mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 14:25:08 +00:00
* fix(errors): record the exception's own stack trace record_error() called traceback.format_exc(), which only sees an exception while its except block is running. plugin_executor records exceptions caught on a worker thread after that block has ended, so every trace on /errors read "NoneType: None". The trace is now built from the exception's __traceback__. The executor's log call had the same problem with exc_info=True and now passes the exception. record_error() also merged LEDMatrixError context into the caller's dict in place; it now works on a copy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(wifi): point at configure_wifi_permissions.sh instead of a sudoers list The module docstring told users to grant NOPASSWD sudo on iptables and ip. configure_wifi_permissions.sh refuses those grants on purpose: a wildcard rule for either runs an arbitrary program as root. Point at the script and say why it leaves them out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(wifi): disconnect finds the saved profile by SSID disconnect_from_network() asked `nmcli -f NAME,802-11-wireless.ssid connection show` for the profile to take down, but nmcli rejects that column for `connection show`, so the lookup always failed and only the device was disconnected. The per-profile lookup _connect_nmcli() already used is now _find_profile_for_ssid(), and both callers share it. It also splits terse output on the last colon and unescapes "\:", so a profile name containing a colon is found. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(wifi): write wifi_config.json atomically and report a failed save _save_config() opened the file for writing in place and swallowed any error, so a wifi_config.json left owned by root made the web toggle for auto-enabling AP mode report success while nothing was saved, and a crash mid-write could truncate the file. It now uses atomic_write_json, which also keeps the file's owner and shared group when root saves it, and returns False on failure. POST /wifi/ap/auto-enable answers 500 in that case. The file is now written with indent=4, like the other config files. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(fonts): resolve plugin:// fonts in the plugin's own directory FontManager looked for a plugin's bundled fonts under Path("plugins") / plugin_id: relative to the process cwd, and not the default install directory (plugin-repos/), so a manifest's plugin:// fonts never loaded. register_plugin_fonts() takes an optional plugin_dir, and PluginManager passes the directory it loaded the plugin from. Callers that omit it get a lookup in the configured plugin_system.plugins_directory, then plugins/, resolved against the install root. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(api-helper): cache responses for the requested cache_ttl APIHelper.get(cache_ttl=...) and set_cache(ttl=...) dropped the ttl on the claim that CacheManager does not support one, but CacheManager.set() takes a ttl, stores it with the entry, and both cache tiers honour it over a reader's max_age. Without it every response expired after the 300-second default read age, whatever the plugin asked for. The ttl is now passed through, and the cache read passes cache_ttl as max_age for entries written without one. The class docstring describes what the helper actually does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(style): one scale range for the schema, element_scale and LogoHelper The generated Scale field allowed 0.1 to 10, element_style's reader capped at 10 with no floor, and LogoHelper accepted 0.05 to 8 and reset anything else to 1.0. A logo scale of 9, which the form accepts, drew at the shipped size. MIN_ELEMENT_SCALE / MAX_ELEMENT_SCALE (0.1, 10.0) in src.element_style are now the schema bounds and the clamp every reader applies through coerce_scale(): a positive number outside the range is clamped, and anything that is not a finite positive number means the default. That also stops element_scale() passing NaN through, since min(nan, 10.0) is nan. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(logos): placeholder lands at the requested path; empty logos list download_missing_logo() wrote its fallback placeholder to <normalize_abbreviation(abbr)>.png in the logo directory rather than to the logo_path the caller passed, so it could return True while nothing existed where the plugin looks (e.g. "TA&M.png" vs "TAANDM.png"). create_placeholder_logo() takes an optional filepath, and download_missing_logo passes the requested one. download_missing_logo_for_team() only caught KeyError, so a team whose "logos" list is empty raised IndexError; it now treats KeyError, IndexError and TypeError as "no logo URL". The placeholder is drawn with PLACEHOLDER_SIZE / PLACEHOLDER_BG, the constants is_placeholder_logo() recognises it by, instead of repeated literals. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(fonts): resolve bundled font paths against the install root TextHelper's default font_dir, the logo placeholder's font and FontManager's font_overrides.json were all relative to the process cwd, so a process started anywhere but the install root (the plugin safety harness, a manual run, a unit without WorkingDirectory) drew with PIL's default face and read no overrides. They now go through font_layout.resolve_asset_path; the overrides file sits in the install root's config/. The resolver docstrings described an order the code does not follow: resolve_asset_path never consults the cwd, and sports_shared's _resolve_font_path tries the cwd first. Both docstrings now say what the code does, and _resolve_font_path calls resolve_asset_path instead of probing FontManager for it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(sync): the web UI reads the sync status file the display writes sync_manager writes its status to tempfile.gettempdir(), but GET /api/v3/sync/status read a hardcoded /tmp/led_matrix_sync_status.json and defaulted the port to a literal 5765. Wherever TMPDIR is set (or on any non-/tmp host) the page only ever showed "starting". The endpoint now uses sync_manager.STATUS_FILE and SYNC_PORT. