Session - COOKIE_SECURE=false no longer persists the owner key for ten years. services/session.cookie_kwargs() drops max_age in that mode, so the browser holds the key in memory and the session ends with the window. Everything still persists server-side; only the browser link is temporary. base.html shows a warning banner (FR/EN) and an extra paragraph in the onboarding modal, and the README explains the trade-off and the backup-key escape hatch. - Both cookie writers (middleware, POST /session/restore) go through cookie_kwargs() so the policy cannot drift between them. - The CSRF guard on /session/restore compared request.url.scheme against the Origin header. Behind a TLS-terminating proxy uvicorn sees http while the browser sends https, so every legitimate restore was rejected with 403. It now compares hosts only, including X-Forwarded-Host. - /static/*, /favicon.ico and /robots.txt skip the middleware. Each cookieless hit was inserting an Owner row no browser could ever use. Reliability - Malformed printer-form FK fields no longer escape as HTTP 500: a non-numeric client_id/driver_id raised ValueError and an unknown driver_id hit a FOREIGN KEY constraint. Both are now 400/404 HTMX fragments, and the duplicated field checks moved into _validate_fields(). - Package exports stream. build_intunewin() encrypts the inner ZIP in 1 MB chunks against temp files with a streaming HMAC and SHA256, and both endpoints serve the result with FileResponse plus a background cleanup task. A 100 MB driver used to be held in memory three or four times over per concurrent download. The byte layout is unchanged. - FileResponse also escapes the download filename, which was previously interpolated raw into Content-Disposition. - python-multipart >= 0.0.18 (CVE-2024-53981, reachable from /drivers/upload) and Pillow >= 10.3 (CVE-2024-28219, reachable from icon upload). - icons.py reads cfg.ICONS_DIR instead of re-deriving the path from DATA_DIR, matching the .intunewin export. UI - Sidebar/topbar shell, inline SVG icon macros (partials/icons.html), card and data-table components, grouped printer list, and the dedicated /printers/new page replacing partials/printer_form.html. Tests - 194 pass with a bare `pytest tests/`: tests/conftest.py now forces cfg.COOKIE_SECURE = False like the e2e conftest already did, so the Secure cookie is no longer dropped over http://testserver. - New coverage for the malformed-FK guards, the chunk-boundary cases in the encrypt loop (every residue mod _CHUNK plus a multi-megabyte payload), temp-dir cleanup after both exports, and the whole COOKIE_SECURE matrix. - test_printer_edit.py located the Edit button by its translated label, so it only passed on English-locale machines. It now targets the showModal() hook, which also cuts the e2e run from 84s to 15s. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
210 lines
9.4 KiB
HTML
210 lines
9.4 KiB
HTML
{% extends "base.html" %}
|
||
{% import "partials/icons.html" as ico %}
|
||
|
||
{% block head_title %}{{ printer.name }} · ImpTune{% endblock %}
|
||
{% block crumb %}
|
||
<span class="crumb" x-data>
|
||
<a href="/printers">{{ ico.i('back', 12) }}<span x-text="$store.i18n.t('back_to_printer_library')">Printers</span></a>
|
||
{% if printer.client_id %}<span>/</span><a href="/clients/{{ printer.client_id }}">{{ printer.client.name }}</a>{% endif %}
|
||
</span>
|
||
{% endblock %}
|
||
{% block page_title %}{{ printer.name }}{% endblock %}
|
||
|
||
{% block page_actions %}
|
||
{% if has_driver %}
|
||
<span class="badge ok">{{ ico.i('check', 12) }}<span x-text="$store.i18n.t('ready_to_export')">Ready</span></span>
|
||
{% else %}
|
||
<span class="badge warn">{{ ico.i('alert', 12) }}<span x-text="$store.i18n.t('needs_driver')">Driver needed</span></span>
|
||
{% endif %}
|
||
{% endblock %}
|
||
|
||
{% block content %}
|
||
<div class="split">
|
||
<!-- Left: what this printer is -->
|
||
<div>
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('network') }}
|
||
