Split BambuPrinter into BambuGenericPrinter -> BambuV1Printer/BambuV2Printer
Completes the GenericPrinter -> BambuGenericPrinter -> BambuV1/V2 chain this project wanted from the start. BambuGenericPrinter holds the fields and behavior every Bambu printer shares (access code, serial number, CA trust, the TLS test/fetch methods); BambuV1Printer and BambuV2Printer each *have* one (composition) and are now genuinely separate types, ready to carry flavour-specific report-schema fields later. Also threads through a new 'sn' (serial number) field the real MQTT topics will need. Adds real 'fetch the CA automatically' capability, verified against a live TLS server (not just compiled): - BambuGenericPrinter::fetch_certificate() does trust-on-first-connect — connects once with verification disabled, captures the certificate the printer actually presents via native_tls's peer_certificate()/to_der(), and returns it as PEM. Deliberately a method you call once by hand (examples/fetch_bambu_cert.rs), not something connect() falls back to silently, since TOFU trusts whoever's on the network the moment you run it. Verified end-to-end against a local openssl s_server: the fetched PEM's SHA-256 fingerprint exactly matched the server's real certificate. - Verified the other direction too: test_bambu_certs (bundled-CA mode) correctly REJECTS that same test server's cert, since it wasn't signed by the real Bambu CA. Splitting BambuV1Printer/BambuV2Printer into distinct types broke the PrinterHandle::BambuV1(x) | PrinterHandle::BambuV2(x) or-pattern in both examples (or-patterns require every alternative to bind the same type) — fixed by giving each variant its own match arm.
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
//! Run with: cargo run --example fetch_bambu_cert -- <printer_id> <output_path>
|
||||
//!
|
||||
//! "Trust on first connect": connects to one printer from printers.toml
|
||||
//! with certificate verification disabled, captures whatever certificate
|
||||
//! it presents, and saves it as PEM. Meant for a printer like P1P that
|
||||
//! doesn't chain to the bundled CA — after running this, point that
|
||||
//! printer's `ca_cert_path` in printers.toml at the saved file and
|
||||
//! `test_bambu_certs` should report it as verified from then on.
|
||||
//!
|
||||
//! This trusts whoever answers on the network *right now* — only run it on
|
||||
//! a network you trust, ideally right after unboxing the printer.
|
||||
|
||||
use continuum_proxy::fleet;
|
||||
use continuum_proxy::printer::{GenericPrinter, PrinterHandle};
|
||||
|
||||
fn main() -> anyhow::Result<()> {
|
||||
let mut args = std::env::args().skip(1);
|
||||
let printer_id = args.next().ok_or_else(|| anyhow::anyhow!("usage: fetch_bambu_cert <printer_id> <output_path>"))?;
|
||||
let output_path = args.next().ok_or_else(|| anyhow::anyhow!("usage: fetch_bambu_cert <printer_id> <output_path>"))?;
|
||||
|
||||
let printers = fleet::load(std::path::Path::new("printers.toml"))?;
|
||||
|
||||
let pem = printers
|
||||
.iter()
|
||||
.find_map(|printer| match printer {
|
||||
PrinterHandle::BambuV1(bambu) if bambu.base().id == printer_id => Some(bambu.fetch_certificate()),
|
||||
PrinterHandle::BambuV2(bambu) if bambu.base().id == printer_id => Some(bambu.fetch_certificate()),
|
||||
_ => None,
|
||||
})
|
||||
.ok_or_else(|| anyhow::anyhow!("no Bambu printer with id '{printer_id}' in printers.toml"))??;
|
||||
|
||||
std::fs::write(&output_path, &pem)?;
|
||||
println!("saved {printer_id}'s certificate to {output_path}");
|
||||
println!("now set ca_cert_path = \"{output_path}\" for {printer_id} in printers.toml");
|
||||
|
||||
Ok(())
|
||||
}
|
||||
Reference in New Issue
Block a user