft by default; ``?purge_stats=true`` to hard-delete).
  2055. Both delete paths now cascade to related ``print_queue`` rows (#1734) —
  2056. hard delete via the ``ON DELETE CASCADE`` FK, soft delete via the
  2057. ``_delete_related_queue_items`` helper. A 409 guard blocks the delete
  2058. when any related queue item is currently mid-print so the dispatcher
  2059. doesn't lose its metadata trail under the running print.
  2060. """
  2061. user, can_modify_all = auth_result
  2062. # Get archive first to check ownership
  2063. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  2064. archive = result.scalar_one_or_none()
  2065. if not archive or not printer_scope.allows(archive.printer_id):
  2066. raise HTTPException(404, "Archive not found")
  2067. # Ownership check
  2068. if not can_modify_all:
  2069. if archive.created_by_id != user.id:
  2070. raise HTTPException(403, "You can only delete your own archives")
  2071. # #1734: block delete when any related queue item is currently printing.
  2072. # Both soft and hard delete are gated — an in-flight print needs its
  2073. # backing archive to stay around for the metadata trail (filament,
  2074. # plate, ams_mapping). The user can stop the print first, then retry.
  2075. from backend.app.services.archive import _count_related_queue_items
  2076. _related_total, related_printing = await _count_related_queue_items(db, archive_id)
  2077. if related_printing > 0:
  2078. raise HTTPException(
  2079. 409,
  2080. f"Cannot delete archive — {related_printing} related queue item(s) are "
  2081. f"currently printing. Stop the print first, then retry.",
  2082. )
  2083. service = ArchiveService(db)
  2084. if purge_stats:
  2085. # Hard-delete the linked PrintLogEntry rows first so their filament /
  2086. # cost / count contributions disappear from /archives/stats. The FK is
  2087. # ON DELETE SET NULL, so without this delete the runs would survive
  2088. # the archive row and keep showing up in totals (#1343 / #1378).
  2089. from sqlalchemy import delete as sa_delete
  2090. from backend.app.models.print_log import PrintLogEntry
  2091. await db.execute(sa_delete(PrintLogEntry).where(PrintLogEntry.archive_id == archive_id))
  2092. await db.commit()
  2093. if not await service.delete_archive(archive_id):
  2094. raise HTTPException(404, "Archive not found")
  2095. return {"status": "deleted", "purged_from_stats": True}
  2096. if not await service.soft_delete_archive(archive_id):
  2097. raise HTTPException(404, "Archive not found")
  2098. return {"status": "deleted", "purged_from_stats": False}
  2099. @router.get("/{archive_id}/download")
  2100. async def download_archive(
  2101. archive_id: int,
  2102. inline: bool = False,
  2103. db: AsyncSession = Depends(get_db),
  2104. auth_result: tuple[User | None, bool] = Depends(
  2105. require_ownership_permission(
  2106. Permission.ARCHIVES_READ_ALL,
  2107. Permission.ARCHIVES_READ_OWN,
  2108. )
  2109. ),
  2110. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2111. ):
  2112. """Download the 3MF file."""
  2113. user, can_read_all = auth_result
  2114. service = ArchiveService(db)
  2115. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2116. file_path = settings.base_dir / archive.file_path
  2117. if not file_path.is_file():
  2118. raise HTTPException(404, "File not found")
  2119. # Use inline disposition to let browser/OS handle file association
  2120. content_disposition = "inline" if inline else "attachment"
  2121. return FileResponse(
  2122. path=file_path,
  2123. filename=archive.filename,
  2124. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  2125. content_disposition_type=content_disposition,
  2126. )
  2127. @router.get("/{archive_id}/file/{filename}")
  2128. async def download_archive_with_filename(
  2129. archive_id: int,
  2130. filename: str,
  2131. db: AsyncSession = Depends(get_db),
  2132. auth_result: tuple[User | None, bool] = Depends(
  2133. require_ownership_permission(
  2134. Permission.ARCHIVES_READ_ALL,
  2135. Permission.ARCHIVES_READ_OWN,
  2136. )
  2137. ),
  2138. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2139. ):
  2140. """Download the 3MF file with filename in URL."""
  2141. user, can_read_all = auth_result
  2142. service = ArchiveService(db)
  2143. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2144. file_path = settings.base_dir / archive.file_path
  2145. if not file_path.is_file():
  2146. raise HTTPException(404, "File not found")
  2147. return FileResponse(
  2148. path=file_path,
  2149. filename=archive.filename,
  2150. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  2151. )
  2152. @router.post("/{archive_id}/slicer-token")
  2153. async def create_archive_slicer_token(
  2154. archive_id: int,
  2155. db: AsyncSession = Depends(get_db),
  2156. auth_result: tuple[User | None, bool] = Depends(
  2157. require_ownership_permission(
  2158. Permission.ARCHIVES_READ_ALL,
  2159. Permission.ARCHIVES_READ_OWN,
  2160. )
  2161. ),
  2162. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2163. ):
  2164. """Create a short-lived download token for opening files in slicer applications.
  2165. Slicer protocol handlers (bambustudioopen://, orcaslicer://) cannot send
  2166. auth headers, so they use this token in the URL path instead.
  2167. """
  2168. from backend.app.core.auth import create_slicer_download_token
  2169. user, can_read_all = auth_result
  2170. service = ArchiveService(db)
  2171. _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2172. token = await create_slicer_download_token("archive", archive_id)
  2173. return {"token": token}
  2174. @router.get("/{archive_id}/dl/{token}/{filename}")
  2175. async def download_archive_for_slicer(
  2176. archive_id: int,
  2177. token: str,
  2178. filename: str,
  2179. db: AsyncSession = Depends(get_db),
  2180. ):
  2181. """Download 3MF file using a slicer download token.
  2182. Token-authenticated (no auth headers needed). The token is short-lived and
  2183. archive-bound, created by POST /{archive_id}/slicer-token, and redeemable
  2184. for the rest of its TTL rather than exactly once -- the slicer is a separate
  2185. process that may fetch the URL more than once (#3029).
  2186. Filename is at the end of the URL so slicers can detect the file format.
  2187. """
  2188. from backend.app.core.auth import verify_slicer_download_token
  2189. if not await verify_slicer_download_token(token, "archive", archive_id, single_use=False):
  2190. raise HTTPException(403, "Invalid or expired download token")
  2191. service = ArchiveService(db)
  2192. archive = await service.get_archive(archive_id)
  2193. if not archive:
  2194. raise HTTPException(404, "Archive not found")
  2195. file_path = settings.base_dir / archive.file_path
  2196. if not file_path.is_file():
  2197. raise HTTPException(404, "File not found")
  2198. return FileResponse(
  2199. path=file_path,
  2200. filename=archive.filename,
  2201. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  2202. )
  2203. @router.get("/{archive_id}/thumbnail")
  2204. async def get_thumbnail(
  2205. archive_id: int,
  2206. db: AsyncSession = Depends(get_db),
  2207. auth_result: tuple[User | None, bool] = Depends(
  2208. require_media_token_ownership(
  2209. Permission.ARCHIVES_READ_ALL,
  2210. Permission.ARCHIVES_READ_OWN,
  2211. )
  2212. ),
  2213. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2214. ):
  2215. """Get the thumbnail image.
  2216. Requires a media token query param (?token=xxx) when auth is enabled, and
  2217. returns 404 for an archive the caller may not read (#3025).
  2218. """
  2219. user, can_read_all = auth_result
  2220. service = ArchiveService(db)
  2221. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2222. if not archive.thumbnail_path:
  2223. raise HTTPException(404, "Thumbnail not found")
  2224. thumb_path = settings.base_dir / archive.thumbnail_path
  2225. if not thumb_path.exists():
  2226. raise HTTPException(404, "Thumbnail file not found")
  2227. # Use file modification time as ETag to bust cache
  2228. mtime = int(thumb_path.stat().st_mtime)
  2229. return FileResponse(
  2230. path=thumb_path,
  2231. media_type="image/png",
  2232. headers={
  2233. "Cache-Control": "no-cache, must-revalidate",
  2234. "ETag": f'"{mtime}"',
  2235. },
  2236. )
  2237. @router.get("/{archive_id}/printer-media")
  2238. async def get_archive_printer_media(
  2239. archive_id: int,
  2240. auth_result: tuple[User | None, bool] = Depends(
  2241. require_ownership_permission(
  2242. Permission.ARCHIVES_READ_ALL,
  2243. Permission.ARCHIVES_READ_OWN,
  2244. )
  2245. ),
  2246. can_list_printer_files: bool = Depends(probe_permissions_if_auth_enabled(Permission.PRINTERS_FILES)),
  2247. printer_scope: PrinterScope = RequestPrinterScope,
  2248. ):
  2249. """Find downloadable timelapse and `/ipcam` files for one print.
  2250. Local attached timelapses are returned without touching the printer.
  2251. Printer directories are listed only when the caller also has
  2252. ``printers:files``; otherwise the local result is returned with a warning.
  2253. Files are downloaded only after the user explicitly selects them in the UI.
  2254. """
  2255. user, can_read_all = auth_result
  2256. async with database.async_session() as db:
  2257. archive = _ensure_archive_visible(
  2258. await ArchiveService(db).get_archive(archive_id), user, can_read_all, printer_scope
  2259. )
  2260. printer = None
  2261. claimed_timelapse_stems: set[str] = set()
  2262. if archive.printer_id is not None:
  2263. printer = (await db.execute(select(Printer).where(Printer.id == archive.printer_id))).scalar_one_or_none()
  2264. if printer is not None and archive.timelapse_path is None:
  2265. claimed_timelapse_stems = await _claimed_timelapse_stems(db, archive.printer_id, archive_id)
  2266. local_timelapse = None
  2267. if archive.timelapse_path:
  2268. local_path = settings.base_dir / archive.timelapse_path
  2269. if await asyncio.to_thread(local_path.is_file):
  2270. local_timelapse = {
  2271. "name": local_path.name,
  2272. "size": (await asyncio.to_thread(local_path.stat)).st_size,
  2273. }
  2274. response = {
  2275. "archive_id": archive.id,
  2276. "printer_id": archive.printer_id,
  2277. "local_timelapse": local_timelapse,
  2278. "remote_files": [],
  2279. "warnings": [],
  2280. }
  2281. if archive.printer_id is None or archive.started_at is None:
  2282. return response
  2283. if not can_list_printer_files:
  2284. response["warnings"].append("printer_files_forbidden")
  2285. return response
  2286. if printer is None or not printer_scope.allows(printer.id):
  2287. response["warnings"].append("printer_missing")
  2288. return response
  2289. if ftps_handshake_blocked(printer.ip_address):
  2290. if local_timelapse is None:
  2291. response["warnings"].append("timelapse_unavailable")
  2292. response["warnings"].append("ipcam_unavailable")
  2293. return response
  2294. remote_files: list[dict] = []
  2295. # If no copy was attached to the archive, offer the matching printer-side
  2296. # timelapse without mutating the archive or deleting anything from the SD.
  2297. if local_timelapse is None:
  2298. videos: list[dict] = []
  2299. any_timelapse_directory_available = False
  2300. for timelapse_dir in ("/timelapse", "/timelapse/video", "/record", "/recording"):
  2301. if ftps_handshake_blocked(printer.ip_address):
  2302. break
  2303. listing = await list_files_result_async(
  2304. printer.ip_address,
  2305. printer.access_code,
  2306. timelapse_dir,
  2307. timeout=_PRINTER_MEDIA_LIST_TIMEOUT_SECONDS,
  2308. printer_model=printer.model,
  2309. )
  2310. any_timelapse_directory_available |= listing.available
  2311. candidates = [
  2312. file
  2313. for file in listing.files
  2314. if not file.get("is_directory") and str(file.get("name") or "").lower().endswith(VIDEO_SUFFIXES)
  2315. ]
  2316. if candidates:
  2317. videos = candidates
  2318. break
  2319. if not any_timelapse_directory_available:
  2320. response["warnings"].append("timelapse_unavailable")
  2321. if videos:
  2322. baseline = set(archive.timelapse_baseline or [])
  2323. eligible = [
  2324. file
  2325. for file in videos
  2326. if str(file.get("name") or "") not in baseline
  2327. and Path(str(file.get("name") or "")).stem not in claimed_timelapse_stems
  2328. ]
  2329. if archive.timelapse_baseline is not None:
  2330. candidate = eligible[0] if len(eligible) == 1 else None
  2331. else:
  2332. candidate, _ = _match_timelapse_by_timestamp(eligible, archive.started_at)
  2333. if candidate is not None:
  2334. remote_files.append(
  2335. {
  2336. "name": candidate.get("name"),
  2337. "path": candidate.get("path"),
  2338. "size": candidate.get("size") or 0,
  2339. "mtime": candidate.get("mtime"),
  2340. "kind": "timelapse",
  2341. }
  2342. )
  2343. if ftps_handshake_blocked(printer.ip_address):
  2344. response["warnings"].append("ipcam_unavailable")
  2345. response["remote_files"] = remote_files
  2346. return response
  2347. ipcam_listing = await list_files_result_async(
  2348. printer.ip_address,
  2349. printer.access_code,
  2350. "/ipcam",
  2351. timeout=_PRINTER_MEDIA_LIST_TIMEOUT_SECONDS,
  2352. printer_model=printer.model,
  2353. )
  2354. if ipcam_listing.available:
  2355. for file in match_ipcam_chunks(ipcam_listing.files, archive.started_at, archive.completed_at):
  2356. remote_files.append(
  2357. {
  2358. "name": file.get("name"),
  2359. "path": file.get("path") or f"/ipcam/{file.get('name')}",
  2360. "size": file.get("size") or 0,
  2361. "mtime": file.get("mtime"),
  2362. "kind": "ipcam",
  2363. }
  2364. )
  2365. else:
  2366. response["warnings"].append("ipcam_unavailable")
  2367. response["remote_files"] = remote_files
  2368. return response
  2369. @router.post("/{archive_id}/media-download-token")
  2370. async def create_archive_media_download_token(
  2371. archive_id: int,
  2372. auth_result: tuple[User | None, bool] = Depends(
  2373. require_ownership_permission(Permission.ARCHIVES_READ_ALL, Permission.ARCHIVES_READ_OWN)
  2374. ),
  2375. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2376. ):
  2377. """Mint a single-use token bound to an archive's attached timelapse."""
  2378. from backend.app.core.auth import create_slicer_download_token
  2379. user, can_read_all = auth_result
  2380. async with database.async_session() as db:
  2381. archive = _ensure_archive_visible(
  2382. await ArchiveService(db).get_archive(archive_id), user, can_read_all, printer_scope
  2383. )
  2384. if not archive.timelapse_path:
  2385. raise HTTPException(404, "Timelapse not found")
  2386. timelapse_path = settings.base_dir / archive.timelapse_path
  2387. if not await asyncio.to_thread(timelapse_path.is_file):
  2388. raise HTTPException(404, "Timelapse file not found")
  2389. return {
  2390. "token": await create_slicer_download_token("archive-timelapse", archive_id),
  2391. "filename": timelapse_path.name,
  2392. }
  2393. @router.get("/{archive_id}/media/dl/{token}/{filename}")
  2394. async def download_archive_media_with_token(
  2395. archive_id: int,
  2396. token: str,
  2397. filename: str,
  2398. ):
  2399. """Consume a resource-bound token and stream an attached timelapse."""
  2400. from backend.app.core.auth import verify_slicer_download_token
  2401. if not await verify_slicer_download_token(token, "archive-timelapse", archive_id):
  2402. return download_error_response(403, "This download link has already been used or has expired.")
  2403. async with database.async_session() as db:
  2404. archive = await ArchiveService(db).get_archive(archive_id)
  2405. if not archive or not archive.timelapse_path:
  2406. return download_error_response(404, "This print has no attached timelapse.")
  2407. timelapse_path = settings.base_dir / archive.timelapse_path
  2408. if not await asyncio.to_thread(timelapse_path.is_file):
  2409. return download_error_response(404, "The attached timelapse is no longer on disk.")
  2410. safe_filename = safe_download_filename(filename, fallback=timelapse_path.name)
  2411. return FileResponse(
  2412. path=timelapse_path,
  2413. filename=safe_filename,
  2414. headers={"Content-Disposition": build_content_disposition(safe_filename)},
  2415. )
  2416. @router.get("/{archive_id}/timelapse")
  2417. async def get_timelapse(
  2418. archive_id: int,
  2419. db: AsyncSession = Depends(get_db),
  2420. auth_result: tuple[User | None, bool] = Depends(
  2421. require_media_token_ownership(
  2422. Permission.ARCHIVES_READ_ALL,
  2423. Permission.ARCHIVES_READ_OWN,
  2424. )
  2425. ),
  2426. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2427. ):
  2428. """Get the timelapse video.