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(http): the rankings resolver sends the project's User-Agent DynamicTeamResolver fetched ESPN rankings with a bare requests.get, so it sent python-requests' default User-Agent, which ESPN rejects; the AP_TOP_N favourites then resolved to nothing. It now sends DEFAULT_HTTP_HEADERS. BaseOddsManager carried its own copy of the User-Agent string and now uses the same shared headers (which also adds Accept-Language). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(backup): record the core release and read the configured plugin dir The manifest's ledmatrix_version came from a VERSION file that does not exist, then from .git/HEAD: a 12-character sha, or "ref: refs/he" when the branch's ref was packed. It is now src.__version__. list_installed_plugins() scanned a hardcoded plugin-repos/, so on an install whose plugin_system.plugins_directory points elsewhere, plugins missing from plugin_state.json were left out of the backup. It now reads the configured directory from config/config.json, defaulting to plugin-repos. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(startup): report a missing display section once A config without a display section produced three errors for the one problem ("Missing required configuration key: display", "Display configuration is missing or empty" and "Display configuration is missing"), and an empty one produced two. _validate_config now reports it once, as a missing key or an empty section, and _validate_display_config leaves it to that. The module docstring said the validator fails fast; nothing in the display service calls raise_on_errors(), so it now says the errors are reported and startup continues. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(wifi): share the copied blocks and name the AP constants - _parse_nmcli_wifi_list() is the one parser behind _scan_nmcli and _scan_nmcli_cached. - _verify_connected(), _wait_for_device_idle(), _failsafe_ap() and _mark_forced() replace blocks that were pasted two or three times in the connect and enable-AP paths. The device-idle wait now checks before its first one-second sleep instead of after it. - _check_command() calls _find_command_path() instead of repeating it. - AP_IP, PORTAL_PORT, AP_PROFILE_NAME and AP_PROFILE_NAMES name values that were spelled out 14, 12, 8 and 2 times; the two deletion loops now walk the same tuple. The iwconfig status path compares the AP address exactly: startswith() also skipped 192.168.4.10-19. - Dropped a second WIFI.SIGNAL query that repeated the first, a no-op "if ssid: continue", the try/except around _connect_wpa_supplicant's constant return, and a second save of a scan scan_networks already saves. - _ensure_wifi_radio_enabled's docstring says it returns True when the radio state cannot be read at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(config): drop dead branches and history comments in ConfigManager - The module docstring pointed plugin authors at update_plugin_config(), which does not exist; it now names save_config_atomic() and save_raw_file_content(). - load_config's FileNotFoundError handler tested the message for "config_secrets.json", but a missing secrets file is handled where it is read, so only config.json reaches it; the check is gone. - save_raw_file_content's `file_type == "main" or "secrets"` guard was always true (anything else raised earlier). - get_raw_file_content('secrets') already returns {} for a missing file, so the os.path.exists() in front of two calls to it is gone. - Comments that narrated earlier behaviour are rewritten as what the code does now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(background-data): present-tense comments, drop unused API - Comments that told the history of each fix (what "used to" happen, "the old per-delivery release") now state the invariant the code keeps. - get_statistics() no longer reports a constant 'queue_size': 0, and the uncalled clear_completed_requests() is gone (_cleanup_completed_requests does that job on every completion). Neither is referenced in core, the web UI or the plugin monorepo. shutdown_background_service() has no production caller either, but it is the only way to tear down the get_background_service() singleton, which the tests rely on, so it stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(odds): drop the unread cache_ttl and merge the odds_data branches BaseOddsManager loaded base_odds_manager.cache_ttl from config and never used it: cached odds live for the update interval (get_odds' ttl=interval). No core or monorepo code reads the attribute, so it is gone along with its log line. The two consecutive `if odds_data:` blocks are one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(backup): one table for the single-file sections config, secrets, wifi and ytm_auth were each spelled out in create, preview, validate and restore. _SINGLE_FILE_SECTIONS lists them once, with the RestoreOptions flag that restores each, and all four walk it. Restore error messages keep their wording ("Failed to restore <file name>"). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(fonts): drop FontManager's write-only state and duplicate logs - fonts_config, font_metadata and font_dependencies were written and never read; the performance_stats keys font_load_times, render_times, total_renders and the per-call "resolve" timings (_record_performance_metric) likewise. get_performance_stats() reads only the counters that remain. Nothing in core or the plugin monorepo references any of them. - A failed BDF load was logged twice, by _load_bdf_font and again by get_font; get_font's line is the one kept. - Removed "NEW:" and commented-out cozette entries, the "Copy font to assets/fonts" comment on code that copies nothing, and local imports of names the module already imports. The deprecated add_font() now resolves assets/fonts against the install root. The @deprecated methods stay. