mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
* fix(web): drop repeats from uniqueItems lists before validating a plugin save dedup_unique_arrays lost its only caller in #330, so submitting a value a uniqueItems list already holds (a stock symbol saved once and posted again) failed the whole save with a validation error. _prepare_plugin_config_for_save runs it again just before validation, which covers both POST /plugins/config and plugin sections posted to /config/main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): /health counts the discovered plugins and logs the checks it fails The plugin check counted plugin_manager.get_available_plugins(), which PluginManager does not have, behind a hasattr guard that made plugin_count 0 on every device. It now counts the discovered manifests, discovering first when nothing has been scanned yet. The config, plugin and hardware checks answered "see logs for details" without logging anything. Each now logs a warning with the traceback. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): store refresh no longer claims a commit-metadata refresh POST /plugins/store/refresh read fetch_commit_info (or fetch_latest_versions) only to append "(with refreshed commit metadata from GitHub)" to its message. It never fetched any: the route re-downloads the registry and nothing else. search_plugins takes the flag, but it reads commit info through its cache, so passing it on would not refresh anything either. The flag is ignored now and the message says what happened. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): refuse a malformed Vegas plugin order instead of clearing it A vegas_plugin_order or vegas_excluded_plugins value that was not JSON, or not a list, was stored as [] and the save answered 200, so a bad value wiped the saved order or exclusions. Both now answer 400 and save nothing, the way plugin_rotation_order already did; the three share one parser. A list that holds anything but plugin-id strings is refused as well. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): per-plugin health and metrics read the display service's latest GET /plugins/health/<id> and /plugins/metrics/<id> called get_health_summary and get_metrics_summary without force_reload, so they answered with whatever the web process read first and kept in memory, while the display service kept writing newer state. They now pass force_reload=True, as the list routes do. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): plugin config reset saves through the shared atomic save POST /plugins/config/reset called config_manager.save_config directly, so it took no backup, and a failed write escaped as an unhandled exception. It then handed on_config_change the raw stored section, not the prepared config a loaded plugin runs with. It now saves through _save_config_atomic with a backup, answers CONFIG_SAVE_FAILED when that fails, and notifies with _prepared_plugin_config, as POST /plugins/config does. POST /plugins/toggle carried its own copy of _save_config_atomic's save_config_atomic-or-save_config fallback; it calls the shared helper now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): one reading and one "unavailable" for each system metric system_metrics.collect_system_metrics() promised None for a metric it could not read, but returned cpu_temp as 0 off a Pi, and the whole no-psutil fallback as zeros. GET /system/status measured the same numbers a second time with its own code, and answered None there. Now both come from collect_system_metrics(), and "unavailable" is None everywhere. /system/status keeps its 0.1s CPU sample and its 10s cache, and gains nothing it did not already send. Two differences: without psutil it answers 200 with null metrics instead of 503, and a disk it cannot stat is null instead of a 500. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): /display/current sends the snapshot as-is and logs a failed read GET /display/current PIL-decoded the preview snapshot and re-encoded it before base64-ing it, spending CPU on the Pi to send the same picture, and dropped any failure with `except Exception: pass`. The /stream/display SSE stream already passed the PNG's bytes straight through. Both now read through web_interface/display_preview.py and answer with the same payload. A missing snapshot is still a null image; any other read failure is logged as a warning. /health reads the snapshot path from the same module. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): one helper puts a submitted plugin config's lists back The plugin-config save turned position-keyed dicts ({"0": ..., "1": ...}) back into lists in five copies: four in the form path's fix_array_structures (whose prefix branches never ran, since no caller passed one), and _fix_json_arrays on the JSON path. It then force-fixed the news plugin's feeds.custom_feeds by name, in case the generic pass had missed it. src/web_interface/config_arrays.coerce_array_shapes now does it for both paths, custom_feeds included. ensure_array_defaults duplicated _fix_none_arrays and is gone. In the same function: the union-type re-checks that the null handling above them made unreachable, the "(temporary)" random_seed debug log, and a commented-out log line are removed. A failed validation is logged once as a warning, not four ERROR lines and a WARNING. Element types are left to normalize_config_values, which already converted them for both paths. One difference: the form path no longer adds an empty {} for a nested object the post left out that has no defaults. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): import at module top and log through the module logger The web_interface.cache imports in config.py and fonts.py were wrapped in `except ImportError` fallbacks. It is an in-repo module that imports nothing from the project, so it cannot fail to import; it is imported once at module top, as system.py now does. cache.py's docstring said blueprints import it lazily "to avoid circular imports"; it now says why that is unnecessary. Five logging.error calls in the dim-schedule GET and three logging.warning calls in plugins.py went to the root logger; they use the module logger. Function-local re-imports of json, os, shutil, logging and Path, all already imported by the module, are gone. The `import os` inside two except blocks of save_plugin_config also made os a local name for the whole function. execute_plugin_action's step-1 handler gets a comment saying why it stays: it looks like a copy of the blueprint handler, but without it a TimeoutExpired from the plugin's script would reach the route's own `except subprocess.TimeoutExpired` and be answered as a 408. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): app.py loses dead CSRF and reconciliation state, comments fixed - csrf was always None, so `if csrf: csrf.exempt(...)` never ran, and its note that the api_v3 blueprint "is exempted above" named an exemption that does not exist. Both are gone; the reason there is no CSRF protection stays, shortened. - The SSE rate-limit comment called the default "tight" at 20 per minute. The default is 1000 per minute and the streams' 200 is the tighter one; the comment now says so. The limits are unchanged. - _reconciliation_done was written and never read. The docstring that explains why reconciliation runs once keeps its reason, in the present tense. - Removed: a dangling "import cache functions" comment with no import under it, a "security check ... within project_root" label on an existence check, the "(simplified version)" narration, and the note that no redirect route is needed. The preview loop's sleep comment no longer mentions a PIL encode that the loop does not do. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(web): api_v3 comments name the package __init__, not a _common module Every route module's docstring said the shared blueprint comes "from ._common", a module the package split never created; they name the package __init__. The PROJECT_ROOT comment described the path from _common.py; it now describes this package and keeps the incident it guards against. The "(corrected) in this commit" note in resolve_pull_command and the /health comment the split's mechanical time -> _pkg.time rewrite garbled ("Stamp the start _pkg.time") read correctly again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): drop hasattr checks for attributes PluginManager always has PluginManager.__init__ sets health_tracker and resource_monitor (to None until they are configured), so the seven hasattr(api_v3.plugin_manager, ...) guards in the health, metrics and limits routes were always true. The falsy checks that do the work stay. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): pages_v3 dispatches partials from a dict with one error handler load_partial chose a loader through a fourteen-branch if/elif, and thirteen of the loaders then wrapped themselves in the same try/except, logging "Error loading partial" without saying which. The route now looks the name up in _PARTIAL_LOADERS and has the one handler, which logs the partial's name. The loaders just render. _load_tools_partial keeps its own messages. The search index's _partial_html already catches a loader that raises. serve_plugin_web_ui repeated _plugin_dir_for inline (containment plus the ledmatrix- prefix fallback); it calls it now. Also removed: the unused markupsafe.escape import, function-local json/Path re-imports, and unused exception bindings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): remove unused imports, locals and a try that cannot fail - get_error_aggregator was imported by the api_v3 package and used by no one; seven names config.py imported, and Path in misc.py and logging in plugins.py, likewise. - branch_info in install_plugin was built and never logged; test_config in /health was bound and never read (the load_config call is the check). - An f-string with no placeholders in the asset upload route. - _installed_plugin_ids wrapped list(manifests.keys()) in try/except; _discovered_plugin_manifests always returns a dict. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): start.py logs its startup lines and drops unreachable branches The startup banner went to stdout with print(); it goes through a logger now, which the app import has already configured, so it reaches the journal with a level and timestamp like every other line. The "no addresses" branch is gone: get_local_ips() always returns at least "localhost". The except around app.run re-raised "only if it's not a client disconnection error" from inside the branch that had just established it was one, so that raise could not run. It is one check now, on a named tuple of the errnos, which the werkzeug log filter uses too. The comment on threaded=True counts three SSE endpoints, which is how many there are. Trailing whitespace is stripped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): save_main_config names its General fields once The General tab's field names were listed twice, once to detect a General form post and again, with four more, to keep the remaining-keys merge from storing them as top-level keys. GENERAL_FIELDS and _MAPPED_TOP_LEVEL_FIELDS hold them now, and the four per-section skip checks are one set. The comment on that merge said plugin configs are handled "here too", and "(including plugin keys)". Plugin sections are handled and removed from the body before it runs; the comment says so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(web): plugin directories come from the plugin manager only Six lookups fell back to PROJECT_ROOT/plugins/<id> when there was no plugin manager: GET /plugins/config's of-the-day data, POST /plugins/action, the plugin static-file route, the calendar credentials upload and the calendar OAuth routes. The loader never scans plugins/ (PluginManager.discover_plugins reads only the configured directory, plugin-repos by default), so what they found there was a plugin that never runs. _plugin_directory() asks the manager and answers None without one, which each route already reports as "not found". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): web-backend Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
444 lines
18 KiB
Python
444 lines
18 KiB
Python
"""Font catalogue, upload, preview and deletion.