  2429. Requires a media token query param (?token=xxx) when auth is enabled, and
  2430. returns 404 for an archive the caller may not read (#3025).
  2431. """
  2432. user, can_read_all = auth_result
  2433. service = ArchiveService(db)
  2434. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2435. if not archive.timelapse_path:
  2436. raise HTTPException(404, "Timelapse not found")
  2437. timelapse_path = settings.base_dir / archive.timelapse_path
  2438. if not timelapse_path.exists():
  2439. raise HTTPException(404, "Timelapse file not found")
  2440. # Use file modification time as ETag to bust cache after processing
  2441. mtime = int(timelapse_path.stat().st_mtime)
  2442. # Detect media type from file extension (AVI from P1S before background conversion)
  2443. suffix = timelapse_path.suffix.lower()
  2444. media_type = {".mp4": "video/mp4", ".avi": "video/x-msvideo", ".mkv": "video/x-matroska"}.get(suffix, "video/mp4")
  2445. ext = suffix if suffix in (".mp4", ".avi", ".mkv") else ".mp4"
  2446. return FileResponse(
  2447. path=timelapse_path,
  2448. media_type=media_type,
  2449. filename=f"{archive.print_name or 'timelapse'}{ext}",
  2450. headers={
  2451. "Cache-Control": "no-cache, must-revalidate",
  2452. "ETag": f'"{mtime}"',
  2453. },
  2454. )
  2455. @router.delete("/{archive_id}/timelapse")
  2456. async def delete_timelapse(
  2457. archive_id: int,
  2458. db: AsyncSession = Depends(get_db),
  2459. auth_result: tuple[User | None, bool] = Depends(
  2460. require_ownership_permission(
  2461. Permission.ARCHIVES_DELETE_ALL,
  2462. Permission.ARCHIVES_DELETE_OWN,
  2463. )
  2464. ),
  2465. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2466. ):
  2467. """Remove the timelapse video from an archive."""
  2468. user, can_modify_all = auth_result
  2469. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  2470. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  2471. if not archive.timelapse_path:
  2472. raise HTTPException(404, "No timelapse attached to this archive")
  2473. # Delete the file
  2474. timelapse_path = settings.base_dir / archive.timelapse_path
  2475. if timelapse_path.exists():
  2476. timelapse_path.unlink()
  2477. # Clear the path in database
  2478. archive.timelapse_path = None
  2479. await db.commit()
  2480. return {"status": "deleted"}
  2481. @router.post("/{archive_id}/timelapse/scan")
  2482. async def scan_timelapse(
  2483. archive_id: int,
  2484. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  2485. printer_scope: PrinterScope = RequestPrinterScope,
  2486. ):
  2487. """Scan printer for timelapse matching this archive and attach it."""
  2488. from backend.app.core.database import async_session
  2489. from backend.app.models.printer import Printer
  2490. from backend.app.services.bambu_ftp import (
  2491. delete_archived_timelapse,
  2492. download_file_bytes_async,
  2493. ftps_handshake_blocked,
  2494. get_ftp_retry_settings,
  2495. list_files_async,
  2496. remote_file_settled,
  2497. with_ftp_retry,
  2498. )
  2499. # Read the archive + printer in a short session and release the pooled DB
  2500. # connection BEFORE the FTP scan/download below — a timelapse pull walks
  2501. # several directories and fetches a 100MB+ video, so holding Depends(get_db)
  2502. # across it pinned one connection idle-in-transaction for minutes (#2572).
  2503. # Scalar columns stay readable on the detached rows (expire_on_commit=False);
  2504. # the attach at the end runs in its own fresh short session.
  2505. async with async_session() as db:
  2506. archive = await ArchiveService(db).get_archive(archive_id)
  2507. if not archive:
  2508. raise HTTPException(404, "Archive not found")
  2509. if archive.timelapse_path:
  2510. return {"status": "exists", "message": "Timelapse already attached"}
  2511. if not archive.printer_id:
  2512. raise HTTPException(400, "Archive has no associated printer")
  2513. printer_scope.ensure(archive.printer_id)
  2514. result = await db.execute(select(Printer).where(Printer.id == archive.printer_id))
  2515. printer = result.scalar_one_or_none()
  2516. if not printer:
  2517. raise HTTPException(404, "Printer not found")
  2518. # Get base name from archive filename (without .3mf extension)
  2519. base_name = Path(archive.filename).stem
  2520. # Scan timelapse directory on printer
  2521. # Different printer models use different paths
  2522. files = []
  2523. for timelapse_path in ["/timelapse", "/timelapse/video", "/record", "/recording"]:
  2524. if ftps_handshake_blocked(printer.ip_address):
  2525. break
  2526. try:
  2527. files = await list_files_async(
  2528. printer.ip_address, printer.access_code, timelapse_path, printer_model=printer.model
  2529. )
  2530. if files:
  2531. break
  2532. except Exception:
  2533. continue
  2534. if not files:
  2535. # "Couldn't reach the printer" and "the printer has no timelapse
  2536. # directory" are different problems with different fixes, and both used
  2537. # to come back as one 500 (#2780). Nothing here will work while the
  2538. # printer's file service is not answering over TLS, so say that rather
  2539. # than reporting an empty directory.
  2540. if ftps_handshake_blocked(printer.ip_address):
  2541. raise HTTPException(
  2542. 503,
  2543. f"Printer {printer.ip_address} is not answering its file service over TLS. "
  2544. "Bambuddy will try again shortly.",
  2545. )
  2546. raise HTTPException(404, "No timelapse directory found on the printer")
  2547. # Look for matching timelapse
  2548. matching_file = None
  2549. video_files = [
  2550. f for f in files if not f.get("is_directory") and f.get("name", "").lower().endswith((".mp4", ".avi"))
  2551. ]
  2552. # Strategy 0: snapshot diff against the baseline captured at print start
  2553. # (#2704). This is the same comparison the automatic scan makes, and the
  2554. # only one here that doesn't depend on the printer's clock — a printer in
  2555. # LAN-only mode can't reach Bambu's NTP server, so the timestamps in both
  2556. # the filename and the FTP mtime can be days out. One reporter's P1S was
  2557. # six and a half days off, which defeats every strategy below.
  2558. #
  2559. # When a baseline exists it is authoritative and the clock-based strategies
  2560. # are skipped entirely: they can only turn an honest "pick one yourself"
  2561. # into a confident wrong answer. Those strategies stay for archives created
  2562. # before the baseline was persisted.
  2563. used_baseline = archive.timelapse_baseline is not None
  2564. if used_baseline:
  2565. baseline = set(archive.timelapse_baseline)
  2566. async with async_session() as db:
  2567. claimed = await _claimed_timelapse_stems(db, archive.printer_id, archive_id)
  2568. candidates = [
  2569. f for f in video_files if f.get("name", "") not in baseline and Path(f.get("name", "")).stem not in claimed
  2570. ]
  2571. if len(candidates) == 1:
  2572. matching_file = candidates[0]
  2573. logger.info("Matched timelapse by print-start baseline: %s", matching_file.get("name"))
  2574. elif candidates:
  2575. # Ambiguous — offer only the plausible files instead of guessing.
  2576. video_files = candidates
  2577. logger.info("Baseline left %s unclaimed candidates for archive %s", len(candidates), archive_id)
  2578. else:
  2579. logger.info("Baseline shows no unclaimed new video on the printer for archive %s", archive_id)
  2580. # Strategy 1: Match by print name in filename
  2581. if not used_baseline:
  2582. for f in video_files:
  2583. fname = f.get("name", "")
  2584. if base_name.lower() in fname.lower():
  2585. matching_file = f
  2586. break
  2587. # Strategy 2: Match by timestamp proximity against print START time.
  2588. # Bambu timelapse filename embeds the print start time in printer-local clock.
  2589. # See _match_timelapse_by_timestamp for the offset-search rationale and why we
  2590. # intentionally don't try to match filename against end time here.
  2591. if not used_baseline and not matching_file and archive.started_at:
  2592. candidate, diff = _match_timelapse_by_timestamp(video_files, archive.started_at)
  2593. if candidate is not None:
  2594. matching_file = candidate
  2595. logger.info("Matched timelapse by timestamp: %s (diff: %s)", candidate.get("name"), diff)
  2596. # Strategy 3: Use file modification time from FTP listing
  2597. # This handles cases where printer's filename timestamp is wrong but file mtime is correct
  2598. if not used_baseline and not matching_file and (archive.started_at or archive.completed_at or archive.created_at):
  2599. from datetime import datetime, timedelta
  2600. _archive_start = archive.started_at
  2601. archive_end = archive.completed_at or archive.created_at
  2602. best_match = None
  2603. best_diff = timedelta(hours=24)
  2604. for f in video_files:
  2605. mtime = f.get("mtime")
  2606. if mtime:
  2607. # Timelapse file should be modified during or shortly after the print
  2608. # The mtime should be close to completion time (video finishes when print ends)
  2609. if archive_end:
  2610. diff = abs(mtime - archive_end)
  2611. if diff < best_diff:
  2612. best_diff = diff
  2613. best_match = f
  2614. logger.debug(
  2615. f"Timelapse mtime match candidate: {f.get('name')}, mtime: {mtime}, diff from end: {diff}"
  2616. )
  2617. if best_match and best_diff < timedelta(hours=2):
  2618. matching_file = best_match
  2619. logger.info("Matched timelapse by file mtime: %s (diff: %s)", best_match.get("name"), best_diff)
  2620. # Strategy 4: If only one timelapse exists and archive was recently completed, use it
  2621. # This handles cases where printer clock is wrong or timezone issues exist
  2622. if not used_baseline and not matching_file and len(video_files) == 1:
  2623. from datetime import datetime, timedelta, timezone
  2624. archive_completed = archive.completed_at or archive.created_at
  2625. if archive_completed:
  2626. if archive_completed.tzinfo is None:
  2627. archive_completed = archive_completed.replace(tzinfo=timezone.utc)
  2628. time_since_completion = datetime.now(timezone.utc) - archive_completed
  2629. # If archive was completed within the last hour, assume the single timelapse is for it
  2630. if time_since_completion < timedelta(hours=1):
  2631. matching_file = video_files[0]
  2632. logger.info("Using single timelapse file as fallback: %s", video_files[0].get("name"))
  2633. # Note: We intentionally don't use a "most recent file" fallback because
  2634. # we can't verify if timelapse was actually enabled for this print.
  2635. # Instead, return the list of available files for manual selection.
  2636. if not matching_file:
  2637. # Return available files for manual selection
  2638. available_files = [
  2639. {
  2640. "name": f.get("name"),
  2641. "path": f.get("path"),
  2642. "size": f.get("size"),
  2643. "mtime": f.get("mtime").isoformat() if f.get("mtime") else None,
  2644. }
  2645. for f in video_files
  2646. ]
  2647. # Sort by mtime descending (most recent first)
  2648. available_files.sort(key=lambda x: x.get("mtime") or "", reverse=True)
  2649. return {
  2650. "status": "not_found",
  2651. "message": "No matching timelapse found - please select manually",
  2652. "available_files": available_files,
  2653. }
  2654. # Download the timelapse - use the full path from the file listing
  2655. remote_path = matching_file.get("path") or f"/timelapse/{matching_file['name']}"
  2656. # Get FTP retry settings
  2657. ftp_retry_enabled, ftp_retry_count, ftp_retry_delay, ftp_timeout = await get_ftp_retry_settings()
  2658. if ftp_retry_enabled:
  2659. timelapse_data = await with_ftp_retry(
  2660. download_file_bytes_async,
  2661. printer.ip_address,
  2662. printer.access_code,
  2663. remote_path,
  2664. socket_timeout=ftp_timeout,
  2665. printer_model=printer.model,
  2666. expected_size=matching_file.get("size"),
  2667. max_retries=ftp_retry_count,
  2668. retry_delay=ftp_retry_delay,
  2669. operation_name=f"Download timelapse {matching_file['name']}",
  2670. cooloff_ip=printer.ip_address,
  2671. )
  2672. else:
  2673. timelapse_data = await download_file_bytes_async(
  2674. printer.ip_address,
  2675. printer.access_code,
  2676. remote_path,
  2677. socket_timeout=ftp_timeout,
  2678. printer_model=printer.model,
  2679. expected_size=matching_file.get("size"),
  2680. )
  2681. if not timelapse_data:
  2682. raise HTTPException(500, "Failed to download timelapse")
  2683. # Confirm the printer has finished writing before we commit to this file and
  2684. # delete the original: matching the listing's size proves we got what it
  2685. # said, not that the file was complete (#2704).
  2686. if not await remote_file_settled(
  2687. printer.ip_address,
  2688. printer.access_code,
  2689. remote_path,
  2690. len(timelapse_data),
  2691. printer_model=printer.model,
  2692. ):
  2693. raise HTTPException(409, "The printer is still writing this video — try again in a moment")
  2694. # Attach in a fresh short session (the read session was released before FTP).
  2695. async with async_session() as db:
  2696. success = await ArchiveService(db).attach_timelapse(archive_id, timelapse_data, matching_file["name"])
  2697. if not success:
  2698. raise HTTPException(500, "Failed to attach timelapse")
  2699. # Safe now, and only now: the transfer matched the size the listing reported
  2700. # and the bytes are committed to the archive (#2704).
  2701. await delete_archived_timelapse(
  2702. printer.ip_address,
  2703. printer.access_code,
  2704. remote_path,
  2705. verified=matching_file.get("size") is not None,
  2706. printer_model=printer.model,
  2707. printer_name=printer.name,
  2708. )
  2709. return {
  2710. "status": "attached",
  2711. "message": f"Timelapse '{matching_file['name']}' attached successfully",
  2712. "filename": matching_file["name"],
  2713. }
  2714. @router.post("/{archive_id}/timelapse/select")
  2715. async def select_timelapse(
  2716. archive_id: int,
  2717. filename: str = Query(..., description="Timelapse filename to attach"),
  2718. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  2719. printer_scope: PrinterScope = RequestPrinterScope,
  2720. ):
  2721. """Manually select a timelapse from the printer to attach."""
  2722. from backend.app.core.database import async_session
  2723. from backend.app.models.printer import Printer
  2724. from backend.app.services.bambu_ftp import (
  2725. delete_archived_timelapse,
  2726. download_file_bytes_async,
  2727. get_ftp_retry_settings,
  2728. list_files_async,
  2729. remote_file_settled,
  2730. with_ftp_retry,
  2731. )
  2732. # Read the archive + printer in a short session and release the pooled DB
  2733. # connection BEFORE the FTP scan/download below (#2572); scalars stay
  2734. # readable after close (expire_on_commit=False), the attach reopens one.
  2735. async with async_session() as db:
  2736. archive = await ArchiveService(db).get_archive(archive_id)
  2737. if not archive:
  2738. raise HTTPException(404, "Archive not found")
  2739. if not archive.printer_id:
  2740. raise HTTPException(400, "Archive has no associated printer")
  2741. printer_scope.ensure(archive.printer_id)
  2742. result = await db.execute(select(Printer).where(Printer.id == archive.printer_id))
  2743. printer = result.scalar_one_or_none()
  2744. if not printer:
  2745. raise HTTPException(404, "Printer not found")
  2746. # Find the file on the printer
  2747. files = []
  2748. remote_path = None
  2749. expected_size = None
  2750. for timelapse_dir in ["/timelapse", "/timelapse/video", "/record", "/recording"]:
  2751. try:
  2752. files = await list_files_async(
  2753. printer.ip_address, printer.access_code, timelapse_dir, printer_model=printer.model
  2754. )
  2755. for f in files:
  2756. if f.get("name") == filename:
  2757. remote_path = f.get("path") or f"{timelapse_dir}/{filename}"
  2758. expected_size = f.get("size")
  2759. break
  2760. if remote_path:
  2761. break
  2762. except Exception:
  2763. continue
  2764. if not remote_path:
  2765. raise HTTPException(404, f"Timelapse '{filename}' not found on printer")
  2766. # Download and attach
  2767. ftp_retry_enabled, ftp_retry_count, ftp_retry_delay, ftp_timeout = await get_ftp_retry_settings()
  2768. if ftp_retry_enabled:
  2769. timelapse_data = await with_ftp_retry(
  2770. download_file_bytes_async,
  2771. printer.ip_address,
  2772. printer.access_code,
  2773. remote_path,
  2774. socket_timeout=ftp_timeout,
  2775. printer_model=printer.model,
  2776. expected_size=expected_size,
  2777. max_retries=ftp_retry_count,
  2778. retry_delay=ftp_retry_delay,
  2779. operation_name=f"Download timelapse {filename}",
  2780. cooloff_ip=printer.ip_address,
  2781. )
  2782. else:
  2783. timelapse_data = await download_file_bytes_async(
  2784. printer.ip_address,
  2785. printer.access_code,
  2786. remote_path,
  2787. socket_timeout=ftp_timeout,
  2788. printer_model=printer.model,
  2789. expected_size=expected_size,
  2790. )
  2791. if not timelapse_data:
  2792. raise HTTPException(500, "Failed to download timelapse")
  2793. # Confirm the printer has finished writing before we commit to this file and
  2794. # delete the original: matching the listing's size proves we got what it
  2795. # said, not that the file was complete (#2704).