<h2 x-data x-text="$store.i18n.t('configuration')">Configuration</h2>
|
||
</div>
|
||
<div class="card-body">
|
||
<dl class="kv">
|
||
<dt x-data x-text="$store.i18n.t('ip_address')">IP address</dt>
|
||
<dd class="mono-val">{{ printer.ip_address }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('port_name')">Port name</dt>
|
||
<dd class="mono-val">{{ printer.port_name }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('client_label')">Client</dt>
|
||
{% if printer.client_id %}
|
||
<dd><a href="/clients/{{ printer.client_id }}">{{ printer.client.name }}</a></dd>
|
||
{% else %}
|
||
<dd class="faint" x-data x-text="$store.i18n.t('unassigned')">Unassigned</dd>
|
||
{% endif %}
|
||
|
||
<dt x-data x-text="$store.i18n.t('duplex_mode_label')">Duplex mode</dt>
|
||
<dd x-data x-text="$store.i18n.t('{{ 'one_sided' if printer.duplex_mode == 'OneSided' else ('long_edge' if printer.duplex_mode == 'LongEdge' else 'short_edge') }}')">{{ printer.duplex_mode }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('color_mode_label')">Color mode</dt>
|
||
<dd x-data x-text="$store.i18n.t('{{ 'color_value' if printer.color_mode else 'grayscale_value' }}')">{{ 'Color' if printer.color_mode else 'Grayscale' }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('paper_size_label')">Paper size</dt>
|
||
<dd>{{ printer.paper_size }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('collate_label')">Collate</dt>
|
||
<dd x-data x-text="$store.i18n.t('{{ 'yes' if printer.collate else 'no' }}')">{{ 'Yes' if printer.collate else 'No' }}</dd>
|
||
</dl>
|
||
</div>
|
||
</section>
|
||
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('driver') }}
|
||
<h2 x-data x-text="$store.i18n.t('driver_section')">Driver</h2>
|
||
</div>
|
||
<div class="card-body">
|
||
{% if printer.driver_id %}
|
||
<dl class="kv">
|
||
<dt x-data x-text="$store.i18n.t('package_label')">Package</dt>
|
||
<dd class="mono-val">{{ printer.driver.original_filename }}</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('driver_names_label')">Driver name(s)</dt>
|
||
<dd>
|
||
<span class="pill-row">
|
||
{% for name in driver_names %}<span class="pill">{{ name }}</span>{% endfor %}
|
||
</span>
|
||
</dd>
|
||
|
||
<dt x-data x-text="$store.i18n.t('architecture_label')">Architecture</dt>
|
||
<dd>{% if printer.driver.architecture %}<span class="badge">{{ printer.driver.architecture }}</span>{% else %}<span class="faint" x-data x-text="$store.i18n.t('unknown')">Unknown</span>{% endif %}</dd>
|
||
</dl>
|
||
{% else %}
|
||
<div class="empty">
|
||
<span class="empty-ico">{{ ico.i('driver', 18) }}</span>
|
||
<strong>No driver assigned</strong>
|
||
<p x-data x-text="$store.i18n.t('export_locked')">Assign a driver to this printer to unlock scripts and export.</p>
|
||
<a href="/printers" class="btn sm" x-data>{{ ico.i('pencil', 14) }}<span x-text="$store.i18n.t('assign_driver_cta')">Assign a driver</span></a>
|
||
</div>
|
||
{% endif %}
|
||
</div>
|
||
</section>
|
||
|
||
{% if has_driver %}
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('terminal') }}
|
||
<div>
|
||
<h2 x-data x-text="$store.i18n.t('intune_commands')">Intune commands</h2>
|
||
<p class="sub" x-data x-text="$store.i18n.t('hint_intune_cmds')">Paste these into the Win32 app's install and uninstall fields.</p>
|
||
</div>
|
||
</div>
|
||
<div class="card-body field-stack">
|
||
<div x-data="{ copiedInstall: false }">
|
||
<span class="label-text" x-text="$store.i18n.t('install_cmd_label')">Install command</span>
|
||
<div class="cmd">
|
||
<code id="install-cmd">{{ install_cmd }}</code>
|
||
<button type="button" @click="
|
||
navigator.clipboard.writeText(document.getElementById('install-cmd').innerText)
|
||
.then(() => { copiedInstall = true; setTimeout(() => copiedInstall = false, 2000) })
|
||
.catch(() => { /* command stays visible for manual copy */ })
|
||
" x-text="copiedInstall ? $store.i18n.t('copied') : $store.i18n.t('copy')">Copy</button>
|
||
</div>
|
||
</div>
|
||