|
|
|
|
Routes decorate the shared `api_v3` Blueprint from the package `__init__`,
|
|
so their endpoint names are unchanged by living here.
|
|
"""
|
|
from web_interface.blueprints.api_v3 import (
|
|
PROJECT_ROOT, Path, Response, SYSTEM_FONTS, api_v3,
|
|
jsonify, logger, os, re, request, validate_file_upload,
|
|
)
|
|
from web_interface.cache import delete_cached, get_cached, set_cached
|
|
|
|
|
|
def _catalog_response(catalog):
|
|
"""The catalog response, with each font's ``used_by`` merged in now.
|
|
|
|
Usage comes from the display service (src/font_usage.py) and changes
|
|
independently of the files, so it is read per request and never stored
|
|
in the 5-minute ``fonts_catalog`` cache: entries are copied, not edited.
|
|
``used_by`` is a list of plugin ids, empty when no loaded plugin
|
|
registered the font, and None when the display service has not reported.
|
|
"""
|
|
from src.font_usage import read_font_usage
|
|
from web_interface.blueprints.api_v3.display import _cache_manager
|
|
try:
|
|
usage = read_font_usage(_cache_manager())
|
|
except Exception:
|
|
logger.debug("[FontCatalog] Could not read font usage", exc_info=True)
|
|
usage = None
|
|
|
|
used_by = {}
|
|
if usage is not None:
|
|
# The snapshot keys fonts by file stem, as the catalog does; match
|
|
# case-insensitively too, since FontManager lower-cases families.
|
|
by_lower = {key.lower(): key for key in catalog}
|
|
for key, plugin_ids in usage['fonts'].items():
|
|
row = key if key in catalog else by_lower.get(key.lower())
|
|
if row is not None:
|
|
used_by.setdefault(row, set()).update(plugin_ids)
|
|
|
|
merged = {
|
|
key: dict(info, used_by=(sorted(used_by.get(key, ())) if usage is not None else None))
|
|
for key, info in catalog.items()
|
|
}
|
|
return jsonify({'status': 'success', 'data': {
|
|
'catalog': merged,
|
|
'font_usage': {
|
|
'available': usage is not None,
|
|
'generated_at': usage['generated_at'] if usage is not None else None,
|
|
},
|
|
}})
|
|
|
|
|
|
@api_v3.route('/fonts/catalog', methods=['GET'])
|
|
def get_fonts_catalog():
|
|
"""Get fonts catalog"""
|
|
cached_result = get_cached('fonts_catalog', ttl_seconds=300)
|
|
if cached_result is not None:
|
|
return _catalog_response(cached_result)
|
|
|
|
# Try to import freetype, but continue without it if unavailable
|
|
try:
|
|
import freetype
|
|
freetype_available = True
|
|
except ImportError:
|
|
freetype_available = False
|
|
|
|
# Scan assets/fonts directory for actual font files
|
|
fonts_dir = PROJECT_ROOT / "assets" / "fonts"
|
|
catalog = {}
|
|
|
|
if fonts_dir.exists() and fonts_dir.is_dir():
|
|
for filename in os.listdir(fonts_dir):
|
|
if filename.endswith(('.ttf', '.otf', '.bdf')):
|
|
filepath = fonts_dir / filename
|
|
# Generate family name from filename (without extension)
|
|
family_name = os.path.splitext(filename)[0]
|
|
|
|
# Try to get font metadata using freetype (for TTF/OTF)
|
|
metadata = {}
|
|
if filename.endswith(('.ttf', '.otf')) and freetype_available:
|
|
try:
|
|
face = freetype.Face(str(filepath))
|
|
if face.valid:
|
|
# Get font family name from font file
|
|