  2796. if not await remote_file_settled(
  2797. printer.ip_address,
  2798. printer.access_code,
  2799. remote_path,
  2800. len(timelapse_data),
  2801. printer_model=printer.model,
  2802. ):
  2803. raise HTTPException(409, "The printer is still writing this video — try again in a moment")
  2804. # Attach in a fresh short session (the read session was released before FTP).
  2805. async with async_session() as db:
  2806. success = await ArchiveService(db).attach_timelapse(archive_id, timelapse_data, filename)
  2807. if not success:
  2808. raise HTTPException(500, "Failed to attach timelapse")
  2809. # Safe now, and only now: the transfer matched the size the listing reported
  2810. # and the bytes are committed to the archive (#2704).
  2811. await delete_archived_timelapse(
  2812. printer.ip_address,
  2813. printer.access_code,
  2814. remote_path,
  2815. verified=expected_size is not None,
  2816. printer_model=printer.model,
  2817. printer_name=printer.name,
  2818. )
  2819. return {
  2820. "status": "attached",
  2821. "message": f"Timelapse '{filename}' attached successfully",
  2822. "filename": filename,
  2823. }
  2824. @router.post("/{archive_id}/timelapse/upload")
  2825. async def upload_timelapse(
  2826. archive_id: int,
  2827. file: UploadFile = File(...),
  2828. db: AsyncSession = Depends(get_db),
  2829. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  2830. printer_scope: PrinterScope = RequestPrinterScope,
  2831. ):
  2832. """Manually upload a timelapse video to an archive."""
  2833. service = ArchiveService(db)
  2834. archive = await service.get_archive(archive_id)
  2835. if not archive or not printer_scope.allows(archive.printer_id):
  2836. raise HTTPException(404, "Archive not found")
  2837. if not file.filename or not file.filename.endswith((".mp4", ".avi", ".mkv")):
  2838. raise HTTPException(400, "File must be a video file (.mp4, .avi, .mkv)")
  2839. content = await file.read()
  2840. safe_filename = _safe_filename(file.filename)
  2841. success = await service.attach_timelapse(archive_id, content, safe_filename)
  2842. if not success:
  2843. raise HTTPException(500, "Failed to attach timelapse")
  2844. return {"status": "attached", "filename": safe_filename}
  2845. @router.get("/{archive_id}/timelapse/info")
  2846. async def get_timelapse_info(
  2847. archive_id: int,
  2848. db: AsyncSession = Depends(get_db),
  2849. auth_result: tuple[User | None, bool] = Depends(
  2850. require_ownership_permission(
  2851. Permission.ARCHIVES_READ_ALL,
  2852. Permission.ARCHIVES_READ_OWN,
  2853. )
  2854. ),
  2855. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2856. ):
  2857. """Get timelapse video metadata for editor."""
  2858. from backend.app.schemas.timelapse import TimelapseInfoResponse
  2859. from backend.app.services.timelapse_processor import TimelapseProcessor
  2860. user, can_read_all = auth_result
  2861. service = ArchiveService(db)
  2862. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2863. if not archive.timelapse_path:
  2864. raise HTTPException(404, "Timelapse not found")
  2865. timelapse_path = settings.base_dir / archive.timelapse_path
  2866. if not timelapse_path.exists():
  2867. raise HTTPException(404, "Timelapse file not found")
  2868. try:
  2869. processor = TimelapseProcessor(timelapse_path)
  2870. info = await processor.get_info()
  2871. return TimelapseInfoResponse(**info)
  2872. except Exception as e:
  2873. logger.error("Failed to get timelapse info: %s", e)
  2874. raise HTTPException(500, f"Failed to get video info: {str(e)}")
  2875. @router.get("/{archive_id}/timelapse/thumbnails")
  2876. async def get_timelapse_thumbnails(
  2877. archive_id: int,
  2878. count: int = Query(10, ge=1, le=30),
  2879. width: int = Query(160, ge=80, le=320),
  2880. db: AsyncSession = Depends(get_db),
  2881. auth_result: tuple[User | None, bool] = Depends(
  2882. require_ownership_permission(
  2883. Permission.ARCHIVES_READ_ALL,
  2884. Permission.ARCHIVES_READ_OWN,
  2885. )
  2886. ),
  2887. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  2888. ):
  2889. """Generate timeline thumbnail frames for visual scrubbing."""
  2890. import base64
  2891. from backend.app.schemas.timelapse import ThumbnailResponse
  2892. from backend.app.services.timelapse_processor import TimelapseProcessor
  2893. user, can_read_all = auth_result
  2894. service = ArchiveService(db)
  2895. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  2896. if not archive.timelapse_path:
  2897. raise HTTPException(404, "Timelapse not found")
  2898. timelapse_path = settings.base_dir / archive.timelapse_path
  2899. if not timelapse_path.exists():
  2900. raise HTTPException(404, "Timelapse file not found")
  2901. try:
  2902. processor = TimelapseProcessor(timelapse_path)
  2903. thumbnails = await processor.generate_thumbnails(count, width)
  2904. return ThumbnailResponse(
  2905. thumbnails=[base64.b64encode(data).decode() for _, data in thumbnails],
  2906. timestamps=[ts for ts, _ in thumbnails],
  2907. )
  2908. except Exception as e:
  2909. logger.error("Failed to generate thumbnails: %s", e)
  2910. raise HTTPException(500, f"Failed to generate thumbnails: {str(e)}")
  2911. @router.post("/{archive_id}/timelapse/process")
  2912. async def process_timelapse(
  2913. archive_id: int,
  2914. trim_start: float = Form(0),
  2915. trim_end: float = Form(None),
  2916. speed: float = Form(1.0),
  2917. save_mode: str = Form("new"),
  2918. output_filename: str = Form(None),
  2919. audio: UploadFile = File(None),
  2920. db: AsyncSession = Depends(get_db),
  2921. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  2922. printer_scope: PrinterScope = RequestPrinterScope,
  2923. ):
  2924. """Process timelapse with trim, speed, and optional audio overlay."""
  2925. import shutil
  2926. import tempfile
  2927. from backend.app.schemas.timelapse import ProcessResponse
  2928. from backend.app.services.timelapse_processor import TimelapseProcessor
  2929. # Validate speed
  2930. if not 0.25 <= speed <= 4.0:
  2931. raise HTTPException(400, "Speed must be between 0.25 and 4.0")
  2932. if save_mode not in ("replace", "new"):
  2933. raise HTTPException(400, "save_mode must be 'replace' or 'new'")
  2934. service = ArchiveService(db)
  2935. archive = await service.get_archive(archive_id)
  2936. if not archive or not archive.timelapse_path or not printer_scope.allows(archive.printer_id):
  2937. raise HTTPException(404, "Timelapse not found")
  2938. timelapse_path = settings.base_dir / archive.timelapse_path
  2939. if not timelapse_path.exists():
  2940. raise HTTPException(404, "Timelapse file not found")
  2941. archive_dir = timelapse_path.parent
  2942. # Handle audio file
  2943. audio_temp_path = None
  2944. if audio and audio.filename:
  2945. # Validate audio file extension
  2946. if not audio.filename.lower().endswith((".mp3", ".wav", ".m4a", ".aac", ".ogg")):
  2947. raise HTTPException(400, "Audio must be .mp3, .wav, .m4a, .aac, or .ogg")
  2948. audio_content = await audio.read()
  2949. # Extract and validate suffix to prevent path injection
  2950. suffix = Path(audio.filename).suffix.lower()
  2951. if suffix not in (".mp3", ".wav", ".m4a", ".aac", ".ogg"):
  2952. raise HTTPException(400, "Invalid audio file extension")
  2953. audio_temp_path = Path(tempfile.gettempdir()) / f"audio_{archive_id}{suffix}"
  2954. audio_temp_path.write_bytes(audio_content)
  2955. try:
  2956. processor = TimelapseProcessor(timelapse_path)
  2957. # Determine output path
  2958. if save_mode == "replace":
  2959. # Process to temp file first, then replace
  2960. temp_output = Path(tempfile.gettempdir()) / f"processed_{archive_id}.mp4"
  2961. output_path = temp_output
  2962. else:
  2963. # Save as new file alongside original
  2964. filename = output_filename or f"{archive.print_name or 'timelapse'}_edited.mp4"
  2965. # Sanitize filename - remove path separators and traversal sequences
  2966. filename = "".join(c for c in filename if c.isalnum() or c in "._- ")
  2967. # Prevent path traversal
  2968. if ".." in filename or not filename or filename.startswith("."):
  2969. filename = f"timelapse_{archive_id}_edited"
  2970. if not filename.endswith(".mp4"):
  2971. filename += ".mp4"
  2972. output_path = archive_dir / filename # SEC-PATH-OK: filename alnum-filtered + .. rejected above
  2973. success = await processor.process(
  2974. output_path=output_path,
  2975. trim_start=trim_start,
  2976. trim_end=trim_end,
  2977. speed=speed,
  2978. audio_path=audio_temp_path,
  2979. )
  2980. if not success:
  2981. raise HTTPException(500, "Video processing failed")
  2982. # Handle save mode
  2983. if save_mode == "replace":
  2984. # Replace original file
  2985. shutil.move(str(output_path), str(timelapse_path))
  2986. final_path = archive.timelapse_path
  2987. message = "Timelapse replaced successfully"
  2988. else:
  2989. final_path = str(output_path.relative_to(settings.base_dir))
  2990. message = f"Saved as {output_path.name}"
  2991. return ProcessResponse(
  2992. status="completed",
  2993. output_path=final_path,
  2994. message=message,
  2995. )
  2996. except HTTPException:
  2997. raise
  2998. except Exception as e:
  2999. logger.error("Timelapse processing failed: %s", e)
  3000. raise HTTPException(500, f"Processing failed: {str(e)}")
  3001. finally:
  3002. # Cleanup temp audio file
  3003. if audio_temp_path and audio_temp_path.exists():
  3004. audio_temp_path.unlink()
  3005. # ============================================
  3006. # Photo Endpoints
  3007. # ============================================
  3008. @router.post("/{archive_id}/photos")
  3009. async def upload_photo(
  3010. archive_id: int,
  3011. file: UploadFile = File(...),
  3012. db: AsyncSession = Depends(get_db),
  3013. auth_result: tuple[User | None, bool] = Depends(
  3014. require_ownership_permission(
  3015. Permission.ARCHIVES_UPDATE_ALL,
  3016. Permission.ARCHIVES_UPDATE_OWN,
  3017. )
  3018. ),
  3019. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3020. ):
  3021. """Upload a photo of the printed result."""
  3022. user, can_modify_all = auth_result
  3023. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  3024. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  3025. if not file.filename or not file.filename.lower().endswith((".jpg", ".jpeg", ".png", ".webp")):
  3026. raise HTTPException(400, "File must be an image (.jpg, .jpeg, .png, .webp)")
  3027. # Get archive directory. parents=True because an archive with no 3MF owns
  3028. # <archive_dir>/<id>/, which nothing else has necessarily created yet.
  3029. photos_dir = archive_photos_dir(archive)
  3030. photos_dir.mkdir(parents=True, exist_ok=True)
  3031. # Generate unique filename
  3032. import uuid
  3033. ext = Path(file.filename).suffix.lower()
  3034. photo_filename = f"{uuid.uuid4().hex[:8]}{ext}"
  3035. photo_path = photos_dir / photo_filename # SEC-PATH-OK: photo_filename = uuid.uuid4().hex[:8] + ext
  3036. # Save file
  3037. content = await file.read()
  3038. photo_path.write_bytes(content)
  3039. # Update archive photos list (create new list to trigger SQLAlchemy change detection)
  3040. photos = list(archive.photos or [])
  3041. photos.append(photo_filename)
  3042. archive.photos = photos
  3043. await db.commit()
  3044. await db.refresh(archive)
  3045. return {"status": "uploaded", "filename": photo_filename, "photos": archive.photos}
  3046. @router.get("/{archive_id}/photos/{filename}")
  3047. async def get_photo(
  3048. archive_id: int,
  3049. filename: str,
  3050. db: AsyncSession = Depends(get_db),
  3051. auth_result: tuple[User | None, bool] = Depends(
  3052. require_media_token_ownership(
  3053. Permission.ARCHIVES_READ_ALL,
  3054. Permission.ARCHIVES_READ_OWN,
  3055. )
  3056. ),
  3057. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3058. ):
  3059. """Get a specific photo.
  3060. Requires a media token query param (?token=xxx) when auth is enabled, and
  3061. returns 404 for an archive the caller may not read (#3025).
  3062. """
  3063. user, can_read_all = auth_result
  3064. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  3065. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  3066. # Membership check first — UUID-generated names on upload mean any URL
  3067. # filename that doesn't appear here is by definition not a real photo.
  3068. # Mirrors the delete handler below; previously this endpoint had no
  3069. # membership check at all and joined `filename` straight to disk.
  3070. if not archive.photos or filename not in archive.photos:
  3071. raise HTTPException(404, "Photo not found")
  3072. # Defence-in-depth: even though the membership check above already
  3073. # constrains `filename` to UUID-generated names from upload,
  3074. # find_archive_photo resolves and containment-checks each candidate,
  3075. # guarding against future code paths that might populate
  3076. # `archive.photos` from a less-trusted source.
  3077. photo_path = find_archive_photo(archive, filename)
  3078. if photo_path is None:
  3079. raise HTTPException(404, "Photo not found")
  3080. # Determine media type
  3081. ext = Path(filename).suffix.lower()
  3082. media_types = {
  3083. ".jpg": "image/jpeg",
  3084. ".jpeg": "image/jpeg",
  3085. ".png": "image/png",
  3086. ".webp": "image/webp",
  3087. }
  3088. media_type = media_types.get(ext, "image/jpeg")
  3089. return FileResponse(path=photo_path, media_type=media_type)
  3090. @router.delete("/{archive_id}/photos/{filename}")
  3091. async def delete_photo(
  3092. archive_id: int,
  3093. filename: str,
  3094. db: AsyncSession = Depends(get_db),
  3095. auth_result: tuple[User | None, bool] = Depends(
  3096. require_ownership_permission(
  3097. Permission.ARCHIVES_DELETE_ALL,
  3098. Permission.ARCHIVES_DELETE_OWN,
  3099. )
  3100. ),
  3101. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3102. ):
  3103. """Delete a photo."""
  3104. user, can_modify_all = auth_result
  3105. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  3106. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  3107. if not archive.photos or filename not in archive.photos:
  3108. raise HTTPException(404, "Photo not found")
  3109. # Delete file — same lookup as get_photo above, so a photo that is
  3110. # readable is also deletable. Removing the name while leaving the file is
  3111. # how a no-3MF archive accumulated photos nobody could see or remove.
  3112. photo_path = find_archive_photo(archive, filename)
  3113. if photo_path is not None:
  3114. photo_path.unlink()
  3115. # Update archive photos list
  3116. photos = [p for p in archive.photos if p != filename]
  3117. archive.photos = photos if photos else None
  3118. await db.commit()
  3119. return {"status": "deleted", "photos": archive.photos}
  3120. # ============================================
  3121. # Post-print outcome confirmation (#1898)
  3122. # ============================================
  3123. # English-only on purpose: this page is rendered by the backend for a phone
  3124. # browser that carries no session and therefore no language preference.
  3125. _VERDICT_LABELS = {"good": "Good part", "reject": "Rejected"}
  3126. _VERDICT_SOURCE_PHRASES = {
  3127. "dialog": "in the app",
  3128. "link": "with a one-tap link",
  3129. "plate_clear": "automatically when the print plate was cleared",
  3130. "printer_card": "from the printer card",
  3131. "api": "through the API",
  3132. "reaction": "with a reaction in chat",
  3133. }
  3134. def _confirm_page(glyph: str, heading: str, body: str) -> str:
  3135. """The small HTML page every one-tap outcome link renders."""
