From 5f0534ffd4af5f1a7fd14aa3ce9cd4488dcb1590 Mon Sep 17 00:00:00 2001 From: Ian Chua Date: Wed, 7 Oct 2026 16:40:25 +0800 Subject: [PATCH] fix: verify TLS hostname on Moonraker wss and apply TLS config to Snapmaker fetch --- src/slic3r/Utils/MoonrakerPrinterAgent.cpp | 5 +++++ src/slic3r/Utils/SnapmakerPrinterAgent.cpp | 19 ++++++++----------- 2 files changed, 13 insertions(+), 11 deletions(-) diff --git a/src/slic3r/Utils/MoonrakerPrinterAgent.cpp b/src/slic3r/Utils/MoonrakerPrinterAgent.cpp index eb8a595860..35ce5a33e6 100644 --- a/src/slic3r/Utils/MoonrakerPrinterAgent.cpp +++ b/src/slic3r/Utils/MoonrakerPrinterAgent.cpp @@ -21,6 +21,7 @@ #include #include #include +#include #include #include #include @@ -194,6 +195,10 @@ void MoonrakerWebsocket::tls_handshake(const std::string& host) throw std::runtime_error("Moonraker WSS: failed to set TLS server name"); } + // verify_peer only validates the chain; also require the leaf certificate to match the + // host we asked for, otherwise any cert chaining to a trusted CA is accepted. + tls_stream.set_verify_callback(net::ssl::host_name_verification(host)); + tls_stream.handshake(net::ssl::stream_base::client); } diff --git a/src/slic3r/Utils/SnapmakerPrinterAgent.cpp b/src/slic3r/Utils/SnapmakerPrinterAgent.cpp index 726eb09629..3db2520194 100644 --- a/src/slic3r/Utils/SnapmakerPrinterAgent.cpp +++ b/src/slic3r/Utils/SnapmakerPrinterAgent.cpp @@ -222,13 +222,9 @@ bool SnapmakerPrinterAgent::fetch_filament_info(std::string dev_id, FilamentSync if (sync_mode != get_filament_sync_mode()) return false; - std::string base_url; - std::string api_key; - { - std::lock_guard lock(connect_mutex); - base_url = device_info.base_url; - api_key = device_info.api_key; - } + // Snapshot everything the fetch needs (URL, api key, TLS/CA): a reconnect can rewrite + // device_info meanwhile. + const ConnectionSettings connection = get_connection_settings(); // Reserve under the same mutex shutdown() uses, so the flag and the count can't race. { @@ -239,17 +235,18 @@ bool SnapmakerPrinterAgent::fetch_filament_info(std::string dev_id, FilamentSync } InFlightGuard guard{filament_fetch_in_flight}; - std::thread([this, guard = std::move(guard), base_url, api_key]() { + std::thread([this, guard = std::move(guard), connection]() { try { - const std::string url = join_url(base_url, "/printer/objects/query?print_task_config&filament_detect"); + const std::string url = join_url(connection.base_url, "/printer/objects/query?print_task_config&filament_detect"); std::string response_body; bool success = false; std::string http_error; auto http = Http::get(url); - if (!api_key.empty()) { - http.header("X-Api-Key", api_key); + configure_http(http, connection); + if (!connection.api_key.empty()) { + http.header("X-Api-Key", connection.api_key); } http.timeout_connect(5) .timeout_max(10)