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(text-helper): cache loaded fonts; drop the pre-textlength fallback TextHelper declared _font_cache, cleared it and reported its size, but never stored anything in it. load_fonts() now keeps each (file, size) it loads there, so clear_font_cache() and get_font_cache_stats() mean what they say and repeated load_fonts() calls reuse the fonts. get_text_width() no longer catches AttributeError for Pillow releases without ImageDraw.textlength; requirements.txt pins Pillow>=12.2. The class docstring describes what the helper does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(common): fix wrong docstrings in api_helper, permission_utils, snapshot_policy - permission_utils called 0o2775 "sticky bit"; the 2 is setgid, which is what makes new files take the directory's group. - snapshot_policy pointed at web_interface/blueprints/api_v3.py, which is a package now; the health check is in api_v3/misc.py. - APIHelper.clear_cache() lost a history note and a fallback to a clear() method that neither CacheManager nor the testing MockCacheManager has. The session headers are built from DEFAULT_HTTP_HEADERS instead of a copy of them, and the module docstring says what the module offers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(sports): present-tense comments in the shared scoreboard renderers - sports_scroll and sports_game_renderer comments that referred to "this PR", "the old flat 128px card" or what the renderer "previously" did now describe the current behaviour and its reason. - The block explaining why non-finite settings are rejected sat above _score_reserve_width; it describes _center_gap_width and now lives in it. - unshare_element_fonts wrapped its import of font_layout.load_truetype in an `except ImportError` that cannot fire inside core; the import stays at call time so tests can spy on the pinned loader. - sports_card docstrings that told the history of a fix say what the code does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(sports-shared): drop dead code, name the ESPN limit - _get_weeks_data asked for limit=1000, which fetch_espn_scoreboard clamps to ESPN_MAX_LIMIT anyway; it now names that constant. Its unused `immediate_events = []` is gone. - _get_season_schedule_dates() returned ("", "") and has no caller in core or the plugin monorepo. - _should_log keeps its warning_type parameter (part of the inherited signature, though nothing in core or the monorepo calls it) and its docstring says the cooldown is shared across types. - An unused ImageFont import is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(sync): one follower-mode switch, shared panel defaults - The class docstring said the leader sends PNG frames. Frames go over UDP as raw RGB; PNG is only the Vegas scroll image sent over TCP. It now describes both paths. - _enter_follower_mode() replaces the two copies of "note the leader, switch from standalone to follower, log, write status" in the frame and scroll-position handlers. - The rows/cols fallbacks use DEFAULT_ROWS / DEFAULT_COLS from src.display_geometry, as chain_length already did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(style): drop _layout_axis, name the layout group title - ElementStyleResolver._layout_axis() had no caller in core or the plugin monorepo. - _element_block_from_spec checked spec['size'] was a dict again after size_spec already had; it reads size_spec. - The "Layout Offsets" title written into three generated schema blocks is _LAYOUT_TITLE. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(logo-helper): say what the placeholder draws; name the 1.5 box factor - _create_placeholder_logo's docstring said it draws the team abbreviation; it draws an outlined grey box and nothing else. The docstring says so, and the "in a real implementation you'd want text" comments are gone. - The 1.5 x panel default logo box, written out six times, is DEFAULT_LOGO_BOX_FACTOR. - ImageDraw is imported with Image at the top of the module. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(logos): drop dead code and a duplicate regex in logo_downloader - _SAFE_LEAGUE_CODE_RE was the same pattern as _SAFE_LEAGUE_RE; both checks use the one. - get_logo_filename_variations reassigned the TA&M case to the list it already had; the function returns the two names directly. - _get_team_name_variations() had no caller in core or the plugin monorepo. - fetch_single_team's docstring was copied from fetch_teams_data; a log message read "for{team_id}". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor: drop the Pillow<9.1 resample shim and a catch-and-reraise - adaptive_images fell back to Image.LANCZOS/NEAREST for Pillow < 9.1; requirements.txt pins Pillow>=12.2. RESAMPLE_LANCZOS and RESAMPLE_NEAREST keep their names (src.common re-exports them). - CacheManager.save_cache caught CacheError only to re-raise it; the disk write is now called directly, with the same result. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(api-helper): stop the real CacheManager's cleanup thread The cache-lifetime tests built a CacheManager and left its cleanup thread's class-wide claim on the directory in place, which broke test_cache_cleanup_thread_ownership when it ran later in the session. The fixture now stops the thread on teardown. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): core-common Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
541 lines
22 KiB
Python
541 lines
22 KiB
Python
"""Routes with no larger group of their own: errors, integrations,
|
|
cache, sync, logs, health and hardware.