  3136. return (
  3137. "<!doctype html><html><head><meta name='viewport' content='width=device-width, initial-scale=1'>"
  3138. "<title>Bambuddy</title></head>"
  3139. "<body style='font-family: system-ui, sans-serif; background:#1a1d21; color:#fff; display:flex;"
  3140. " align-items:center; justify-content:center; min-height:90vh; margin:0'>"
  3141. f"<div style='text-align:center; padding:0 1.5rem; max-width:32rem'>"
  3142. f"<div style='font-size:3rem'>{glyph}</div><h2>{heading}</h2>{body}</div></body></html>"
  3143. )
  3144. async def _render_already_answered_page(db: AsyncSession, archive: PrintArchive) -> str:
  3145. """Explain a spent one-tap link instead of calling it invalid.
  3146. The plate-clear default, the app and the other link all answer the same
  3147. prompt, so the button in a push notification is routinely tapped after the
  3148. question is settled. Report the verdict on file, when and how it landed,
  3149. and where to change it.
  3150. """
  3151. from backend.app.api.routes.settings import get_external_base_url
  3152. name = html_escape(archive.print_name or archive.filename or "")
  3153. # The verdict's own timestamp, not the moment the token was spent: a
  3154. # verdict changed later in the app would otherwise be dated by the older
  3155. # event. Pre-#1898 rows have neither, and then the page omits the date.
  3156. used_at = archive.user_verdict_at or archive.confirm_token_used_at
  3157. if used_at is not None and used_at.tzinfo is not None:
  3158. used_at = used_at.astimezone(timezone.utc)
  3159. when = used_at.strftime("%Y-%m-%d %H:%M UTC") if used_at else None
  3160. how = _VERDICT_SOURCE_PHRASES.get(archive.user_verdict_source or "")
  3161. label = _VERDICT_LABELS.get(archive.user_verdict or "")
  3162. if label:
  3163. recorded = f"Recorded as <strong>{label}</strong>"
  3164. if how:
  3165. recorded += f" {how}"
  3166. if when:
  3167. recorded += f" on {when}"
  3168. recorded += "."
  3169. else:
  3170. # The verdict was cleared again in the app; the link stays spent.
  3171. recorded = "This prompt was already answered and the verdict has since been cleared."
  3172. base = await get_external_base_url(db)
  3173. link = html_escape(f"{base}/archives?confirm={archive.id}", quote=True)
  3174. glyph = "&#10003;" if archive.user_verdict == "good" else "&#10007;" if archive.user_verdict else "&#8505;"
  3175. return _confirm_page(
  3176. glyph,
  3177. "Already answered",
  3178. f"<p style='color:#9ca3af'>{name}</p>"
  3179. f"<p style='color:#9ca3af'>{recorded}</p>"
  3180. f"<p><a style='color:#00ae42' href='{link}'>Open this print in Bambuddy</a> to change it.</p>",
  3181. )
  3182. def _render_confirm_prompt_page(request: Request, archive: PrintArchive, verdict: str) -> str:
  3183. """The page a one-tap verdict link opens. It has recorded nothing yet.
  3184. GET is where link unfurlers, mail-security scanners and browser prefetchers
  3185. arrive, uninvited and within seconds of the message being sent, so GET
  3186. writes nothing at all -- the verdict is recorded by the form below, over
  3187. POST, which none of them issue.
  3188. The form submits itself only for a page opened from a notification button,
  3189. which is what keeps the operator at one tap. The marker for that
  3190. (``?tap=1``) is put on the Telegram inline keyboard's URLs and nowhere else
  3191. -- never on a URL that travels in message text -- so a mail-security
  3192. sandbox that renders HTML and runs JavaScript cannot press the button for
  3193. the operator: it only ever sees the unmarked URL out of the body. The
  3194. User-Agent heuristic still runs on top of that, but it is no longer the
  3195. only thing between a scanner and the write; it cannot be, because such a
  3196. sandbox sends an ordinary Chrome string.
  3197. Every other arrival -- an unmarked link somebody typed or mailed, a browser
  3198. with JavaScript off -- gets the same page and presses the button.
  3199. """
  3200. name = html_escape(archive.print_name or archive.filename or "")
  3201. # Escaped although the route only lets good/reject through: the page must
  3202. # not depend on a check made in another function.
  3203. label = html_escape(_VERDICT_LABELS.get(verdict, verdict))
  3204. # No action attribute: the form posts back to the URL the page was loaded
  3205. # from, so it works behind a reverse proxy and on a host external_url does
  3206. # not name.
  3207. form = (
  3208. "<form method='post' id='confirm-form'>"
  3209. "<button type='submit' style='font: inherit; font-size:1.1rem; padding:0.9rem 2rem;"
  3210. " border:0; border-radius:0.5rem; background:#00ae42; color:#fff'>Yes, record it</button>"
  3211. "</form>"
  3212. )
  3213. # The SPA's CSP allows inline scripts only with the per-request nonce the
  3214. # security-headers middleware mints (main.py). Without one -- no middleware,
  3215. # an unmarked URL, or an unattended-looking caller -- the page simply waits
  3216. # for the button.
  3217. nonce = getattr(request.state, "csp_nonce", None)
  3218. script = ""
  3219. if nonce and is_one_tap_request(request.query_params) and not is_unattended_fetch(request.method, request.headers):
  3220. script = (
  3221. f"<script nonce='{html_escape(nonce, quote=True)}'>"
  3222. "document.getElementById('confirm-form').submit();</script>"
  3223. )
  3224. return _confirm_page(
  3225. "&#63;",
  3226. "Confirm this outcome",
  3227. f"<p style='color:#9ca3af'>{name}</p>"
  3228. f"<p style='color:#9ca3af'>Record this print as <strong>{label}</strong>?</p>"
  3229. f"{form}{script}",
  3230. )
  3231. def _confirm_response(html: str):
  3232. """The one-tap pages, never cached.
  3233. A proxy holding on to "Saved" or to the prompt would answer a later tap
  3234. from its cache, and the prompt page is a capability URL either way.
  3235. """
  3236. from fastapi.responses import HTMLResponse
  3237. return HTMLResponse(html, headers={"Cache-Control": "no-store"})
  3238. async def _load_confirmable_archive(db: AsyncSession, token: str, verdict: str) -> PrintArchive:
  3239. """Resolve a one-tap capability token, or raise the route's 400/404."""
  3240. if verdict not in ("good", "reject"):
  3241. raise HTTPException(400, "Verdict must be 'good' or 'reject'")
  3242. result = await db.execute(
  3243. select(PrintArchive).where(PrintArchive.confirm_token == token, PrintArchive.confirm_token.isnot(None))
  3244. )
  3245. archive = result.scalar_one_or_none()
  3246. if not archive:
  3247. raise HTTPException(404, "Confirmation link is invalid or was already used")
  3248. return archive
  3249. @router.get("/confirm/{token}/{verdict}")
  3250. async def confirm_outcome_page(
  3251. request: Request,
  3252. token: str,
  3253. verdict: str,
  3254. db: AsyncSession = Depends(get_db),
  3255. ):
  3256. """Open a one-tap verdict link. Reads only — the verdict is recorded by POST.
  3257. This used to be the route that recorded, and that was the defect: a GET
  3258. that changes state is answered by everything that walks a URL. Telegram
  3259. and Slack fetch the links in a message body to build a preview card, mail
  3260. gateways detonate them before delivery, browsers prefetch them — any one
  3261. of those spent the single-use token and settled the outcome before the
  3262. operator had read the question, always in the "good" direction because
  3263. good_url came first. Suppressing previews per channel does not cover the
  3264. proxies and scanners in between; only removing the write from GET does.
  3265. So GET now hands back the prompt page and nothing else. The page's form
  3266. POSTs to this same URL, and :func:`confirm_outcome_by_token` records it.
  3267. The human cost is zero for the path the feature is built around: a URL
  3268. opened from a notification button carries ``?tap=1`` and the page submits
  3269. itself, so that tap is still the only tap. Nothing else gets that script,
  3270. including a scanner that runs JavaScript -- the marker is on the buttons,
  3271. not in the message text a scanner reads.
  3272. """
  3273. archive = await _load_confirmable_archive(db, token, verdict)
  3274. if archive.confirm_token_used_at is not None:
  3275. # Answered already — by hand, by the other link, by the plate-clear
  3276. # default or by a reaction. Report what is on file and change nothing.
  3277. return _confirm_response(await _render_already_answered_page(db, archive))
  3278. return _confirm_response(_render_confirm_prompt_page(request, archive, verdict))
  3279. @router.post("/confirm/{token}/{verdict}")
  3280. async def confirm_outcome_by_token(
  3281. token: str,
  3282. verdict: str,
  3283. db: AsyncSession = Depends(get_db),
  3284. ):
  3285. """Record a print-outcome verdict via the capability token from a push notification.
  3286. Deliberately unauthenticated: the token IS the credential. It is a 256-bit
  3287. per-archive capability, minted when the confirmation prompt fires, and it
  3288. only ever grants writing good/reject on that one archive, exactly once.
  3289. "Exactly once" is enforced by ``confirm_token_used_at`` rather than by
  3290. dropping the token value, so a link for a print that was already answered
  3291. can be recognised and explained instead of looking broken.
  3292. POST is what keeps the capability the operator's: unfurlers, scanners and
  3293. prefetchers issue GET, and the GET route above writes nothing. The two
  3294. callers that reach here are the prompt page's form and the ntfy action
  3295. button, which performs its own request from the phone and is configured
  3296. with ``method=POST``. Returns a small HTML page for the phone browser.
  3297. """
  3298. archive = await _load_confirmable_archive(db, token, verdict)
  3299. if archive.confirm_token_used_at is not None:
  3300. return _confirm_response(await _render_already_answered_page(db, archive))
  3301. archive.user_verdict = verdict
  3302. stamp_verdict(archive, "link")
  3303. retire_confirm_token(archive)
  3304. # Same mirror as the PATCH route (#1444): verdict-aware statistics read
  3305. # print_log_entries, so the latest run must carry the verdict too.
  3306. from backend.app.models.print_log import PrintLogEntry
  3307. latest_entry = await db.scalar(
  3308. select(PrintLogEntry).where(PrintLogEntry.archive_id == archive.id).order_by(PrintLogEntry.id.desc()).limit(1)
  3309. )
  3310. if latest_entry is not None:
  3311. latest_entry.user_verdict = verdict
  3312. await db.commit()
  3313. label = "Good part" if verdict == "good" else "Rejected"
  3314. name = archive.print_name or archive.filename
  3315. return _confirm_response(
  3316. _confirm_page(
  3317. "&#10003;" if verdict == "good" else "&#10007;",
  3318. label,
  3319. f"<p style='color:#9ca3af'>{html_escape(name)}</p>"
  3320. "<p style='color:#9ca3af'>Saved &mdash; you can close this page.</p>",
  3321. )
  3322. )
  3323. # ============================================
  3324. # QR Code Endpoint
  3325. # ============================================
  3326. @router.get("/{archive_id}/qrcode")
  3327. async def get_qrcode(
  3328. archive_id: int,
  3329. request: Request,
  3330. size: int = 200,
  3331. db: AsyncSession = Depends(get_db),
  3332. auth_result: tuple[User | None, bool] = Depends(
  3333. require_media_token_ownership(
  3334. Permission.ARCHIVES_READ_ALL,
  3335. Permission.ARCHIVES_READ_OWN,
  3336. )
  3337. ),
  3338. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3339. ):
  3340. """Generate a QR code that links to this archive.
  3341. Requires a media token query param (?token=xxx) when auth is enabled, and
  3342. returns 404 for an archive the caller may not read (#3025).
  3343. """
  3344. user, can_read_all = auth_result
  3345. try:
  3346. import qrcode
  3347. from PIL import Image as PILImage
  3348. except ImportError:
  3349. raise HTTPException(500, "QR code generation not available - qrcode package not installed")
  3350. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  3351. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  3352. # Build URL to archive download
  3353. base_url = str(request.base_url).rstrip("/")
  3354. archive_url = f"{base_url}/api/v1/archives/{archive_id}/download"
  3355. # Generate QR code
  3356. qr = qrcode.QRCode(
  3357. version=1,
  3358. error_correction=qrcode.constants.ERROR_CORRECT_M,
  3359. box_size=10,
  3360. border=2,
  3361. )
  3362. qr.add_data(archive_url)
  3363. qr.make(fit=True)
  3364. img = qr.make_image(fill_color="black", back_color="white")
  3365. # Convert to PIL Image for resizing
  3366. pil_img = img.get_image()
  3367. # Resize if needed
  3368. if size != 200:
  3369. pil_img = pil_img.resize((size, size), PILImage.Resampling.LANCZOS)
  3370. # Convert to bytes
  3371. buffer = io.BytesIO()
  3372. pil_img.save(buffer, format="PNG")
  3373. buffer.seek(0)
  3374. qr_filename = f"qr_{archive.print_name or archive_id}.png"
  3375. return Response(
  3376. content=buffer.getvalue(),
  3377. media_type="image/png",
  3378. headers={"Content-Disposition": build_content_disposition(qr_filename, disposition="inline")},
  3379. )
  3380. @router.get("/{archive_id}/capabilities")
  3381. async def get_archive_capabilities(
  3382. archive_id: int,
  3383. db: AsyncSession = Depends(get_db),
  3384. auth_result: tuple[User | None, bool] = Depends(
  3385. require_ownership_permission(
  3386. Permission.ARCHIVES_READ_ALL,
  3387. Permission.ARCHIVES_READ_OWN,
  3388. )
  3389. ),
  3390. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3391. ):
  3392. """Check what viewing capabilities are available for this 3MF file."""
  3393. import defusedxml.ElementTree as ET
  3394. user, can_read_all = auth_result
  3395. service = ArchiveService(db)
  3396. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  3397. file_path = settings.base_dir / archive.file_path
  3398. if not file_path.is_file():
  3399. raise HTTPException(404, "File not found")
  3400. has_model = False
  3401. has_gcode = False
  3402. has_source = False
  3403. build_volume = {"x": 256, "y": 256, "z": 256} # Default to X1/P1 size
  3404. filament_colors: list[str] = []
  3405. # Check if source 3MF exists - this is where actual mesh data typically lives
  3406. source_path = None
  3407. if archive.source_3mf_path:
  3408. source_path = settings.base_dir / archive.source_3mf_path
  3409. if source_path.exists():
  3410. has_source = True
  3411. # Helper function to check for mesh data and extract colors from a 3MF file
  3412. def extract_3mf_info(zf_path: Path) -> tuple[bool, list[str], dict]:
  3413. """Extract mesh presence, colors, and build volume from a 3MF file."""
  3414. found_mesh = False
  3415. colors: list[str] = []
  3416. volume = {"x": 256, "y": 256, "z": 256}
  3417. try:
  3418. with zipfile.ZipFile(zf_path, "r") as zf:
  3419. names = zf.namelist()
  3420. # Check for 3D model - look for actual mesh data
  3421. for name in names:
  3422. if name.endswith(".model"):
  3423. try:
  3424. content = zf.read(name).decode("utf-8")
  3425. if "<vertex" in content or "<mesh" in content:
  3426. found_mesh = True
  3427. break
  3428. except Exception:
  3429. pass # Skip unreadable .model entries in archive
  3430. # Extract filament colors from project_settings.config
  3431. if "Metadata/project_settings.config" in names:
  3432. try:
  3433. config_content = zf.read("Metadata/project_settings.config").decode("utf-8")
  3434. config_data = json.loads(config_content)
  3435. # Parse printable_area: ['0x0', '256x0', '256x256', '0x256']
  3436. printable_area = config_data.get("printable_area", [])
  3437. if printable_area and len(printable_area) >= 3:
  3438. max_x = 0
  3439. max_y = 0
  3440. for coord in printable_area:
  3441. if "x" in coord:
  3442. parts = coord.split("x")
  3443. if len(parts) == 2:
  3444. try:
  3445. x, y = int(parts[0]), int(parts[1])
  3446. max_x = max(max_x, x)
  3447. max_y = max(max_y, y)
  3448. except ValueError:
  3449. pass # Skip non-numeric printable_area coordinate
  3450. if max_x > 0 and max_y > 0:
  3451. volume["x"] = max_x
  3452. volume["y"] = max_y
  3453. # Parse printable_height
  3454. printable_height = config_data.get("printable_height")
  3455. if printable_height:
  3456. try:
  3457. volume["z"] = int(printable_height)
  3458. except (ValueError, TypeError):
  3459. pass # Skip unparseable printable_height value
  3460. # Extract filament colors
  3461. raw_colors = config_data.get("filament_colour", [])
  3462. if raw_colors:
  3463. for color in raw_colors:
  3464. if color and isinstance(color, str):
  3465. colors.append(color)
  3466. except Exception:
  3467. pass # Skip malformed project_settings.config
  3468. except zipfile.BadZipFile:
  3469. pass # File is not a valid zip/3MF archive
  3470. return found_mesh, colors, volume
  3471. # First check source 3MF for mesh data and colors (preferred for 3D model viewing)
  3472. if has_source and source_path:
  3473. source_has_mesh, source_colors, source_volume = extract_3mf_info(source_path)
  3474. if source_has_mesh:
  3475. has_model = True
  3476. if source_colors:
  3477. filament_colors = source_colors
  3478. if source_volume["x"] != 256 or source_volume["y"] != 256 or source_volume["z"] != 256:
  3479. build_volume = source_volume
  3480. try:
  3481. with zipfile.ZipFile(file_path, "r") as zf:
  3482. names = zf.namelist()
  3483. # Check for G-code in the sliced file. Shared with the library's
  3484. # file-type classification so the card's badge and what the File
  3485. # Manager makes of the same file cannot disagree (#2993).