<div x-data="{ copiedUninstall: false }">
|
||
<span class="label-text" x-text="$store.i18n.t('uninstall_cmd_label')">Uninstall command</span>
|
||
<div class="cmd">
|
||
<code id="uninstall-cmd">{{ uninstall_cmd }}</code>
|
||
<button type="button" @click="
|
||
navigator.clipboard.writeText(document.getElementById('uninstall-cmd').innerText)
|
||
.then(() => { copiedUninstall = true; setTimeout(() => copiedUninstall = false, 2000) })
|
||
.catch(() => { /* command stays visible for manual copy */ })
|
||
" x-text="copiedUninstall ? $store.i18n.t('copied') : $store.i18n.t('copy')">Copy</button>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
</section>
|
||
{% endif %}
|
||
</div>
|
||
|
||
<!-- Right: what you can do with it -->
|
||
<div>
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('package') }}
|
||
<h2 x-data x-text="$store.i18n.t('export_section')">Deploy</h2>
|
||
</div>
|
||
<div class="card-body">
|
||
{% if has_driver %}
|
||
<div class="field-stack">
|
||
<div>
|
||
<a class="btn" href="/printers/{{ printer.id }}/packages/intunewin" x-data>
|
||
{{ ico.i('download', 14) }}<span x-text="$store.i18n.t('download_intunewin')">Download .intunewin</span>
|
||
</a>
|
||
<span class="hint" x-data x-text="$store.i18n.t('hint_intunewin')">.intunewin — upload to Intune as a Win32 app.</span>
|
||
</div>
|
||
<div>
|
||
<a class="btn ghost" href="/printers/{{ printer.id }}/packages/ninja" x-data>
|
||
{{ ico.i('download', 14) }}<span x-text="$store.i18n.t('download_ninja')">Download NinjaRMM ZIP</span>
|
||
</a>
|
||
<span class="hint" x-data x-text="$store.i18n.t('hint_ninja')">ZIP — plain scripts for NinjaRMM or a manual run.</span>
|
||
</div>
|
||
</div>
|
||
{% else %}
|
||
<p class="dim" x-data x-text="$store.i18n.t('export_locked')">Assign a driver to this printer to unlock scripts and export.</p>
|
||
{% endif %}
|
||
</div>
|
||
</section>
|
||
|
||
{% if has_driver %}
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('script') }}
|
||
<h2 x-data x-text="$store.i18n.t('scripts_section')">PowerShell scripts</h2>
|
||
</div>
|
||
<div class="card-body">
|
||
<div class="btn-row">
|
||
<a class="btn ghost sm mono" href="/printers/{{ printer.id }}/scripts/install.ps1">{{ ico.i('download', 13) }}install.ps1</a>
|
||
<a class="btn ghost sm mono" href="/printers/{{ printer.id }}/scripts/uninstall.ps1">{{ ico.i('download', 13) }}uninstall.ps1</a>
|
||
<a class="btn ghost sm mono" href="/printers/{{ printer.id }}/scripts/detect.ps1">{{ ico.i('download', 13) }}detect.ps1</a>
|
||
</div>
|
||
</div>
|
||
</section>
|
||
{% endif %}
|
||
|
||
<section class="card">
|
||
<div class="card-head">
|
||
{{ ico.i('image') }}
|
||
<h2 x-data x-text="$store.i18n.t('icon_section')">Icon</h2>
|
||
</div>
|
||
<div class="card-body">
|
||
<div id="icon-status">
|
||
{% if has_icon %}
|
||
<p class="ok-note">{{ ico.i('check', 14) }}<span x-data x-text="$store.i18n.t('icon_uploaded')">Icon saved</span></p>
|
||
<div class="icon-preview">
|
||
<img src="/printers/{{ printer.id }}/icon" width="56" height="56" alt="">
|
||
<span class="meta">256×256 PNG</span>
|
||
</div>
|
||
{% else %}
|
||
<p class="dim" x-data x-text="$store.i18n.t('no_icon')">No icon. Intune will show its default.</p>
|
||
{% endif %}
|
||
</div>
|
||
<form hx-post="/printers/{{ printer.id }}/icon"
|
||
hx-target="#icon-status" hx-swap="innerHTML"
|
||
hx-encoding="multipart/form-data">
|
||
<div class="uploader">
|
||
<input type="file" name="file" accept="image/png" required
|
||
x-data :aria-label="$store.i18n.t('upload_icon')">
|
||
<div class="btn-row">
|
||
<button type="submit" class="btn ghost sm" x-data>
|
||
{{ ico.i('upload', 13) }}<span x-text="$store.i18n.t('{{ 'replace_icon' if has_icon else 'upload_icon' }}')">Upload icon</span>
|
||
</button>
|
||
</div>
|
||
<p class="hint" x-data x-text="$store.i18n.t('hint_icon')">PNG, exactly 256 × 256, 750 KB max.</p>
|
||
</div>
|
||
</form>
|
||
</div>
|
||
</section>
|
||
</div>
|
||
</div>
|
||
{% endblock %}
|