|
|
|
|
Routes decorate the shared `api_v3` Blueprint from ._common, so their
|
|
endpoint names are unchanged by living here.
|
|
"""
|
|
from web_interface.blueprints.api_v3 import (
|
|
_coerce_to_bool,
|
|
ErrorCode, Path, _JOURNALCTL, _MQTT_BRIDGE_CONFIG, _MQTT_BRIDGE_DEFAULTS,
|
|
_MQTT_BRIDGE_DIR, _SUDO, _coerce_mqtt_bridge_value,
|
|
_get_display_service_status, _mqtt_bridge_service_state,
|
|
_read_mqtt_bridge_config, api_v3, contextlib, describe_exception,
|
|
error_response, json, jsonify, logger, os, redact_text, request,
|
|
subprocess, success_response, tempfile,
|
|
)
|
|
from src.common.path_safety import safe_path_component
|
|
from src.common import sync_manager as _sync
|
|
from src import error_aggregator as _errors
|
|
import web_interface.blueprints.api_v3 as _pkg
|
|
# Read through the module rather than bound by value: tests patch these
|
|
# as module attributes, and a value binding would not see the patch.
|
|
# Several are also called from helpers that live in __init__, so the
|
|
# package is the only patch point that covers every caller.
|
|
|
|
|
|
@api_v3.route('/health', methods=['GET'])
|
|
def get_health():
|
|
"""Get system health status"""
|
|
try:
|
|
health_status = {
|
|
'status': 'healthy',
|
|
'timestamp': _pkg.time.time(),
|
|
'services': {},
|
|
'checks': {}
|
|
}
|
|
|
|
# Check web interface service
|
|
# Stamp the start _pkg.time before measuring against it -- reading it with a
|
|
# fallback of _pkg.time.time() and only assigning afterwards made the very
|
|
# first call subtract two separate clock reads, reporting a small
|
|
# negative uptime.
|
|
if not hasattr(get_health, '_start_time'):
|
|
get_health._start_time = _pkg.time.time()
|
|
health_status['services']['web_interface'] = {
|
|
'status': 'running',
|
|
'uptime_seconds': _pkg.time.time() - get_health._start_time
|
|
}
|
|
|
|
# Check display service
|
|
display_service_status = _get_display_service_status()
|
|
health_status['services']['display_service'] = {
|
|
'status': 'active' if display_service_status.get('active') else 'inactive',
|
|
'details': display_service_status
|
|
}
|
|
|
|
# Check config file accessibility
|
|
try:
|
|
if api_v3.config_manager:
|
|
test_config = api_v3.config_manager.load_config()
|
|
health_status['checks']['config_file'] = {
|
|
'status': 'accessible',
|
|
'readable': True
|
|
}
|
|
else:
|
|
health_status['checks']['config_file'] = {
|
|
'status': 'unknown',
|
|
'readable': False
|
|
}
|
|
except Exception as e:
|
|
health_status['checks']['config_file'] = {
|
|
'status': 'error',
|
|
'readable': False,
|
|
'error': 'see logs for details'
|
|
}
|
|
|
|
# Check plugin system
|
|
try:
|
|
if api_v3.plugin_manager:
|
|
# Try to discover plugins (lightweight check)
|
|
plugin_count = len(api_v3.plugin_manager.get_available_plugins()) if hasattr(api_v3.plugin_manager, 'get_available_plugins') else 0
|
|
health_status['checks']['plugin_system'] = {
|
|
'status': 'operational',
|
|
'plugin_count': plugin_count
|
|
}
|
|
else:
|
|
health_status['checks']['plugin_system'] = {
|
|
'status': 'not_initialized'
|
|
}
|
|
except Exception as e:
|
|
health_status['checks']['plugin_system'] = {
|
|
'status': 'error',
|
|
'error': 'see logs for details'
|
|
}
|
|
|
|
# Check hardware connectivity (if display manager available)
|
|
try:
|
|
snapshot_path = "/tmp/led_matrix_preview.png"
|
|
if os.path.exists(snapshot_path):
|
|
# Check if snapshot is recent (updated in last 60 seconds)
|
|
mtime = os.path.getmtime(snapshot_path)
|
|
age_seconds = _pkg.time.time() - mtime
|
|
health_status['checks']['hardware'] = {
|
|
'status': 'connected' if age_seconds < 60 else 'stale',
|
|
'snapshot_age_seconds': round(age_seconds, 1)
|
|
}
|
|
else:
|
|
health_status['checks']['hardware'] = {
|
|
'status': 'no_snapshot',
|
|
'note': 'Display service may not be running'
|
|
}
|
|
except Exception as e:
|
|
health_status['checks']['hardware'] = {
|
|
'status': 'unknown',
|
|
'error': 'see logs for details'
|
|
}
|
|
|
|
# Determine overall health
|
|
all_healthy = all(
|
|
check.get('status') in ['accessible', 'operational', 'connected', 'running', 'active']
|
|
for check in health_status['checks'].values()
|
|
)
|
|
|
|
if not all_healthy:
|
|
health_status['status'] = 'degraded'
|
|
|
|
return jsonify({'status': 'success', 'data': health_status})
|
|
except Exception as e:
|
|
logger.error("%s failed", request.path, exc_info=True)
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': 'An error occurred; see logs for details',
|
|
'details': describe_exception(e),
|
|
'data': {'status': 'unhealthy'}
|
|
}), 500
|
|
@api_v3.route('/hardware/status', methods=['GET'])
|
|
def get_hardware_status():
|
|
"""Return LED matrix hardware initialization status written by display_manager at startup."""