  3486. has_gcode = names_carry_gcode(names)
  3487. # Check for 3D model in sliced file (fallback if no source)
  3488. if not has_model:
  3489. for name in names:
  3490. if name.endswith(".model"):
  3491. try:
  3492. content = zf.read(name).decode("utf-8")
  3493. if "<vertex" in content or "<mesh" in content:
  3494. has_model = True
  3495. break
  3496. except Exception:
  3497. pass # Skip unreadable .model entries in archive
  3498. # Extract filament colors from slice_info.config (for gcode preview)
  3499. # These are the actual filaments used in the print, indexed by tool/extruder
  3500. slice_colors: list[str] = []
  3501. if "Metadata/slice_info.config" in names:
  3502. try:
  3503. slice_content = zf.read("Metadata/slice_info.config").decode("utf-8")
  3504. root = ET.fromstring(slice_content)
  3505. filaments = root.findall(".//filament")
  3506. filament_map: dict[int, str] = {}
  3507. for f in filaments:
  3508. fid = f.get("id")
  3509. fcolor = f.get("color")
  3510. used_g = f.get("used_g", "0")
  3511. try:
  3512. used_amount = float(used_g)
  3513. except (ValueError, TypeError):
  3514. used_amount = 0
  3515. if fid is not None and fcolor:
  3516. try:
  3517. tool_id = int(fid) - 1
  3518. if tool_id >= 0 and used_amount > 0:
  3519. filament_map[tool_id] = fcolor
  3520. except ValueError:
  3521. pass # Skip filament entry with non-numeric ID
  3522. if filament_map:
  3523. max_tool = max(filament_map.keys())
  3524. for i in range(max_tool + 1):
  3525. slice_colors.append(filament_map.get(i, "#00AE42"))
  3526. except Exception:
  3527. pass # Skip malformed slice_info.config XML
  3528. # Use slice_info colors if we don't have colors from source yet
  3529. if not filament_colors and slice_colors:
  3530. filament_colors = slice_colors
  3531. # Extract build volume from sliced file if not already set from source
  3532. if build_volume["x"] == 256 and build_volume["y"] == 256:
  3533. if "Metadata/project_settings.config" in names:
  3534. try:
  3535. config_content = zf.read("Metadata/project_settings.config").decode("utf-8")
  3536. config_data = json.loads(config_content)
  3537. printable_area = config_data.get("printable_area", [])
  3538. if printable_area and len(printable_area) >= 3:
  3539. max_x = 0
  3540. max_y = 0
  3541. for coord in printable_area:
  3542. if "x" in coord:
  3543. parts = coord.split("x")
  3544. if len(parts) == 2:
  3545. try:
  3546. x, y = int(parts[0]), int(parts[1])
  3547. max_x = max(max_x, x)
  3548. max_y = max(max_y, y)
  3549. except ValueError:
  3550. pass # Skip non-numeric printable_area coordinate
  3551. if max_x > 0 and max_y > 0:
  3552. build_volume["x"] = max_x
  3553. build_volume["y"] = max_y
  3554. printable_height = config_data.get("printable_height")
  3555. if printable_height:
  3556. try:
  3557. build_volume["z"] = int(printable_height)
  3558. except (ValueError, TypeError):
  3559. pass # Skip unparseable printable_height value
  3560. # Fallback colors from project_settings if still empty
  3561. if not filament_colors:
  3562. raw_colors = config_data.get("filament_colour", [])
  3563. if raw_colors:
  3564. for color in raw_colors:
  3565. if color and isinstance(color, str):
  3566. filament_colors.append(color)
  3567. except Exception:
  3568. pass # Skip malformed project_settings.config
  3569. except zipfile.BadZipFile:
  3570. raise HTTPException(400, "Invalid 3MF file")
  3571. return {
  3572. "has_model": has_model,
  3573. "has_gcode": has_gcode,
  3574. "has_source": has_source,
  3575. "build_volume": build_volume,
  3576. "filament_colors": filament_colors,
  3577. }
  3578. @router.get("/{archive_id}/gcode")
  3579. async def get_gcode(
  3580. archive_id: int,
  3581. plate: int | None = None,
  3582. db: AsyncSession = Depends(get_db),
  3583. auth_result: tuple[User | None, bool] = Depends(
  3584. require_ownership_permission(
  3585. Permission.ARCHIVES_READ_ALL,
  3586. Permission.ARCHIVES_READ_OWN,
  3587. )
  3588. ),
  3589. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3590. ):
  3591. """Extract and return G-code from the 3MF file.
  3592. When *plate* is provided, returns the G-code for that specific plate
  3593. (e.g. ``?plate=2`` returns ``Metadata/plate_2.gcode``). If omitted, falls
  3594. back to the archive's lowest-numbered plate — not the first member in the
  3595. zip, which is whatever order the slicer wrote and routinely puts plate 2
  3596. ahead of plate 1.
  3597. """
  3598. user, can_read_all = auth_result
  3599. service = ArchiveService(db)
  3600. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  3601. file_path = settings.base_dir / archive.file_path
  3602. if not file_path.is_file():
  3603. raise HTTPException(404, "File not found")
  3604. if plate is not None and plate < 1:
  3605. raise HTTPException(400, "Plate index must be >= 1")
  3606. try:
  3607. with zipfile.ZipFile(file_path, "r") as zf:
  3608. # Bambu 3MF files store G-code in Metadata/plate_X.gcode
  3609. gcode_files = [n for n in zf.namelist() if n.startswith("Metadata/") and n.endswith(".gcode")]
  3610. if not gcode_files:
  3611. raise HTTPException(
  3612. 404,
  3613. "No G-code found. This file hasn't been sliced yet - G-code is only available after slicing in Bambu Studio.",
  3614. )
  3615. if plate is not None:
  3616. selected = select_plate_gcode_name(gcode_files, plate)
  3617. if selected is None:
  3618. raise HTTPException(404, f"Plate {plate} not found in this archive")
  3619. else:
  3620. selected = default_plate_gcode_name(gcode_files)
  3621. gcode_content = zf.read(selected).decode("utf-8")
  3622. return Response(content=gcode_content, media_type="text/plain")
  3623. except zipfile.BadZipFile:
  3624. raise HTTPException(400, "Invalid 3MF file")
  3625. except HTTPException:
  3626. raise
  3627. except Exception as e:
  3628. raise HTTPException(500, f"Error extracting G-code: {str(e)}")
  3629. @router.get("/{archive_id}/plate-preview")
  3630. async def get_plate_preview(
  3631. archive_id: int,
  3632. db: AsyncSession = Depends(get_db),
  3633. auth_result: tuple[User | None, bool] = Depends(
  3634. require_media_token_ownership(
  3635. Permission.ARCHIVES_READ_ALL,
  3636. Permission.ARCHIVES_READ_OWN,
  3637. )
  3638. ),
  3639. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3640. ):
  3641. """Get the plate preview image from the 3MF file.
  3642. Returns the slicer-generated plate thumbnail which shows the model
  3643. with correct colors and positioning.
  3644. Requires a media token query param (?token=xxx) when auth is enabled, and
  3645. returns 404 for an archive the caller may not read (#3025).
  3646. """
  3647. user, can_read_all = auth_result
  3648. service = ArchiveService(db)
  3649. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  3650. file_path = settings.base_dir / archive.file_path
  3651. if not file_path.is_file():
  3652. raise HTTPException(404, "File not found")
  3653. try:
  3654. with zipfile.ZipFile(file_path, "r") as zf:
  3655. names = zf.namelist()
  3656. # Try to find plate preview images in order of preference
  3657. # First look for the specific plate being printed (check slice_info for plate index)
  3658. plate_num = 1
  3659. if "Metadata/slice_info.config" in names:
  3660. try:
  3661. import defusedxml.ElementTree as ET
  3662. slice_content = zf.read("Metadata/slice_info.config").decode("utf-8")
  3663. root = ET.fromstring(slice_content)
  3664. plate_elem = root.find(".//plate/metadata[@key='index']")
  3665. if plate_elem is not None:
  3666. plate_num = int(plate_elem.get("value", "1"))
  3667. except Exception:
  3668. pass # Default plate_num=1 if slice_info is missing or malformed
  3669. # Try plate-specific image first, then fall back to plate_1
  3670. preview_paths = [
  3671. f"Metadata/plate_{plate_num}.png",
  3672. "Metadata/plate_1.png",
  3673. "Metadata/thumbnail.png",
  3674. ]
  3675. for preview_path in preview_paths:
  3676. if preview_path in names:
  3677. image_data = zf.read(preview_path)
  3678. return Response(content=image_data, media_type="image/png")
  3679. # If no plate image, try any PNG in Metadata
  3680. for name in names:
  3681. if name.startswith("Metadata/plate_") and name.endswith(".png") and "_small" not in name:
  3682. image_data = zf.read(name)
  3683. return Response(content=image_data, media_type="image/png")
  3684. raise HTTPException(404, "No plate preview found in 3MF file")
  3685. except zipfile.BadZipFile:
  3686. raise HTTPException(400, "Invalid 3MF file")
  3687. except HTTPException:
  3688. raise
  3689. except Exception as e:
  3690. raise HTTPException(500, f"Error extracting plate preview: {str(e)}")
  3691. @router.post("/upload")
  3692. async def upload_archive(
  3693. file: UploadFile = File(...),
  3694. printer_id: int | None = None,
  3695. prefer_filename_for_name: bool = Query(
  3696. False,
  3697. description=(
  3698. "Name the archive after the uploaded filename instead of the print_name "
  3699. "embedded in the 3MF's metadata. Off by default, which keeps the embedded "
  3700. "name. Turn it on when the filename you send is the meaningful one — an "
  3701. "integration naming files after its own jobs, or a file whose embedded "
  3702. "title is a stale name from whoever originally sliced it."
  3703. ),
  3704. ),
  3705. db: AsyncSession = Depends(get_db),
  3706. current_user: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_CREATE),
  3707. printer_scope: PrinterScope = RequestPrinterScope,
  3708. ):
  3709. """Manually upload a 3MF file to archive.
  3710. prefer_filename_for_name is the same flag the FTP review flow and
  3711. virtual-printer dispatch already pass to ArchiveService.archive_print —
  3712. this endpoint just didn't expose it (#1152 follow-up). Those callers derive
  3713. it from the VP-scoped `virtual_printer_archive_name_source` setting; here it
  3714. is per-request, because the caller is an API client that knows whether the
  3715. filename it sent is the meaningful one (#2609).
  3716. """
  3717. printer_scope.ensure(printer_id)
  3718. if not file.filename or not file.filename.endswith(".3mf"):
  3719. raise HTTPException(400, "File must be a .3mf file")
  3720. # Save uploaded file temporarily — strip directory components to prevent path traversal
  3721. safe_filename = _safe_filename(file.filename)
  3722. temp_path = (
  3723. settings.archive_dir / "temp" / safe_filename
  3724. ) # SEC-PATH-OK: safe_filename = _safe_filename(...) basename-stripped above
  3725. temp_path.parent.mkdir(parents=True, exist_ok=True)
  3726. try:
  3727. content = await file.read()
  3728. # #1401: same content validation as library upload — catches
  3729. # raw-gcode-renamed-to-.3mf and other unprintable shapes before
  3730. # archiving them and offering them up for print.
  3731. from backend.app.api.routes.library import validate_print_file_upload
  3732. validate_print_file_upload(file.filename, content)
  3733. temp_path.write_bytes(content)
  3734. service = ArchiveService(db)
  3735. archive = await service.archive_print(
  3736. printer_id=printer_id,
  3737. source_file=temp_path,
  3738. created_by_id=current_user.id if current_user else None,
  3739. prefer_filename_for_name=prefer_filename_for_name,
  3740. )
  3741. if not archive:
  3742. raise HTTPException(400, "Failed to archive file")
  3743. return ArchiveResponse.model_validate(archive)
  3744. finally:
  3745. if temp_path.exists():
  3746. temp_path.unlink()
  3747. @router.post("/upload-bulk")
  3748. async def upload_archives_bulk(
  3749. files: list[UploadFile] = File(...),
  3750. printer_id: int | None = None,
  3751. prefer_filename_for_name: bool = Query(
  3752. False,
  3753. description=(
  3754. "Name each archive after its uploaded filename instead of the print_name "
  3755. "embedded in the 3MF's metadata. Applies to every file in the batch. Off "
  3756. "by default, which keeps the embedded name."
  3757. ),
  3758. ),
  3759. db: AsyncSession = Depends(get_db),
  3760. current_user: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_CREATE),
  3761. printer_scope: PrinterScope = RequestPrinterScope,
  3762. ):
  3763. """Bulk upload multiple 3MF files to archive.
  3764. prefer_filename_for_name applies to every file in the batch. See
  3765. upload_archive for the flag's lineage.
  3766. """
  3767. printer_scope.ensure(printer_id)
  3768. from backend.app.api.routes.library import validate_print_file_upload
  3769. results = []
  3770. errors = []
  3771. for file in files:
  3772. if not file.filename or not file.filename.endswith(".3mf"):
  3773. errors.append({"filename": file.filename or "unknown", "error": "Not a .3mf file"})
  3774. continue
  3775. safe_filename = _safe_filename(file.filename)
  3776. temp_path = (
  3777. settings.archive_dir / "temp" / safe_filename
  3778. ) # SEC-PATH-OK: safe_filename = _safe_filename(...) basename-stripped above
  3779. temp_path.parent.mkdir(parents=True, exist_ok=True)
  3780. try:
  3781. content = await file.read()
  3782. # #1401: bulk-upload variant of the library validation. Collect
  3783. # the rejection per-file rather than aborting the whole batch
  3784. # so one bad file in a 10-file drag-drop doesn't lose the
  3785. # other nine.
  3786. try:
  3787. validate_print_file_upload(file.filename, content)
  3788. except HTTPException as exc:
  3789. errors.append({"filename": file.filename, "error": exc.detail})
  3790. continue
  3791. temp_path.write_bytes(content)
  3792. service = ArchiveService(db)
  3793. archive = await service.archive_print(
  3794. printer_id=printer_id,
  3795. source_file=temp_path,
  3796. created_by_id=current_user.id if current_user else None,
  3797. prefer_filename_for_name=prefer_filename_for_name,
  3798. )
  3799. if archive:
  3800. results.append(
  3801. {
  3802. "filename": file.filename,
  3803. "id": archive.id,
  3804. "status": "success",
  3805. }
  3806. )
  3807. else:
  3808. errors.append({"filename": file.filename, "error": "Failed to process"})
  3809. except Exception as e:
  3810. logger.exception("Failed to upload archive %s: %s", file.filename, e)
  3811. errors.append({"filename": file.filename, "error": "Failed to process file"})
  3812. finally:
  3813. if temp_path.exists():
  3814. temp_path.unlink()
  3815. return {
  3816. "uploaded": len(results),
  3817. "failed": len(errors),
  3818. "results": results,
  3819. "errors": errors,
  3820. }
  3821. @router.get("/{archive_id}/plates")
  3822. async def get_archive_plates(
  3823. archive_id: int,
  3824. db: AsyncSession = Depends(get_db),
  3825. auth_result: tuple[User | None, bool] = Depends(
  3826. require_ownership_permission(
  3827. Permission.ARCHIVES_READ_ALL,
  3828. Permission.ARCHIVES_READ_OWN,
  3829. )
  3830. ),
  3831. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  3832. ):
  3833. """Get available plates from a multi-plate 3MF archive.
