af2f20a45b
The manual fetch_bambu_cert workflow works but needs two commands and a printers.toml edit. ensure_trusted() collapses that into one call, using the same trust model SSH uses for host keys: - a pin already on disk (certs/pinned/<id>.pem) is used directly, no new trust decision is made on every run - no pin yet + bundled CA verifies fine (current-gen printers): nothing to do - no pin yet + bundled CA fails (P1P, etc.): auto-pins via trust-on-first-connect, same as fetch_bambu_cert, but automatic - an *explicit* pin (you set ca_cert_path yourself) never gets silently auto-pinned over — a failure there is a real error examples/auto_connect_bambu.rs demonstrates the one-command flow. Verified all three states against local test servers, not just compiled: first run with no pin auto-pins and connects; second run against the same server is silent (no re-TOFU message) and just verifies against the pin; third run after swapping the server's certificate correctly FAILS instead of silently re-pinning — confirms the security property survives the smoother UX.
50 lines
1.2 KiB
TOML
50 lines
1.2 KiB
TOML
[package]
|
|
name = "continuum-proxy"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
description = "Continuum edge gateway daemon — runs on-site, bridges printers to the cloud control plane"
|
|
license = "UNLICENSED"
|
|
|
|
[lib]
|
|
name = "continuum_proxy"
|
|
path = "src/lib.rs"
|
|
|
|
[[bin]]
|
|
name = "continuum-proxy"
|
|
path = "src/main.rs"
|
|
|
|
[[example]]
|
|
name = "printer_polymorphism"
|
|
path = "examples/printer_polymorphism.rs"
|
|
|
|
[[example]]
|
|
name = "test_bambu_certs"
|
|
path = "examples/test_bambu_certs.rs"
|
|
|
|
[[example]]
|
|
name = "fetch_bambu_cert"
|
|
path = "examples/fetch_bambu_cert.rs"
|
|
|
|
[[example]]
|
|
name = "auto_connect_bambu"
|
|
path = "examples/auto_connect_bambu.rs"
|
|
|
|
[dependencies]
|
|
tokio = { version = "1.40", features = ["full"] }
|
|
tokio-tungstenite = { version = "0.24", features = ["native-tls"] }
|
|
futures-util = "0.3"
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
toml = "0.8"
|
|
native-tls = "0.2"
|
|
base64 = "0.22"
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
anyhow = "1"
|
|
thiserror = "1"
|
|
dotenvy = "0.15"
|
|
|
|
# Real printer protocol clients (MQTT for Bambu, HTTP for PrusaLink/
|
|
# Moonraker, FTPS for gcode transfer) go here once you're ready to build
|
|
# past the stubs in src/printer/ — see that module's doc comment.
|