|
|
status_path = "/tmp/led_matrix_hw_status.json" # nosec B108
|
|
try:
|
|
with open(status_path) as f:
|
|
hw_data = json.load(f)
|
|
return jsonify({"status": "success", "data": hw_data})
|
|
except FileNotFoundError:
|
|
return jsonify({"status": "success", "data": {"ok": None, "error": "Display service not yet started"}})
|
|
except PermissionError:
|
|
logger.warning("Permission denied reading hardware status file; display service may be running as a different user")
|
|
return jsonify({"status": "success", "data": {"ok": False, "error": "Hardware status temporarily unavailable"}})
|
|
except json.JSONDecodeError:
|
|
logger.error("Failed to parse hardware status file", exc_info=True)
|
|
return jsonify({"status": "success", "data": {"ok": False, "error": "Hardware status file corrupted"}})
|
|
except Exception:
|
|
logger.error("Unexpected error reading hardware status", exc_info=True)
|
|
return jsonify({"status": "error", "message": "Unable to read hardware status"}), 500
|
|
@api_v3.route('/logs', methods=['GET'])
|
|
def get_logs():
|
|
"""Get system logs from journalctl"""
|
|
try:
|
|
if not _JOURNALCTL:
|
|
return jsonify({'status': 'error', 'message': 'journalctl not found on this system'}), 503
|
|
# Get recent logs from journalctl
|
|
_cmd = ([_SUDO, _JOURNALCTL] if _SUDO else [_JOURNALCTL]) + [
|
|
'-u', 'ledmatrix.service', '-u', 'ledmatrix-web.service',
|
|
'-n', '100', '--no-pager', '--output=short-iso']
|
|
result = subprocess.run(
|
|
_cmd,
|
|
capture_output=True,
|
|
text=True,
|
|
timeout=5
|
|
)
|
|
|
|
if result.returncode == 0:
|
|
logs_text = result.stdout.strip()
|
|
return jsonify({
|
|
'status': 'success',
|
|
'data': {
|
|
'logs': logs_text if logs_text else 'No logs available from ledmatrix or ledmatrix-web service'
|
|
}
|
|
})
|
|
else:
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': f'Failed to get logs: {result.stderr}'
|
|
}), 500
|
|
|
|
except subprocess.TimeoutExpired:
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': 'Timeout while fetching logs'
|
|
}), 500
|
|
# Multi-Display Sync Endpoints
|
|
@api_v3.route('/sync/status', methods=['GET'])
|
|
def get_sync_status():
|
|
"""Return live multi-display sync status written by the display process."""