  3834. Returns a list of plates with their index, name, thumbnail availability,
  3835. and filament requirements. For single-plate exports, returns a single plate.
  3836. """
  3837. import re
  3838. import defusedxml.ElementTree as ET
  3839. user, can_read_all = auth_result
  3840. service = ArchiveService(db)
  3841. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  3842. file_path = settings.base_dir / archive.file_path
  3843. if not file_path.is_file():
  3844. raise HTTPException(404, "Archive file not found")
  3845. plates = []
  3846. # Initialize so the `has_gcode = bool(gcode_files)` after the try/except
  3847. # never raises NameError when the archive isn't a valid zip (e.g. plain
  3848. # .gcode file from a sliced-archive flow that didn't request 3MF output).
  3849. gcode_files: list[str] = []
  3850. # Printer / process preset names the 3MF was prepared with — used by the
  3851. # SliceModal to default its dropdowns (#1325).
  3852. embedded_presets: dict[str, str | None] = {"printer": None, "process": None}
  3853. # Process settings the designer changed away from the stock preset (#2622),
  3854. # offered in the SliceModal for a cross-printer re-slice. Same payload the
  3855. # library plates endpoint returns — SliceModal reads one shape for both.
  3856. design_overrides: list[dict] = []
  3857. try:
  3858. with zipfile.ZipFile(file_path, "r") as zf:
  3859. namelist = zf.namelist()
  3860. embedded_presets = extract_embedded_presets_from_3mf(zf)
  3861. if _PROJECT_SETTINGS_PATH in namelist:
  3862. try:
  3863. design_overrides = [
  3864. o._asdict()
  3865. for o in overrides_from_config(json.loads(zf.read(_PROJECT_SETTINGS_PATH).decode("utf-8")))
  3866. ]
  3867. except (ValueError, OSError, KeyError):
  3868. design_overrides = []
  3869. # Find all plate gcode files to determine available plates
  3870. gcode_files = [n for n in namelist if n.startswith("Metadata/plate_") and n.endswith(".gcode")]
  3871. # If no gcode is present (source-only or unsliced), fall back to plate JSON/PNG
  3872. plate_indices: list[int] = []
  3873. if gcode_files:
  3874. # Extract plate indices from gcode filenames
  3875. for gf in gcode_files:
  3876. # "Metadata/plate_5.gcode" -> 5
  3877. try:
  3878. # Remove "Metadata/plate_" and ".gcode"
  3879. plate_str = gf[15:-6]
  3880. plate_indices.append(int(plate_str))
  3881. except ValueError:
  3882. pass # Skip gcode file with non-numeric plate index
  3883. else:
  3884. plate_json_files = [n for n in namelist if n.startswith("Metadata/plate_") and n.endswith(".json")]
  3885. plate_png_files = [
  3886. n
  3887. for n in namelist
  3888. if n.startswith("Metadata/plate_")
  3889. and n.endswith(".png")
  3890. and "_small" not in n
  3891. and "no_light" not in n
  3892. ]
  3893. plate_name_candidates = plate_json_files + plate_png_files
  3894. plate_re = re.compile(r"^Metadata/plate_(\d+)\.(json|png)$")
  3895. seen_indices: set[int] = set()
  3896. for name in plate_name_candidates:
  3897. match = plate_re.match(name)
  3898. if match:
  3899. try:
  3900. index = int(match.group(1))
  3901. except ValueError:
  3902. continue
  3903. if index in seen_indices:
  3904. continue
  3905. seen_indices.add(index)
  3906. plate_indices.append(index)
  3907. if not plate_indices:
  3908. # No plate metadata found
  3909. return {
  3910. "archive_id": archive_id,
  3911. "filename": archive.filename,
  3912. "plates": [],
  3913. "is_multi_plate": False,
  3914. }
  3915. plate_indices.sort()
  3916. # Parse model_settings.config for plate names + object assignments
  3917. # Plate names are stored with plater_id and plater_name keys
  3918. plate_names = {} # plater_id -> name
  3919. plate_object_ids: dict[int, list[str]] = {}
  3920. object_names_by_id: dict[str, str] = {}
  3921. if "Metadata/model_settings.config" in namelist:
  3922. try:
  3923. model_content = zf.read("Metadata/model_settings.config").decode()
  3924. model_root = ET.fromstring(model_content)
  3925. # Build object ID -> name map
  3926. for obj_elem in model_root.findall(".//object"):
  3927. obj_id = obj_elem.get("id")
  3928. if not obj_id:
  3929. continue
  3930. name_meta = obj_elem.find("metadata[@key='name']")
  3931. obj_name = name_meta.get("value") if name_meta is not None else None
  3932. if obj_name:
  3933. object_names_by_id[obj_id] = obj_name
  3934. for plate_elem in model_root.findall(".//plate"):
  3935. plater_id = None
  3936. plater_name = None
  3937. for meta in plate_elem.findall("metadata"):
  3938. key = meta.get("key")
  3939. value = meta.get("value")
  3940. if key == "plater_id" and value:
  3941. try:
  3942. plater_id = int(value)
  3943. except ValueError:
  3944. pass # Skip plate with non-numeric plater_id
  3945. elif key == "plater_name" and value:
  3946. plater_name = value.strip()
  3947. if plater_id is not None and plater_name:
  3948. plate_names[plater_id] = plater_name
  3949. if plater_id is not None:
  3950. for instance_elem in plate_elem.findall("model_instance"):
  3951. for inst_meta in instance_elem.findall("metadata"):
  3952. if inst_meta.get("key") == "object_id":
  3953. obj_id = inst_meta.get("value")
  3954. if not obj_id:
  3955. continue
  3956. plate_object_ids.setdefault(plater_id, [])
  3957. if obj_id not in plate_object_ids[plater_id]:
  3958. plate_object_ids[plater_id].append(obj_id)
  3959. except Exception:
  3960. pass # model_settings.config parsing is optional
  3961. # Parse slice_info.config for plate metadata
  3962. plate_metadata = {} # plate_index -> {filaments, prediction, weight, name, objects}
  3963. if "Metadata/slice_info.config" in namelist:
  3964. content = zf.read("Metadata/slice_info.config").decode()
  3965. root = ET.fromstring(content)
  3966. for plate_elem in root.findall(".//plate"):
  3967. plate_info = {
  3968. "filaments": [],
  3969. "prediction": None,
  3970. "weight": None,
  3971. "name": None,
  3972. "objects": [],
  3973. "bed_type": None,
  3974. }
  3975. # Get plate index from metadata
  3976. plate_index = None
  3977. for meta in plate_elem.findall("metadata"):
  3978. key = meta.get("key")
  3979. value = meta.get("value")
  3980. if key == "index" and value:
  3981. try:
  3982. plate_index = int(value)
  3983. except ValueError:
  3984. pass # Skip plate with non-numeric index
  3985. elif key == "prediction" and value:
  3986. try:
  3987. plate_info["prediction"] = int(value)
  3988. except ValueError:
  3989. pass # Skip non-numeric print time prediction
  3990. elif key == "weight" and value:
  3991. try:
  3992. plate_info["weight"] = float(value)
  3993. except ValueError:
  3994. pass # Skip non-numeric filament weight
  3995. elif key == "curr_bed_type" and value:
  3996. # Per-plate bed type so the PrintModal can show the
  3997. # right plate alongside each option (#1281).
  3998. plate_info["bed_type"] = value.strip()
  3999. # Get filaments used in this plate
  4000. for filament_elem in plate_elem.findall("filament"):
  4001. filament_id = filament_elem.get("id")
  4002. filament_type = filament_elem.get("type", "")
  4003. filament_color = filament_elem.get("color", "")
  4004. used_g = filament_elem.get("used_g", "0")
  4005. used_m = filament_elem.get("used_m", "0")
  4006. try:
  4007. used_grams = float(used_g)
  4008. except (ValueError, TypeError):
  4009. used_grams = 0
  4010. if used_grams > 0 and filament_id:
  4011. plate_info["filaments"].append(
  4012. {
  4013. "slot_id": int(filament_id),
  4014. "type": filament_type,
  4015. "color": filament_color,
  4016. "used_grams": round(used_grams, 1),
  4017. "used_meters": float(used_m) if used_m else 0,
  4018. }
  4019. )
  4020. # Sort filaments by slot ID
  4021. plate_info["filaments"].sort(key=lambda x: x["slot_id"])
  4022. # Collect all object names on this plate
  4023. for obj_elem in plate_elem.findall("object"):
  4024. obj_name = obj_elem.get("name")
  4025. if obj_name and obj_name not in plate_info["objects"]:
  4026. plate_info["objects"].append(obj_name)
  4027. # Set plate name: prefer custom name from model_settings.config,
  4028. # fall back to first object name if no custom name was set
  4029. if plate_index is not None:
  4030. custom_name = plate_names.get(plate_index)
  4031. if custom_name:
  4032. plate_info["name"] = custom_name
  4033. else:
  4034. # Fall back to first object name as hint
  4035. if plate_info["objects"]:
  4036. plate_info["name"] = plate_info["objects"][0]
  4037. plate_metadata[plate_index] = plate_info
  4038. # Parse plate_*.json for object lists when slice_info is missing
  4039. plate_json_objects: dict[int, list[str]] = {}
  4040. for name in namelist:
  4041. match = re.match(r"^Metadata/plate_(\d+)\.json$", name)
  4042. if not match:
  4043. continue
  4044. try:
  4045. plate_index = int(match.group(1))
  4046. except ValueError:
  4047. continue
  4048. try:
  4049. payload = json.loads(zf.read(name).decode())
  4050. bbox_objects = payload.get("bbox_objects", [])
  4051. names = []
  4052. for obj in bbox_objects:
  4053. obj_name = obj.get("name") if isinstance(obj, dict) else None
  4054. if obj_name and obj_name not in names:
  4055. names.append(obj_name)
  4056. if names:
  4057. plate_json_objects[plate_index] = names
  4058. except Exception:
  4059. continue
  4060. # Build plate list
  4061. for idx in plate_indices:
  4062. meta = plate_metadata.get(idx, {})
  4063. has_thumbnail = f"Metadata/plate_{idx}.png" in namelist
  4064. objects = meta.get("objects", [])
  4065. if not objects:
  4066. objects = plate_json_objects.get(idx, [])
  4067. if not objects and plate_object_ids.get(idx):
  4068. objects = [
  4069. object_names_by_id.get(obj_id, f"Object {obj_id}") for obj_id in plate_object_ids.get(idx, [])
  4070. ]
  4071. plate_name = meta.get("name")
  4072. if not plate_name:
  4073. plate_name = plate_names.get(idx)
  4074. if not plate_name and objects:
  4075. plate_name = objects[0]
  4076. plates.append(
  4077. {
  4078. "index": idx,
  4079. "name": plate_name,
  4080. "objects": objects,
  4081. "object_count": len(objects),
  4082. "has_thumbnail": has_thumbnail,
  4083. "thumbnail_url": f"/api/v1/archives/{archive_id}/plate-thumbnail/{idx}"
  4084. if has_thumbnail
  4085. else None,
  4086. "print_time_seconds": meta.get("prediction"),
  4087. "filament_used_grams": meta.get("weight"),
  4088. "filaments": meta.get("filaments", []),
  4089. "bed_type": meta.get("bed_type"),
  4090. }
  4091. )
  4092. except Exception as e:
  4093. logger.warning("Failed to parse plates from archive %s: %s", archive_id, e)
  4094. # Has gcode iff the plate list was built from .gcode filenames (as opposed
  4095. # to the JSON/PNG fallback for source-only 3MF projects). Callers that need
  4096. # to preview gcode — the viewer, skip-objects — can gate on this instead of
  4097. # 404-ing on every plate request.
  4098. has_gcode = bool(gcode_files)
  4099. return {
  4100. "archive_id": archive_id,
  4101. "filename": archive.filename,
  4102. "plates": plates,
  4103. "is_multi_plate": len(plates) > 1,
  4104. "has_gcode": has_gcode,
  4105. "embedded_printer": embedded_presets["printer"],
  4106. "embedded_process": embedded_presets["process"],
  4107. "design_overrides": design_overrides,
  4108. }
  4109. @router.get("/{archive_id}/plate-thumbnail/{plate_index}")
  4110. async def get_plate_thumbnail(
  4111. archive_id: int,
  4112. plate_index: int,
  4113. db: AsyncSession = Depends(get_db),
  4114. auth_result: tuple[User | None, bool] = Depends(
  4115. require_media_token_ownership(
  4116. Permission.ARCHIVES_READ_ALL,
  4117. Permission.ARCHIVES_READ_OWN,
  4118. )
  4119. ),
  4120. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4121. ):
  4122. """Get the thumbnail image for a specific plate.
  4123. Requires a media token query param (?token=xxx) when auth is enabled, and
  4124. returns 404 for an archive the caller may not read (#3025).
  4125. """
  4126. user, can_read_all = auth_result
  4127. service = ArchiveService(db)
  4128. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  4129. file_path = settings.base_dir / archive.file_path
  4130. if not file_path.is_file():
  4131. raise HTTPException(404, "Archive file not found")
  4132. try:
  4133. with zipfile.ZipFile(file_path, "r") as zf:
  4134. thumb_path = f"Metadata/plate_{plate_index}.png"
  4135. if thumb_path in zf.namelist():
  4136. data = zf.read(thumb_path)
  4137. return Response(content=data, media_type="image/png")
  4138. except Exception:
  4139. pass # Fall through to 404 if archive is unreadable or thumbnail missing
  4140. raise HTTPException(404, f"Thumbnail for plate {plate_index} not found")
  4141. async def _try_preview_slice_filaments(
  4142. db: AsyncSession,
  4143. *,
  4144. kind: str,
  4145. source_id: int,
  4146. plate_id: int,
  4147. file_path: Path,
  4148. request_id: str | None = None,
  4149. ) -> list[dict] | None:
  4150. """Run a preview slice via the user's configured sidecar so the filament
  4151. list endpoint can return real per-plate filaments for unsliced project
  4152. files. Returns ``None`` on any failure — the caller falls back to the
  4153. painted-face heuristic. ``request_id`` flows through to the sidecar
  4154. for live progress on the SliceModal's inline spinner + toast.
  4155. """
  4156. from backend.app.api.routes.settings import get_setting
  4157. from backend.app.services.slice_preview import get_preview_filaments
  4158. from backend.app.services.slicer_api import get_stall_timeout_seconds
  4159. preferred = (await get_setting(db, "preferred_slicer")) or "bambu_studio"
  4160. if preferred == "orcaslicer":
  4161. configured = await get_setting(db, "orcaslicer_api_url")
  4162. api_url = (configured or settings.slicer_api_url).strip()
  4163. elif preferred == "bambu_studio":
  4164. configured = await get_setting(db, "bambu_studio_api_url")
  4165. api_url = (configured or settings.bambu_studio_api_url).strip()
  4166. else:
  4167. return None
  4168. if not api_url:
  4169. return None
  4170. try:
  4171. file_bytes = file_path.read_bytes()
  4172. except OSError:
  4173. return None
  4174. return await get_preview_filaments(
  4175. kind=kind,
  4176. source_id=source_id,
  4177. plate_id=plate_id,
  4178. file_bytes=file_bytes,
  4179. file_name=file_path.name,
  4180. api_url=api_url,
  4181. request_id=request_id,
  4182. timeout_seconds=await get_stall_timeout_seconds(db),
  4183. )
  4184. @router.get("/{archive_id}/filament-requirements")
  4185. async def get_filament_requirements(
  4186. archive_id: int,
  4187. plate_id: int | None = None,
  4188. request_id: str | None = None,
  4189. full_slots: bool = False,
  4190. db: AsyncSession = Depends(get_db),
  4191. auth_result: tuple[User | None, bool] = Depends(
  4192. require_ownership_permission(
  4193. Permission.ARCHIVES_READ_ALL,
  4194. Permission.ARCHIVES_READ_OWN,
  4195. )
  4196. ),
  4197. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4198. ):
  4199. """Get filament requirements from the archived 3MF file.
  4200. Returns the filaments used in this print with their slot IDs, types, colors,
  4201. and usage amounts. This can be compared with current AMS state before reprinting.