family_name_from_font = face.family_name.decode('utf-8') if face.family_name else family_name
|
|
metadata = {
|
|
'family': family_name_from_font,
|
|
'style': face.style_name.decode('utf-8') if face.style_name else 'Regular',
|
|
'num_glyphs': face.num_glyphs,
|
|
'units_per_em': face.units_per_EM
|
|
}
|
|
# Use font's family name if available
|
|
if family_name_from_font:
|
|
family_name = family_name_from_font
|
|
except Exception:
|
|
# If freetype fails, use filename-based name
|
|
pass
|
|
|
|
# Store relative path from project root
|
|
relative_path = str(filepath.relative_to(PROJECT_ROOT))
|
|
font_type = 'ttf' if filename.endswith('.ttf') else 'otf' if filename.endswith('.otf') else 'bdf'
|
|
|
|
# Generate human-readable display name from family_name
|
|
display_name = family_name.replace('-', ' ').replace('_', ' ')
|
|
# Add space before capital letters for camelCase names
|
|
display_name = re.sub(r'([a-z])([A-Z])', r'\1 \2', display_name)
|
|
# Add space before numbers that follow letters
|
|
display_name = re.sub(r'([a-zA-Z])(\d)', r'\1 \2', display_name)
|
|
# Clean up multiple spaces
|
|
display_name = ' '.join(display_name.split())
|
|
|
|
# Use filename (without extension) as unique key to avoid collisions
|
|
# when multiple files share the same family_name from font metadata
|
|
catalog_key = os.path.splitext(filename)[0]
|
|
|
|
# Check if this is a system font (cannot be deleted)
|
|
is_system = catalog_key.lower() in SYSTEM_FONTS
|
|
|
|
# BDF files are fixed-size bitmap strikes: FreeType
|
|
# accepts only the pixel size baked into the file. The
|
|
# UI needs to know that before offering a size control,
|
|
# or it offers a number that cannot take effect.
|
|
native_size = None
|
|
if font_type == 'bdf':
|
|
try:
|
|
from src.element_style import _read_bdf_native_size
|
|
native_size = _read_bdf_native_size(str(filepath))
|
|
except Exception as e:
|
|
logger.debug("Could not read native size for BDF font %s: %s",
|
|
filepath, e)
|
|
native_size = None
|
|
|
|
catalog[catalog_key] = {
|
|
'filename': filename,
|
|
'family_name': family_name,
|
|
'display_name': display_name,
|
|
'path': relative_path,
|
|
'type': font_type,
|
|
'is_system': is_system,
|
|
'scalable': font_type != 'bdf',
|
|
'native_size': native_size,
|
|
'metadata': metadata if metadata else None
|
|
}
|
|
|
|
set_cached('fonts_catalog', catalog, ttl_seconds=300)
|
|
|
|
return _catalog_response(catalog)
|
|
@api_v3.route('/fonts/tokens', methods=['GET'])
|
|
def get_font_tokens():
|
|
"""Get font size tokens"""
|
|
# This would integrate with the actual font system
|
|
# For now, return sample tokens
|
|
tokens = {
|
|
'xs': 6,
|
|
'sm': 8,
|
|
'md': 10,
|
|
'lg': 12,
|
|
'xl': 14,
|
|
'xxl': 16
|
|
}
|
|
return jsonify({'status': 'success', 'data': {'tokens': tokens}})
|
|
@api_v3.route('/fonts/upload', methods=['POST'])
|
|
def upload_font():
|
|
"""Upload font file"""
|
|
if 'font_file' not in request.files:
|
|
return jsonify({'status': 'error', 'message': 'No font file provided'}), 400
|
|
|
|
font_file = request.files['font_file']
|
|
if font_file.filename == '':