|
|
# The display process writes this file; read it where it is written.
|
|
status_file = _sync.STATUS_FILE
|
|
# Also surface config so the UI can show the configured role even before
|
|
# the display process has written a status file.
|
|
cfg_role = "standalone"
|
|
cfg_port = _sync.SYNC_PORT
|
|
if api_v3.config_manager:
|
|
try:
|
|
cfg = api_v3.config_manager.load_config().get("sync", {})
|
|
cfg_role = cfg.get("role", "standalone")
|
|
cfg_port = int(cfg.get("port", _sync.SYNC_PORT))
|
|
except Exception:
|
|
pass
|
|
|
|
if os.path.exists(status_file):
|
|
try:
|
|
with open(status_file) as f:
|
|
live = json.load(f)
|
|
return jsonify({"status": "success", "data": live})
|
|
except Exception:
|
|
pass
|
|
|
|
# Status file not yet written — return config-only placeholder
|
|
return jsonify({
|
|
"status": "success",
|
|
"data": {
|
|
"role": cfg_role,
|
|
"port": cfg_port,
|
|
"state": "starting",
|
|
}
|
|
})
|
|
@api_v3.route('/cache/list', methods=['GET'])
|
|
def list_cache_files():
|
|
"""List all cache files with metadata"""
|
|
if not api_v3.cache_manager:
|
|
# Initialize cache manager if not already initialized
|
|
from src.cache_manager import CacheManager
|
|
api_v3.cache_manager = CacheManager()
|
|
|
|
cache_files = api_v3.cache_manager.list_cache_files()
|
|
cache_dir = api_v3.cache_manager.get_cache_dir()
|
|
|
|
return jsonify({
|
|
'status': 'success',
|
|
'data': {
|
|
'cache_files': cache_files,
|
|
'cache_dir': cache_dir,
|
|
'total_files': len(cache_files)
|
|
}
|
|
})
|
|
@api_v3.route('/cache/delete', methods=['POST'])
|
|
def delete_cache_file():
|
|
"""Delete a specific cache file by key"""
|
|
if not api_v3.cache_manager:
|
|
# Initialize cache manager if not already initialized
|
|
from src.cache_manager import CacheManager
|
|
api_v3.cache_manager = CacheManager()
|
|
|
|
data = request.get_json(silent=True)
|
|
if not data or 'key' not in data:
|
|
return jsonify({'status': 'error', 'message': 'cache key is required'}), 400
|
|
|
|
cache_key = data['key']
|
|
|
|
# The key names the file about to be removed. DiskCache refuses an
|
|
# unusable key on its own, but silently: say so here instead of
|
|
# reporting a deletion that never happened.
|
|
if safe_path_component(cache_key) is None:
|
|
return jsonify({'status': 'error', 'message': 'Invalid cache key'}), 400
|
|
|
|
# Delete the cache file
|
|
api_v3.cache_manager.clear_cache(cache_key)
|
|
|
|
return jsonify({
|
|
'status': 'success',
|
|
'message': f'Cache file for key "{cache_key}" deleted successfully'
|
|
})
|
|
def _errors_cache():
|
|
"""The shared cache the display service publishes its errors to."""
|
|
if not api_v3.cache_manager:
|
|
from src.cache_manager import CacheManager
|
|
api_v3.cache_manager = CacheManager()
|
|
return api_v3.cache_manager
|
|
|
|
|
|
def _redact_error_text(text, keep_lines=False):
|
|
"""Credentials out of plugin exception text, which can quote a URL with
|
|
an API key in it. Stack traces keep their line breaks and indentation."""
|
|
if not isinstance(text, str):
|
|
return text
|
|
if not keep_lines:
|
|
return redact_text(text, max_length=len(text) + 1)
|
|
return '\n'.join(
|
|
line[:len(line) - len(line.lstrip())] + redact_text(line, max_length=len(line) + 1)
|
|
for line in text.splitlines()
|
|
)
|
|
|
|
|
|
def _redact_error_record(record):
|
|
if not isinstance(record, dict):
|
|
return record
|
|
record = dict(record)
|
|
record['message'] = _redact_error_text(record.get('message'))
|
|
record['stack_trace'] = _redact_error_text(record.get('stack_trace'), keep_lines=True)
|
|
if isinstance(record.get('context'), dict):
|
|
record['context'] = {k: _redact_error_text(v) for k, v in record['context'].items()}
|
|
return record
|
|
|
|
|
|
def _read_errors():
|
|
snapshot, clear_request = _errors.read_error_report(_errors_cache())
|
|
return snapshot, clear_request
|
|
|
|
|
|
@api_v3.route('/errors/summary', methods=['GET'])
|
|
def get_error_summary():
|
|
"""
|
|
Get summary of all errors for monitoring and debugging.
|
|
|
|
Returns error counts, detected patterns, and recent errors, as last
|
|
reported by the display service (which runs the plugins, so it is the
|
|
only process that records their errors). ``snapshot_available`` is false
|
|
until it has reported; ``generated_at`` says when it did.
|
|
"""
|
|
try:
|
|
summary = _errors.error_summary_from_report(*_read_errors())
|
|
summary['recent_errors'] = [_redact_error_record(r) for r in summary['recent_errors']]
|
|
for pattern in summary['active_patterns'].values():
|
|
if isinstance(pattern, dict) and isinstance(pattern.get('sample_messages'), list):
|
|
pattern['sample_messages'] = [_redact_error_text(m) for m in pattern['sample_messages']]
|
|
message = ("Error summary retrieved" if summary['snapshot_available']
|
|
else "The display service has not reported any errors yet")
|
|
return success_response(data=summary, message=message)
|
|
except Exception as e:
|
|
logger.error(f"Error getting error summary: {e}", exc_info=True)
|
|
return error_response(
|
|
error_code=ErrorCode.SYSTEM_ERROR,
|
|
message="Failed to retrieve error summary",
|
|
status_code=500
|
|
)
|
|
@api_v3.route('/errors/plugin/<plugin_id>', methods=['GET'])
|
|
def get_plugin_errors(plugin_id):
|
|
"""
|
|
Get error health status for a specific plugin.