  4202. Args:
  4203. archive_id: The archive ID
  4204. plate_id: Optional plate index to filter filaments for (for multi-plate files)
  4205. """
  4206. import defusedxml.ElementTree as ET
  4207. user, can_read_all = auth_result
  4208. service = ArchiveService(db)
  4209. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  4210. file_path = settings.base_dir / archive.file_path
  4211. if not file_path.is_file():
  4212. raise HTTPException(404, "Archive file not found")
  4213. filaments = []
  4214. try:
  4215. with zipfile.ZipFile(file_path, "r") as zf:
  4216. # Parse slice_info.config for filament requirements
  4217. if "Metadata/slice_info.config" in zf.namelist():
  4218. content = zf.read("Metadata/slice_info.config").decode()
  4219. root = ET.fromstring(content)
  4220. # If plate_id is specified, find filaments for that specific plate
  4221. if plate_id is not None:
  4222. # Find the plate element with matching index
  4223. for plate_elem in root.findall(".//plate"):
  4224. plate_index = None
  4225. for meta in plate_elem.findall("metadata"):
  4226. if meta.get("key") == "index":
  4227. try:
  4228. plate_index = int(meta.get("value", "0"))
  4229. except ValueError:
  4230. pass # Skip plate with non-numeric index metadata
  4231. break
  4232. if plate_index == plate_id:
  4233. # Extract filaments from this plate element
  4234. for filament_elem in plate_elem.findall("filament"):
  4235. filament_id = filament_elem.get("id")
  4236. filament_type = filament_elem.get("type", "")
  4237. filament_color = filament_elem.get("color", "")
  4238. used_g = filament_elem.get("used_g", "0")
  4239. used_m = filament_elem.get("used_m", "0")
  4240. tray_info_idx = filament_elem.get("tray_info_idx", "")
  4241. try:
  4242. used_grams = float(used_g)
  4243. except (ValueError, TypeError):
  4244. used_grams = 0
  4245. if used_grams > 0 and filament_id:
  4246. filaments.append(
  4247. {
  4248. "slot_id": int(filament_id),
  4249. "type": filament_type,
  4250. "color": filament_color,
  4251. "used_grams": round(used_grams, 1),
  4252. "used_meters": float(used_m) if used_m else 0,
  4253. "tray_info_idx": tray_info_idx,
  4254. "used_in_plate": True,
  4255. }
  4256. )
  4257. break
  4258. else:
  4259. # No plate_id specified - extract all filaments with used_g > 0
  4260. # This is the legacy behavior for single-plate files
  4261. for filament_elem in root.findall(".//filament"):
  4262. filament_id = filament_elem.get("id")
  4263. filament_type = filament_elem.get("type", "")
  4264. filament_color = filament_elem.get("color", "")
  4265. used_g = filament_elem.get("used_g", "0")
  4266. used_m = filament_elem.get("used_m", "0")
  4267. tray_info_idx = filament_elem.get("tray_info_idx", "")
  4268. # Only include filaments that are actually used
  4269. try:
  4270. used_grams = float(used_g)
  4271. except (ValueError, TypeError):
  4272. used_grams = 0
  4273. if used_grams > 0 and filament_id:
  4274. filaments.append(
  4275. {
  4276. "slot_id": int(filament_id),
  4277. "type": filament_type,
  4278. "color": filament_color,
  4279. "used_grams": round(used_grams, 1),
  4280. "used_meters": float(used_m) if used_m else 0,
  4281. "tray_info_idx": tray_info_idx,
  4282. "used_in_plate": True,
  4283. }
  4284. )
  4285. # Re-slicing a source that already carries slice_info (#2712).
  4286. # See library.py for the full rationale: the slice modal's list is
  4287. # positional, so a source using only slot 4 must still present
  4288. # four slots or the pick lands on slot 1. The print path keeps the
  4289. # used-only list it depends on.
  4290. if full_slots and filaments:
  4291. filaments = expand_to_project_slots(zf, filaments)
  4292. # Unsliced project files: see library.py for full rationale.
  4293. # Return the FULL project_settings.config slot list with a
  4294. # used_in_plate flag derived from the preview slice; the
  4295. # CLI needs every slot pre-filled to avoid silent default
  4296. # substitution.
  4297. if not filaments:
  4298. project_filaments = extract_project_filaments_from_3mf(zf)
  4299. used_slot_ids: set[int] = set()
  4300. if project_filaments and plate_id is not None:
  4301. preview = await _try_preview_slice_filaments(
  4302. db,
  4303. kind="archive",
  4304. source_id=archive_id,
  4305. plate_id=plate_id,
  4306. file_path=file_path,
  4307. request_id=request_id,
  4308. )
  4309. if preview is not None:
  4310. used_slot_ids = {f["slot_id"] for f in preview}
  4311. fallback_all_used = not used_slot_ids
  4312. for f in project_filaments:
  4313. f["used_in_plate"] = fallback_all_used or f["slot_id"] in used_slot_ids
  4314. filaments = project_filaments
  4315. # Sort by slot ID
  4316. filaments.sort(key=lambda x: x["slot_id"])
  4317. # Enrich with nozzle mapping for dual-nozzle printers
  4318. nozzle_mapping = extract_nozzle_mapping_from_3mf(zf)
  4319. if nozzle_mapping:
  4320. for filament in filaments:
  4321. filament["nozzle_id"] = nozzle_mapping.get(filament["slot_id"])
  4322. # Nozzle-rack machines (#1784): the print dialog offers a rack
  4323. # position per filament group, which needs the group table as well
  4324. # as the carriage above.
  4325. annotate_rack_groups(filaments, file_path, plate_id)
  4326. except Exception as e:
  4327. logger.warning("Failed to parse filament requirements from archive %s: %s", archive_id, e)
  4328. return {
  4329. "archive_id": archive_id,
  4330. "filename": archive.filename,
  4331. "plate_id": plate_id,
  4332. "filaments": filaments,
  4333. }
  4334. @router.post("/{archive_id}/slice", status_code=202)
  4335. async def slice_archive(
  4336. archive_id: int,
  4337. request: SliceRequest,
  4338. db: AsyncSession = Depends(get_db),
  4339. current_user: User | None = RequirePermissionIfAuthEnabled(Permission.LIBRARY_UPLOAD),
  4340. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4341. actor: User | ApiKeyActor | None = RequestActor,
  4342. ):
  4343. """Enqueue a slice job for an archive's source. Returns 202 + job_id;
  4344. the slice runs in the background, the caller polls `GET /slice-jobs/{id}`.
  4345. Source preference: ``source_3mf_path`` (the un-sliced project file the
  4346. user originally sent to slice) → ``file_path`` (the sliced 3MF/gcode that
  4347. actually printed).
  4348. """
  4349. from backend.app.api.routes.library import guard_nozzle_class_reslice, slice_and_persist_as_archive
  4350. from backend.app.core.database import async_session
  4351. from backend.app.services.slice_dispatch import (
  4352. http_exception_to_job_error,
  4353. slice_dispatch,
  4354. )
  4355. archive = await db.get(PrintArchive, archive_id)
  4356. # Per-row ownership gate — mirror the archive read routes. LIBRARY_UPLOAD
  4357. # alone let a READ_OWN caller slice another user's archive by raw id even
  4358. # though GET on that id returned 404. An API key is checked as its owner
  4359. # (RequestActor); only auth off keeps can_read_all=True.
  4360. can_read_all = actor is None or actor.has_permission(Permission.ARCHIVES_READ_ALL.value)
  4361. archive = _ensure_archive_visible(archive, actor, can_read_all, printer_scope)
  4362. src_relative = archive.source_3mf_path or archive.file_path
  4363. if not src_relative:
  4364. raise HTTPException(
  4365. status_code=400,
  4366. detail="Archive has no source file to slice",
  4367. )
  4368. src_path = (
  4369. Path(settings.base_dir) / src_relative
  4370. ) # SEC-PATH-OK: src_relative is archive.source_3mf_path from DB, set by _resolve_source_3mf_path which already does resolve+relative_to containment
  4371. if not src_path.exists():
  4372. raise HTTPException(status_code=404, detail="Archive source file missing on disk")
  4373. raw_filename = archive.filename or src_path.name
  4374. src_lower = raw_filename.lower()
  4375. if not (
  4376. src_lower.endswith(".stl")
  4377. or src_lower.endswith(".3mf")
  4378. or src_lower.endswith(".step")
  4379. or src_lower.endswith(".stp")
  4380. ):
  4381. raise HTTPException(
  4382. status_code=400,
  4383. detail="Archive's source file must be STL, 3MF, or STEP to slice",
  4384. )
  4385. # Match the library route: derive the sliced output's filename from
  4386. # `print_name` when set, so the new archive row's display name lines
  4387. # up with the source's display.
  4388. src_ext = Path(raw_filename).suffix.lower() or ".3mf"
  4389. src_filename = (
  4390. f"{archive.print_name.strip()}{src_ext}" if archive.print_name and archive.print_name.strip() else raw_filename
  4391. )
  4392. model_bytes = src_path.read_bytes()
  4393. archive_id_local = archive.id
  4394. user_id = current_user.id if current_user else None
  4395. # Block a cross-nozzle-class re-slice (single-nozzle <-> H2D) up front —
  4396. # BambuStudio's multi-extruder validator would otherwise reject it with a
  4397. # cryptic error. No-op for same-class or un-sliced sources.
  4398. await guard_nozzle_class_reslice(db, current_user, request, archive.sliced_for_model)
  4399. async def _run(job_id: int):
  4400. async with async_session() as task_db:
  4401. # Re-fetch the source archive on the background-task session.
  4402. src_archive = await task_db.get(PrintArchive, archive_id_local)
  4403. if src_archive is None:
  4404. raise http_exception_to_job_error(
  4405. HTTPException(status_code=404, detail="Archive disappeared during slice")
  4406. )
  4407. try:
  4408. response = await slice_and_persist_as_archive(
  4409. task_db,
  4410. model_bytes=model_bytes,
  4411. model_filename=src_filename,
  4412. request=request,
  4413. source_archive=src_archive,
  4414. current_user_id=user_id,
  4415. job_id=job_id,
  4416. )
  4417. except HTTPException as exc:
  4418. raise http_exception_to_job_error(exc) from exc
  4419. return response.model_dump()
  4420. job = await slice_dispatch.enqueue(
  4421. kind="archive",
  4422. source_id=archive.id,
  4423. source_name=archive.print_name or archive.filename or f"archive {archive.id}",
  4424. owner_id=user_id,
  4425. run=_run,
  4426. )
  4427. return {
  4428. "job_id": job.id,
  4429. "status": job.status,
  4430. "status_url": f"/api/v1/slice-jobs/{job.id}",
  4431. }
  4432. @router.post("/{archive_id}/reprint")
  4433. async def reprint_archive(
  4434. archive_id: int,
  4435. printer_id: int,
  4436. # SECURITY.md SEC-AUTH-1: every route either has an explicit auth dep or
  4437. # is in the route-auth-coverage allowlist. Gating the deprecation stub on
  4438. # QUEUE_CREATE matches the replacement route (POST /queue/) and means
  4439. # anonymous callers bounce at auth instead of seeing the deprecation
  4440. # message — leaking "this route exists" to unauthenticated callers is
  4441. # exactly the shape the backstop guards against.
  4442. _: User | None = RequirePermissionIfAuthEnabled(Permission.QUEUE_CREATE),
  4443. ):
  4444. """Legacy direct reprint endpoint. Use POST /queue/ instead."""
  4445. logger.warning(
  4446. "Gone API used: POST /archives/%s/reprint?printer_id=%s; use POST /queue/ instead",
  4447. archive_id,
  4448. printer_id,
  4449. )
  4450. raise HTTPException(
  4451. status_code=410,
  4452. detail="Direct archive reprint has been removed. Create a print queue item with POST /queue/.",
  4453. )
  4454. # =============================================================================
  4455. # Project Page API
  4456. # =============================================================================
  4457. @router.get("/{archive_id}/project-page")
  4458. async def get_project_page(
  4459. archive_id: int,
  4460. db: AsyncSession = Depends(get_db),
  4461. auth_result: tuple[User | None, bool] = Depends(
  4462. require_ownership_permission(
  4463. Permission.ARCHIVES_READ_ALL,
  4464. Permission.ARCHIVES_READ_OWN,
  4465. )
  4466. ),
  4467. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4468. ):
  4469. """Get the project page data from the 3MF file."""
  4470. from backend.app.schemas.archive import ProjectPageResponse
  4471. from backend.app.services.archive import ProjectPageParser
  4472. user, can_read_all = auth_result
  4473. service = ArchiveService(db)
  4474. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  4475. file_path = settings.base_dir / archive.file_path
  4476. if not file_path.is_file():
  4477. raise HTTPException(404, "Archive file not found")
  4478. parser = ProjectPageParser(file_path)
  4479. data = parser.parse(archive_id)
  4480. return ProjectPageResponse(**data)
  4481. @router.patch("/{archive_id}/project-page")
  4482. async def update_project_page(
  4483. archive_id: int,
  4484. update_data: dict,
  4485. db: AsyncSession = Depends(get_db),
  4486. auth_result: tuple[User | None, bool] = Depends(
  4487. require_ownership_permission(
  4488. Permission.ARCHIVES_UPDATE_ALL,
  4489. Permission.ARCHIVES_UPDATE_OWN,
  4490. )
  4491. ),
  4492. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4493. ):
  4494. """Update project page metadata in the 3MF file."""
  4495. from backend.app.services.archive import ProjectPageParser
  4496. user, can_modify_all = auth_result
  4497. service = ArchiveService(db)
  4498. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_modify_all, printer_scope)
  4499. file_path = settings.base_dir / archive.file_path
  4500. if not file_path.is_file():
  4501. raise HTTPException(404, "Archive file not found")
  4502. parser = ProjectPageParser(file_path)
  4503. success = parser.update_metadata(update_data)
  4504. if not success:
  4505. raise HTTPException(500, "Failed to update project page")
  4506. # Return updated data
  4507. data = parser.parse(archive_id)
  4508. return data
  4509. @router.get("/{archive_id}/project-image/{image_path:path}")
  4510. async def get_project_image(
  4511. archive_id: int,
  4512. image_path: str,
  4513. db: AsyncSession = Depends(get_db),
  4514. auth_result: tuple[User | None, bool] = Depends(
  4515. require_media_token_ownership(
  4516. Permission.ARCHIVES_READ_ALL,
  4517. Permission.ARCHIVES_READ_OWN,
  4518. )
  4519. ),
  4520. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4521. ):
  4522. """Get an image from the 3MF project page.
  4523. Requires a media token query param (?token=xxx) when auth is enabled, and
  4524. returns 404 for an archive the caller may not read (#3025).
  4525. """
  4526. user, can_read_all = auth_result
  4527. from backend.app.services.archive import ProjectPageParser
  4528. service = ArchiveService(db)
  4529. archive = _ensure_archive_visible(await service.get_archive(archive_id), user, can_read_all, printer_scope)
  4530. file_path = settings.base_dir / archive.file_path
  4531. if not file_path.is_file():
  4532. raise HTTPException(404, "Archive file not found")
  4533. parser = ProjectPageParser(file_path)
  4534. result = parser.get_image(image_path)
  4535. if not result:
  4536. raise HTTPException(404, "Image not found in 3MF file")
  4537. image_data, content_type = result
  4538. return Response(
  4539. content=image_data,
  4540. media_type=content_type,
  4541. headers={"Cache-Control": "max-age=3600"},
  4542. )
  4543. # =============================================================================
  4544. # Source 3MF API (Original Project Files)
  4545. # =============================================================================
  4546. def _resolve_source_3mf_path(archive: PrintArchive, source_filename: str) -> Path:
  4547. """Resolve where to write a source 3MF for ``archive``.
  4548. Normal archives nest the source under ``<archive_file_dir>/source/``.
  4549. "Fallback" archives (created in main.py when MQTT reports a print start
  4550. but Bambuddy never saw the source 3MF — cloud / Handy / pre-existing
  4551. SD-card prints) carry ``file_path=""``. Joining that with ``base_dir``
  4552. via the ``/`` operator silently yields ``base_dir`` itself, whose parent
  4553. is ``base_dir.parent`` — which sent the upload to ``/app/source/`` and
  4554. raised a 500 on the final ``relative_to`` (#1531). Fallback archives
  4555. now land under ``<base_dir>/archive/no_source/<archive_id>/`` instead,
  4556. which stays inside the data volume and remains addressable by every
  4557. read site that does ``base_dir / archive.source_3mf_path``.
  4558. The resolved directory is asserted to be inside ``base_dir`` even when
  4559. ``archive.file_path`` is populated, so a row corrupted by an old import
  4560. or manual SQL edit fails with a clear 500 instead of writing outside
  4561. the data volume.