|
|
return jsonify({'status': 'error', 'message': 'No file selected'}), 400
|
|
|
|
# Validate filename. validate_file_upload takes max_size_mb but only
|
|
# checks the filename/extension with it -- it never looks at the
|
|
# actual upload size, so the size limit below is enforced separately
|
|
# before the file is saved (same pattern as the .star upload above).
|
|
MAX_FONT_SIZE_MB = 10
|
|
is_valid, error_msg = validate_file_upload(
|
|
font_file.filename,
|
|
max_size_mb=MAX_FONT_SIZE_MB,
|
|
allowed_extensions=['.ttf', '.otf', '.bdf']
|
|
)
|
|
if not is_valid:
|
|
return jsonify({'status': 'error', 'message': error_msg}), 400
|
|
|
|
# Check file size (stated limit is MAX_FONT_SIZE_MB)
|
|
font_file.seek(0, 2) # Seek to end
|
|
file_size = font_file.tell()
|
|
font_file.seek(0) # Reset to beginning
|
|
max_font_size_bytes = MAX_FONT_SIZE_MB * 1024 * 1024
|
|
if file_size > max_font_size_bytes:
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': f'File too large (max {MAX_FONT_SIZE_MB}MB, got {file_size / 1024 / 1024:.1f}MB)'
|
|
}), 400
|
|
|
|
font_family = request.form.get('font_family', '')
|
|
|
|
if not font_family:
|
|
return jsonify({'status': 'error', 'message': 'Font file and family name required'}), 400
|
|
|
|
# Validate font family name
|
|
if not font_family.replace('_', '').replace('-', '').isalnum():
|
|
return jsonify({'status': 'error', 'message': 'Font family name must contain only letters, numbers, underscores, and hyphens'}), 400
|
|
|
|
# Save the font file to assets/fonts directory
|
|
fonts_dir = PROJECT_ROOT / "assets" / "fonts"
|
|
fonts_dir.mkdir(parents=True, exist_ok=True)
|
|
|
|
# Create filename from family name
|
|
original_ext = os.path.splitext(font_file.filename)[1].lower()
|
|
safe_filename = f"{font_family}{original_ext}"
|
|
filepath = fonts_dir / safe_filename
|
|
|
|
# Check if file already exists
|
|
if filepath.exists():
|
|
return jsonify({'status': 'error', 'message': f'Font with name {font_family} already exists'}), 400
|
|
|
|
# Save the file
|
|
font_file.save(str(filepath))
|
|
|
|
delete_cached('fonts_catalog')
|
|
|
|
return jsonify({
|
|
'status': 'success',
|
|
'message': f'Font {font_family} uploaded successfully',
|
|
'font_family': font_family,
|
|
'filename': safe_filename,
|
|
'path': f'assets/fonts/{safe_filename}'
|
|
})
|
|
@api_v3.route('/fonts/preview', methods=['GET'])
|
|
def get_font_preview() -> tuple[Response, int] | Response:
|
|
"""Generate a preview image of text rendered with a specific font"""
|
|
from PIL import Image, ImageDraw, ImageFont
|
|
import io
|
|
import base64
|
|
|
|
# Limits to prevent DoS via large image generation on constrained devices
|
|
MAX_TEXT_CHARS = 100
|
|
MAX_TEXT_LINES = 3
|
|
MAX_DIM = 1024 # Max width or height in pixels
|
|
MAX_PIXELS = 500000 # Max total pixels (e.g., ~700x700)
|
|
|
|
font_filename = request.args.get('font', '')
|
|
text = request.args.get('text', 'Sample Text 123')
|
|
bg_color = request.args.get('bg', '000000')
|
|
fg_color = request.args.get('fg', 'ffffff')
|
|
|
|
# Validate text length and line count early
|
|
if len(text) > MAX_TEXT_CHARS:
|
|
return jsonify({'status': 'error', 'message': f'Text exceeds maximum length of {MAX_TEXT_CHARS} characters'}), 400
|
|
if text.count('\n') >= MAX_TEXT_LINES:
|
|
return jsonify({'status': 'error', 'message': f'Text exceeds maximum of {MAX_TEXT_LINES} lines'}), 400
|
|
|
|
# Safe integer parsing for size
|
|
try:
|
|
size = int(request.args.get('size', 12))
|
|
except (ValueError, TypeError, OverflowError):
|
|
return jsonify({'status': 'error', 'message': 'Invalid font size'}), 400
|
|
|
|
if not font_filename:
|
|
return jsonify({'status': 'error', 'message': 'Font filename required'}), 400
|
|
|
|
# Validate size
|
|
if size < 4 or size > 72:
|
|
return jsonify({'status': 'error', 'message': 'Font size must be between 4 and 72'}), 400
|
|
|
|