|
|
|
|
Args:
|
|
plugin_id: Plugin identifier
|
|
|
|
Returns health status and error statistics for the plugin, from the
|
|
display service's last report (see get_error_summary). A plugin with no
|
|
recorded errors is "healthy".
|
|
"""
|
|
try:
|
|
health = _errors.plugin_health_from_report(*_read_errors(), plugin_id)
|
|
health['last_error'] = _redact_error_record(health['last_error'])
|
|
return success_response(data=health, message="Plugin health retrieved")
|
|
except Exception as e:
|
|
logger.error(f"Error getting plugin health for {plugin_id}: {e}", exc_info=True)
|
|
return error_response(
|
|
error_code=ErrorCode.SYSTEM_ERROR,
|
|
message=f"Failed to retrieve health for plugin {plugin_id}",
|
|
status_code=500
|
|
)
|
|
@api_v3.route('/errors/clear', methods=['POST'])
|
|
def clear_old_errors():
|
|
"""
|
|
Clear error records older than specified age.
|
|
|
|
Request body (optional):
|
|
max_age_hours: Maximum age in hours (default: 24, max: 8760 = 1 year)
|
|
all: true clears every error recorded so far (max_age_hours ignored)
|
|
|
|
The errors live in the display service, so this records a clear request
|
|
that it applies within a few seconds. Reads hide the cleared errors from
|
|
the moment the request is recorded.
|
|
"""
|
|
try:
|
|
data = request.get_json(silent=True) or {}
|
|
clear_all = _coerce_to_bool(data.get('all'))
|
|
raw_max_age = data.get('max_age_hours', 24)
|
|
|
|
# Validate and coerce max_age_hours
|
|
max_age_hours = None
|
|
if not clear_all:
|
|
try:
|
|
max_age_hours = int(raw_max_age)
|
|
if max_age_hours < 1:
|
|
return error_response(
|
|
error_code=ErrorCode.INVALID_INPUT,
|
|
message="max_age_hours must be at least 1",
|
|
context={'provided_value': raw_max_age},
|
|
status_code=400
|
|
)
|
|
if max_age_hours > 8760: # 1 year max
|
|
return error_response(
|
|
error_code=ErrorCode.INVALID_INPUT,
|
|
message="max_age_hours cannot exceed 8760 (1 year)",
|
|
context={'provided_value': raw_max_age},
|
|
status_code=400
|
|
)
|
|
except (ValueError, TypeError, OverflowError):
|
|
return error_response(
|
|
error_code=ErrorCode.INVALID_INPUT,
|
|
message="max_age_hours must be a valid integer",
|
|
context={'provided_value': str(raw_max_age)},
|
|
status_code=400
|
|
)
|
|
|
|
now = _pkg.time.time()
|
|
cutoff = now if clear_all else now - max_age_hours * 3600
|
|
try:
|
|
result = _errors.request_error_clear(_errors_cache(), cutoff)
|
|
except OSError as e:
|
|
logger.error("Could not record an error clear request: %s", e)
|
|
return error_response(
|
|
error_code=ErrorCode.SYSTEM_ERROR,
|
|
message="Could not record the clear request in the shared cache",
|
|
status_code=500
|
|
)
|
|
|
|
scope = "all errors" if clear_all else f"errors older than {max_age_hours} hours"
|
|
return success_response(
|
|
data=result,
|
|
message=(f"Clear of {scope} requested; the display service applies it "
|
|
f"within about {int(_errors.SNAPSHOT_TICK_INTERVAL)} seconds")
|
|
)
|
|
except Exception as e:
|
|
logger.error(f"Error clearing old errors: {e}", exc_info=True)
|
|
return error_response(
|
|
error_code=ErrorCode.SYSTEM_ERROR,
|
|
message="Failed to clear old errors",
|
|
status_code=500
|
|
)
|
|
|
|
|
|
@api_v3.route('/integrations/mqtt-bridge', methods=['GET'])
|
|
def get_mqtt_bridge():
|
|
"""Bridge service state and its settings, minus the password."""
|
|
try:
|
|
config = _read_mqtt_bridge_config()
|
|
password = config.get('mqtt_password')
|
|
safe = {key: config.get(key, default)
|
|
for key, default in _MQTT_BRIDGE_DEFAULTS.items()}
|
|
return jsonify({
|
|
'status': 'success',
|
|
'data': {
|
|
'service': _mqtt_bridge_service_state(),
|
|
'config_exists': _MQTT_BRIDGE_CONFIG.is_file(),
|
|
'config_path': str(_MQTT_BRIDGE_CONFIG),
|
|
'config': safe,
|
|
# Enough to render "a password is set" without disclosing it.
|
|
'password_set': bool(password),
|
|
'env_override_prefix': 'LEDMATRIX_MQTT_',
|
|
}
|
|
})
|
|
except Exception as e:
|
|
logger.exception('Error reading MQTT bridge settings')
|
|
return jsonify({'status': 'error', 'message': 'Could not read bridge settings',
|
|
'details': describe_exception(e)}), 500
|
|
|
|
@api_v3.route('/integrations/mqtt-bridge/config', methods=['PUT'])
|
|
def update_mqtt_bridge_config():
|
|
"""Write bridge_config.json.