  4562. """
  4563. if archive.file_path:
  4564. archive_file = settings.base_dir / archive.file_path
  4565. source_dir = archive_file.parent / "source"
  4566. else:
  4567. source_dir = settings.base_dir / "archive" / "no_source" / str(archive.id)
  4568. # Containment check via resolve() — catches absolute file_path, `..`
  4569. # traversal, and any other shape that escapes the data volume — but we
  4570. # return the *literal* source_dir below. Resolving the returned path
  4571. # would canonicalise away a symlinked DATA_DIR (legitimate on TrueNAS /
  4572. # QNAP / Synology storage pools, and any `-v /symlink:/app/data`
  4573. # mount), which would then make the caller's
  4574. # ``source_path.relative_to(settings.base_dir)`` raise because the
  4575. # left side is canonical and the right is the symlink path.
  4576. try:
  4577. source_dir.resolve().relative_to(settings.base_dir.resolve())
  4578. except ValueError as exc:
  4579. raise HTTPException(
  4580. 500,
  4581. f"Archive {archive.id} resolves to a path outside the data directory; cannot attach source.",
  4582. ) from exc
  4583. source_dir.mkdir(parents=True, exist_ok=True)
  4584. return (
  4585. source_dir / source_filename
  4586. ) # SEC-PATH-OK: callers pass _safe_filename(...) basename-stripped; source_dir resolve+relative_to checked above
  4587. @router.post("/{archive_id}/source")
  4588. async def upload_source_3mf(
  4589. archive_id: int,
  4590. file: UploadFile = File(...),
  4591. db: AsyncSession = Depends(get_db),
  4592. auth_result: tuple[User | None, bool] = Depends(
  4593. require_ownership_permission(
  4594. Permission.ARCHIVES_UPDATE_ALL,
  4595. Permission.ARCHIVES_UPDATE_OWN,
  4596. )
  4597. ),
  4598. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4599. ):
  4600. """Upload the original source 3MF project file for an archive."""
  4601. user, can_modify_all = auth_result
  4602. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4603. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  4604. if not file.filename or not file.filename.endswith(".3mf"):
  4605. raise HTTPException(400, "File must be a .3mf file")
  4606. # Save the source 3MF file - preserve original filename, strip directory components
  4607. source_filename = _safe_filename(file.filename)
  4608. source_path = _resolve_source_3mf_path(archive, source_filename)
  4609. # Delete old source file if exists
  4610. if archive.source_3mf_path:
  4611. old_source_path = settings.base_dir / archive.source_3mf_path
  4612. if old_source_path.exists():
  4613. old_source_path.unlink()
  4614. content = await file.read()
  4615. # #1401: validate zip header on source 3MF uploads too — source files
  4616. # are uploaded for reprint and slicing, so an invalid one breaks the
  4617. # same downstream paths as a bad sliced file.
  4618. from backend.app.api.routes.library import validate_print_file_upload
  4619. validate_print_file_upload(file.filename, content)
  4620. source_path.write_bytes(content)
  4621. # Update archive with source path (relative to base_dir)
  4622. archive.source_3mf_path = str(source_path.relative_to(settings.base_dir))
  4623. await db.commit()
  4624. await db.refresh(archive)
  4625. return {
  4626. "status": "uploaded",
  4627. "source_3mf_path": archive.source_3mf_path,
  4628. "filename": source_filename,
  4629. }
  4630. @router.get("/{archive_id}/source")
  4631. async def download_source_3mf(
  4632. archive_id: int,
  4633. db: AsyncSession = Depends(get_db),
  4634. auth_result: tuple[User | None, bool] = Depends(
  4635. require_ownership_permission(
  4636. Permission.ARCHIVES_READ_ALL,
  4637. Permission.ARCHIVES_READ_OWN,
  4638. )
  4639. ),
  4640. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4641. ):
  4642. """Download the source 3MF project file."""
  4643. user, can_read_all = auth_result
  4644. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4645. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  4646. if not archive.source_3mf_path:
  4647. raise HTTPException(404, "No source 3MF attached to this archive")
  4648. source_path = settings.base_dir / archive.source_3mf_path
  4649. if not source_path.exists():
  4650. raise HTTPException(404, "Source 3MF file not found on disk")
  4651. # Use the actual filename from the path
  4652. filename = source_path.name
  4653. return FileResponse(
  4654. path=source_path,
  4655. filename=filename,
  4656. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  4657. )
  4658. @router.get("/{archive_id}/source/{filename}")
  4659. async def download_source_3mf_for_slicer(
  4660. archive_id: int,
  4661. filename: str,
  4662. db: AsyncSession = Depends(get_db),
  4663. auth_result: tuple[User | None, bool] = Depends(
  4664. require_ownership_permission(
  4665. Permission.ARCHIVES_READ_ALL,
  4666. Permission.ARCHIVES_READ_OWN,
  4667. )
  4668. ),
  4669. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4670. ):
  4671. """Download source 3MF with filename in URL."""
  4672. user, can_read_all = auth_result
  4673. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4674. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  4675. if not archive.source_3mf_path:
  4676. raise HTTPException(404, "No source 3MF attached to this archive")
  4677. source_path = settings.base_dir / archive.source_3mf_path
  4678. if not source_path.exists():
  4679. raise HTTPException(404, "Source 3MF file not found on disk")
  4680. return FileResponse(
  4681. path=source_path,
  4682. filename=filename if filename.endswith(".3mf") else f"{filename}.3mf",
  4683. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  4684. )
  4685. @router.post("/{archive_id}/source-slicer-token")
  4686. async def create_source_slicer_token(
  4687. archive_id: int,
  4688. db: AsyncSession = Depends(get_db),
  4689. auth_result: tuple[User | None, bool] = Depends(
  4690. require_ownership_permission(
  4691. Permission.ARCHIVES_READ_ALL,
  4692. Permission.ARCHIVES_READ_OWN,
  4693. )
  4694. ),
  4695. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4696. ):
  4697. """Create a short-lived download token for opening source 3MF in slicer."""
  4698. from backend.app.core.auth import create_slicer_download_token
  4699. user, can_read_all = auth_result
  4700. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4701. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  4702. if not archive.source_3mf_path:
  4703. raise HTTPException(404, "No source 3MF attached to this archive")
  4704. token = await create_slicer_download_token("source", archive_id)
  4705. return {"token": token}
  4706. @router.get("/{archive_id}/source-dl/{token}/{filename}")
  4707. async def download_source_3mf_for_slicer_with_token(
  4708. archive_id: int,
  4709. token: str,
  4710. filename: str,
  4711. db: AsyncSession = Depends(get_db),
  4712. ):
  4713. """Download source 3MF using a slicer download token.
  4714. Token-authenticated (no auth headers needed). The token is short-lived and
  4715. archive-bound, created by POST /{archive_id}/source-slicer-token, and
  4716. redeemable for the rest of its TTL rather than exactly once (#3029).
  4717. """
  4718. from backend.app.core.auth import verify_slicer_download_token
  4719. if not await verify_slicer_download_token(token, "source", archive_id, single_use=False):
  4720. raise HTTPException(403, "Invalid or expired download token")
  4721. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4722. archive = result.scalar_one_or_none()
  4723. if not archive:
  4724. raise HTTPException(404, "Archive not found")
  4725. if not archive.source_3mf_path:
  4726. raise HTTPException(404, "No source 3MF attached to this archive")
  4727. source_path = settings.base_dir / archive.source_3mf_path
  4728. if not source_path.exists():
  4729. raise HTTPException(404, "Source 3MF file not found on disk")
  4730. return FileResponse(
  4731. path=source_path,
  4732. filename=filename if filename.endswith(".3mf") else f"{filename}.3mf",
  4733. media_type="application/vnd.ms-package.3dmanufacturing-3dmodel+xml",
  4734. )
  4735. @router.post("/upload-source")
  4736. async def upload_source_3mf_by_name(
  4737. file: UploadFile = File(...),
  4738. print_name: str = Query(None, description="Match archive by print name"),
  4739. db: AsyncSession = Depends(get_db),
  4740. _: User | None = RequirePermissionIfAuthEnabled(Permission.ARCHIVES_UPDATE_ALL),
  4741. ):
  4742. """Upload source 3MF and match to archive by print name.
  4743. This endpoint is designed for slicer post-processing scripts.
  4744. It finds the most recent archive matching the print name and attaches the source.
  4745. """
  4746. if not file.filename or not file.filename.endswith(".3mf"):
  4747. raise HTTPException(400, "File must be a .3mf file")
  4748. safe_filename = _safe_filename(file.filename)
  4749. # Derive print name from filename if not provided
  4750. if not print_name:
  4751. # Remove .3mf extension and common suffixes
  4752. print_name = safe_filename.rsplit(".3mf", 1)[0]
  4753. # Remove _source suffix if present
  4754. if print_name.endswith("_source"):
  4755. print_name = print_name[:-7]
  4756. # Find matching archive - try exact match first, then fuzzy
  4757. result = await db.execute(
  4758. select(PrintArchive)
  4759. .where(PrintArchive.print_name == print_name)
  4760. .order_by(PrintArchive.created_at.desc())
  4761. .limit(1)
  4762. )
  4763. archive = result.scalar_one_or_none()
  4764. if not archive:
  4765. # Try matching filename without .gcode.3mf
  4766. result = await db.execute(
  4767. select(PrintArchive)
  4768. .where(PrintArchive.filename.like(f"{print_name}%"))
  4769. .order_by(PrintArchive.created_at.desc())
  4770. .limit(1)
  4771. )
  4772. archive = result.scalar_one_or_none()
  4773. if not archive:
  4774. # Try case-insensitive partial match on print_name
  4775. result = await db.execute(
  4776. select(PrintArchive)
  4777. .where(PrintArchive.print_name.ilike(f"%{print_name}%"))
  4778. .order_by(PrintArchive.created_at.desc())
  4779. .limit(1)
  4780. )
  4781. archive = result.scalar_one_or_none()
  4782. if not archive:
  4783. raise HTTPException(404, f"No archive found matching '{print_name}'")
  4784. # Save the source 3MF file - preserve original filename, strip directory components
  4785. source_filename = safe_filename
  4786. source_path = _resolve_source_3mf_path(archive, source_filename)
  4787. # Delete old source file if exists
  4788. if archive.source_3mf_path:
  4789. old_source_path = settings.base_dir / archive.source_3mf_path
  4790. if old_source_path.exists():
  4791. old_source_path.unlink()
  4792. content = await file.read()
  4793. # #1401: same zip-header check as the other upload routes — the
  4794. # match-by-name endpoint is used by slicer post-processing scripts,
  4795. # so a misconfigured script is exactly how a bad 3MF would slip in.
  4796. from backend.app.api.routes.library import validate_print_file_upload
  4797. validate_print_file_upload(file.filename, content)
  4798. source_path.write_bytes(content)
  4799. # Update archive with source path
  4800. archive.source_3mf_path = str(source_path.relative_to(settings.base_dir))
  4801. await db.commit()
  4802. await db.refresh(archive)
  4803. return {
  4804. "status": "uploaded",
  4805. "archive_id": archive.id,
  4806. "archive_name": archive.print_name or archive.filename,
  4807. "source_3mf_path": archive.source_3mf_path,
  4808. "filename": source_filename,
  4809. }
  4810. @router.delete("/{archive_id}/source")
  4811. async def delete_source_3mf(
  4812. archive_id: int,
  4813. db: AsyncSession = Depends(get_db),
  4814. auth_result: tuple[User | None, bool] = Depends(
  4815. require_ownership_permission(
  4816. Permission.ARCHIVES_DELETE_ALL,
  4817. Permission.ARCHIVES_DELETE_OWN,
  4818. )
  4819. ),
  4820. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4821. ):
  4822. """Delete the source 3MF project file from an archive."""
  4823. user, can_modify_all = auth_result
  4824. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4825. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  4826. if not archive.source_3mf_path:
  4827. raise HTTPException(404, "No source 3MF attached to this archive")
  4828. # Delete the file
  4829. source_path = settings.base_dir / archive.source_3mf_path
  4830. if source_path.exists():
  4831. source_path.unlink()
  4832. # Clear the path in database
  4833. archive.source_3mf_path = None
  4834. await db.commit()
  4835. return {"status": "deleted"}
  4836. # =============================================================================
  4837. # F3D API (Fusion 360 Design Files)
  4838. # =============================================================================
  4839. @router.post("/{archive_id}/f3d")
  4840. async def upload_f3d(
  4841. archive_id: int,
  4842. file: UploadFile = File(...),
  4843. db: AsyncSession = Depends(get_db),
  4844. auth_result: tuple[User | None, bool] = Depends(
  4845. require_ownership_permission(
  4846. Permission.ARCHIVES_UPDATE_ALL,
  4847. Permission.ARCHIVES_UPDATE_OWN,
  4848. )
  4849. ),
  4850. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4851. ):
  4852. """Upload a Fusion 360 design file for an archive."""
  4853. user, can_modify_all = auth_result
  4854. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4855. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  4856. if not file.filename or not file.filename.endswith(".f3d"):
  4857. raise HTTPException(400, "File must be a .f3d file")
  4858. # Get archive directory and create f3d subdirectory
  4859. file_path = settings.base_dir / archive.file_path
  4860. archive_dir = file_path.parent
  4861. f3d_dir = archive_dir / "f3d"
  4862. f3d_dir.mkdir(exist_ok=True)
  4863. # Delete old F3D file if exists
  4864. if archive.f3d_path:
  4865. old_f3d_path = settings.base_dir / archive.f3d_path
  4866. if old_f3d_path.exists():
  4867. old_f3d_path.unlink()
  4868. # Save the F3D file - preserve original filename, strip directory components
  4869. f3d_filename = _safe_filename(file.filename)
  4870. f3d_path = f3d_dir / f3d_filename # SEC-PATH-OK: f3d_filename = _safe_filename(...) basename-stripped above
  4871. content = await file.read()
  4872. f3d_path.write_bytes(content)
  4873. # Update archive with F3D path (relative to base_dir)
  4874. archive.f3d_path = str(f3d_path.relative_to(settings.base_dir))
  4875. await db.commit()
  4876. await db.refresh(archive)
  4877. return {
  4878. "status": "uploaded",
  4879. "f3d_path": archive.f3d_path,
  4880. "filename": f3d_filename,
  4881. }
  4882. @router.get("/{archive_id}/f3d")
  4883. async def download_f3d(
  4884. archive_id: int,
  4885. db: AsyncSession = Depends(get_db),
  4886. auth_result: tuple[User | None, bool] = Depends(
  4887. require_ownership_permission(
  4888. Permission.ARCHIVES_READ_ALL,
  4889. Permission.ARCHIVES_READ_OWN,
  4890. )
  4891. ),
  4892. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4893. ):
  4894. """Download the Fusion 360 design file."""
  4895. user, can_read_all = auth_result
  4896. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4897. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_read_all, printer_scope)
  4898. if not archive.f3d_path:
  4899. raise HTTPException(404, "No F3D file attached to this archive")
  4900. f3d_path = settings.base_dir / archive.f3d_path
  4901. if not f3d_path.exists():
  4902. raise HTTPException(404, "F3D file not found on disk")
  4903. # Use the actual filename from the path
  4904. filename = f3d_path.name
  4905. return FileResponse(
  4906. path=f3d_path,
  4907. filename=filename,
  4908. media_type="application/octet-stream",
  4909. )
  4910. @router.delete("/{archive_id}/f3d")
  4911. async def delete_f3d(
  4912. archive_id: int,
  4913. db: AsyncSession = Depends(get_db),
  4914. auth_result: tuple[User | None, bool] = Depends(
  4915. require_ownership_permission(
  4916. Permission.ARCHIVES_DELETE_ALL,
  4917. Permission.ARCHIVES_DELETE_OWN,
  4918. )
  4919. ),
  4920. printer_scope: PrinterScope = MediaOrRequestPrinterScope,
  4921. ):
  4922. """Delete the Fusion 360 design file from an archive."""
  4923. user, can_modify_all = auth_result
  4924. result = await db.execute(select(PrintArchive).where(PrintArchive.id == archive_id))
  4925. archive = _ensure_archive_visible(result.scalar_one_or_none(), user, can_modify_all, printer_scope)
  4926. if not archive.f3d_path:
  4927. raise HTTPException(404, "No F3D file attached to this archive")
  4928. # Delete the file
  4929. f3d_path = settings.base_dir / archive.f3d_path
  4930. if f3d_path.exists():
  4931. f3d_path.unlink()
  4932. # Clear the path in database
  4933. archive.f3d_path = None
  4934. await db.commit()
  4935. return {"status": "deleted"}