# Security: Validate font_filename to prevent path traversal
|
|
# Only allow alphanumeric, hyphen, underscore, and dot (for extension)
|
|
safe_name = Path(font_filename).name # Strip any directory components
|
|
if safe_name != font_filename or '..' in font_filename:
|
|
return jsonify({'status': 'error', 'message': 'Invalid font filename'}), 400
|
|
|
|
# Validate extension
|
|
allowed_extensions = ['.ttf', '.otf', '.bdf']
|
|
has_valid_ext = any(safe_name.lower().endswith(ext) for ext in allowed_extensions)
|
|
name_without_ext = safe_name.rsplit('.', 1)[0] if '.' in safe_name else safe_name
|
|
|
|
# Find the font file
|
|
fonts_dir = PROJECT_ROOT / "assets" / "fonts"
|
|
if not fonts_dir.exists():
|
|
return jsonify({'status': 'error', 'message': 'Fonts directory not found'}), 404
|
|
|
|
font_path = fonts_dir / safe_name
|
|
|
|
if not font_path.exists() and not has_valid_ext:
|
|
# Try finding by family name (without extension)
|
|
for ext in allowed_extensions:
|
|
potential_path = fonts_dir / f"{name_without_ext}{ext}"
|
|
if potential_path.exists():
|
|
font_path = potential_path
|
|
break
|
|
|
|
# Final security check: ensure path is within fonts_dir
|
|
try:
|
|
font_path.resolve().relative_to(fonts_dir.resolve())
|
|
except ValueError:
|
|
return jsonify({'status': 'error', 'message': 'Invalid font path'}), 400
|
|
|
|
if not font_path.exists():
|
|
return jsonify({'status': 'error', 'message': f'Font file not found: {font_filename}'}), 404
|
|
|
|
# Parse colors
|
|
try:
|
|
bg_rgb = tuple(int(bg_color[i:i+2], 16) for i in (0, 2, 4))
|
|
fg_rgb = tuple(int(fg_color[i:i+2], 16) for i in (0, 2, 4))
|
|
except (ValueError, IndexError):
|
|
bg_rgb = (0, 0, 0)
|
|
fg_rgb = (255, 255, 255)
|
|
|
|
# Load font
|
|
font = None
|
|
if str(font_path).endswith('.bdf'):
|
|
# BDF fonts require complex per-glyph rendering via freetype
|
|
# Return explicit error rather than showing misleading preview with default font
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': 'BDF font preview not supported. BDF fonts will render correctly on the LED matrix.'
|
|
}), 400
|
|
else:
|
|
# TTF/OTF fonts
|
|
try:
|
|
font = ImageFont.truetype(str(font_path), size)
|
|
except (IOError, OSError) as e:
|
|
# IOError/OSError raised for invalid/corrupt font files
|
|
logger.warning("[FontPreview] Failed to load font %s: %s", font_path, e)
|
|
font = ImageFont.load_default()
|
|
|
|
# Calculate text size
|
|
temp_img = Image.new('RGB', (1, 1))
|
|
temp_draw = ImageDraw.Draw(temp_img)
|
|
bbox = temp_draw.textbbox((0, 0), text, font=font)
|
|
text_width = bbox[2] - bbox[0]
|
|
text_height = bbox[3] - bbox[1]
|
|
|
|
# Create image with padding
|
|
padding = 10
|
|
img_width = max(text_width + padding * 2, 100)
|
|
img_height = max(text_height + padding * 2, 30)
|
|
|
|
# Validate resulting image size to prevent memory/CPU spikes
|
|
if img_width > MAX_DIM or img_height > MAX_DIM:
|
|
return jsonify({'status': 'error', 'message': 'Requested image too large'}), 400
|
|
if img_width * img_height > MAX_PIXELS:
|
|
return jsonify({'status': 'error', 'message': 'Requested image too large'}), 400
|
|
|
|
img = Image.new('RGB', (img_width, img_height), bg_rgb)
|
|
draw = ImageDraw.Draw(img)
|
|
|
|
# Center text
|
|
x = (img_width - text_width) // 2
|
|
y = (img_height - text_height) // 2
|
|
|
|
draw.text((x, y), text, font=font, fill=fg_rgb)
|
|
|
|
# Convert to base64
|
|
buffer = io.BytesIO()
|
|
img.save(buffer, format='PNG')
|
|
buffer.seek(0)
|
|
img_base64 = base64.b64encode(buffer.getvalue()).decode('utf-8')
|
|
|
|
return jsonify({
|
|
'status': 'success',
|
|
'data': {
|
|
'image': f'data:image/png;base64,{img_base64}',
|
|
'width': img_width,
|
|
'height': img_height
|
|
}
|
|
})
|
|
@api_v3.route('/fonts/<font_family>', methods=['DELETE'])
|
|
def delete_font(font_family: str) -> tuple[Response, int] | Response:
|
|
"""Delete a user-uploaded font file"""