|
|
|
|
The password is write-only: omit it to leave whatever is stored alone, send
|
|
a value to replace it, or send clear_password to remove it. It is never
|
|
returned by the GET above, so a form that round-tripped it would otherwise
|
|
have to blank it on every save.
|
|
"""
|
|
try:
|
|
# No `or {}` here: get_json(silent=True) returns None for a missing or
|
|
# unparseable body, and `None or {}` produced an empty dict that then
|
|
# satisfied the isinstance check below -- so malformed JSON, `null`,
|
|
# `[]` and `false` all reported success while applying nothing.
|
|
data = request.get_json(silent=True)
|
|
if not isinstance(data, dict):
|
|
return jsonify({'status': 'error', 'message': 'Body must be a JSON object'}), 400
|
|
|
|
config = _read_mqtt_bridge_config()
|
|
existing_password = config.get('mqtt_password')
|
|
|
|
updates = {}
|
|
for key in _MQTT_BRIDGE_DEFAULTS:
|
|
if key not in data:
|
|
continue
|
|
value, err = _coerce_mqtt_bridge_value(key, data[key])
|
|
if err:
|
|
return jsonify({'status': 'error', 'message': err}), 400
|
|
updates[key] = value
|
|
|
|
config.update(updates)
|
|
|
|
# Coerced, not merely truthy: the string "false" is truthy in Python,
|
|
# so a client echoing the field back as a string would have wiped a
|
|
# stored password it meant to keep.
|
|
if _coerce_to_bool(data.get('clear_password')):
|
|
config['mqtt_password'] = None
|
|
elif 'mqtt_password' in data and str(data['mqtt_password']) != '':
|
|
new_password = str(data['mqtt_password'])
|
|
if len(new_password) > 300:
|
|
return jsonify({'status': 'error', 'message': 'Password is too long'}), 400
|
|
config['mqtt_password'] = new_password
|
|
else:
|
|
config['mqtt_password'] = existing_password
|
|
|
|
# CWE-319: a password with TLS off is sent in the clear. On a trusted
|
|
# LAN that is a normal, deliberate setup, so this is refused rather
|
|
# than forbidden -- allow_insecure_mqtt is the explicit acknowledgement.
|
|
insecure = bool(config.get('mqtt_password')) and not config.get('mqtt_tls')
|
|
if insecure and not config.get('allow_insecure_mqtt'):
|
|
return jsonify({
|
|
'status': 'error',
|
|
'message': 'MQTT credentials would cross the network in cleartext '
|
|
'with TLS disabled. Enable mqtt_tls, or set '
|
|
'allow_insecure_mqtt to accept that on a trusted network.'
|
|
}), 400
|
|
if insecure:
|
|
logger.warning('MQTT bridge: a password is set without TLS and '
|
|
'allow_insecure_mqtt is on; credentials will cross the '
|
|
'network in cleartext')
|
|
|
|
_MQTT_BRIDGE_DIR.mkdir(parents=True, exist_ok=True)
|
|
# Write via a temp file in the same directory so a crash mid-write
|
|
# cannot leave a half-written config the bridge would refuse to load.
|
|
fd, tmp_path = tempfile.mkstemp(dir=str(_MQTT_BRIDGE_DIR), prefix='.bridge_config.')
|
|
try:
|
|
with os.fdopen(fd, 'w', encoding='utf-8') as handle:
|
|
json.dump(config, handle, indent=2, sort_keys=True)
|
|
handle.write('\n')
|
|
os.chmod(tmp_path, 0o600)
|
|
os.replace(tmp_path, _MQTT_BRIDGE_CONFIG)
|
|
except Exception:
|
|
with contextlib.suppress(OSError):
|
|
os.unlink(tmp_path)
|
|
raise
|
|
|
|
service = _mqtt_bridge_service_state()
|
|
message = 'Bridge settings saved.'
|
|
if service['active']:
|
|
message += ' Restart the bridge for them to take effect.'
|
|
return jsonify({'status': 'success', 'message': message,
|
|
'data': {'password_set': bool(config.get('mqtt_password')),
|
|
'restart_required': service['active']}})
|
|
except Exception as e:
|
|
logger.exception('Error saving MQTT bridge settings')
|
|
return jsonify({'status': 'error', 'message': 'Could not save bridge settings',
|
|
'details': describe_exception(e)}), 500
|