|
|
# Security: Validate font_family to prevent path traversal
|
|
# Reject if it contains path separators or ..
|
|
if '..' in font_family or '/' in font_family or '\\' in font_family:
|
|
return jsonify({'status': 'error', 'message': 'Invalid font family name'}), 400
|
|
|
|
# Only allow safe characters: alphanumeric, hyphen, underscore, dot
|
|
if not re.match(r'^[a-zA-Z0-9_\-\.]+$', font_family):
|
|
return jsonify({'status': 'error', 'message': 'Invalid font family name'}), 400
|
|
|
|
# Check if this is a system font (uses module-level SYSTEM_FONTS frozenset)
|
|
if font_family.lower() in SYSTEM_FONTS:
|
|
return jsonify({'status': 'error', 'message': 'Cannot delete system fonts'}), 403
|
|
|
|
# Find and delete the font file
|
|
fonts_dir = PROJECT_ROOT / "assets" / "fonts"
|
|
|
|
# Ensure fonts directory exists
|
|
if not fonts_dir.exists() or not fonts_dir.is_dir():
|
|
return jsonify({'status': 'error', 'message': 'Fonts directory not found'}), 404
|
|
|
|
deleted = False
|
|
deleted_filename = None
|
|
|
|
# Only try valid font extensions (no empty string to avoid matching directories)
|
|
for ext in ['.ttf', '.otf', '.bdf']:
|
|
potential_path = fonts_dir / f"{font_family}{ext}"
|
|
|
|
# Security: Verify path is within fonts_dir
|
|
try:
|
|
potential_path.resolve().relative_to(fonts_dir.resolve())
|
|
except ValueError:
|
|
continue # Path escapes fonts_dir, skip
|
|
|
|
if potential_path.exists() and potential_path.is_file():
|
|
potential_path.unlink()
|
|
deleted = True
|
|
deleted_filename = f"{font_family}{ext}"
|
|
break
|
|
|
|
if not deleted:
|
|
# Try case-insensitive match within fonts directory
|
|
font_family_lower = font_family.lower()
|
|
for filename in os.listdir(fonts_dir):
|
|
# Only consider files with valid font extensions
|
|
if not any(filename.lower().endswith(ext) for ext in ['.ttf', '.otf', '.bdf']):
|
|
continue
|
|
|
|
name_without_ext = os.path.splitext(filename)[0]
|
|
if name_without_ext.lower() == font_family_lower:
|
|
filepath = fonts_dir / filename
|
|
|
|
# Security: Verify path is within fonts_dir
|
|
try:
|
|
filepath.resolve().relative_to(fonts_dir.resolve())
|
|
except ValueError:
|
|
continue # Path escapes fonts_dir, skip
|
|
|
|
if filepath.is_file():
|
|
filepath.unlink()
|
|
deleted = True
|
|
deleted_filename = filename
|
|
break
|
|
|
|
if not deleted:
|
|
return jsonify({'status': 'error', 'message': f'Font not found: {font_family}'}), 404
|
|
|
|
delete_cached('fonts_catalog')
|
|
|
|
return jsonify({
|
|
'status': 'success',
|
|
'message': f'Font {deleted_filename} deleted successfully'
|
|
})
|