Something went wrong. Try again.
A fork of https://github.com/crosspoint-reader/crosspoint-reader
Something went wrong. Try again.
66 kB · 1991 lines
C++
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992#include "CrossPointWebServer.h"
#include <ArduinoJson.h>#include <BoardConfig.h>#include <FsHelpers.h>#include <HalGPIO.h>#include <HalStorage.h>#include <LibraryBuilder.h>#include <Logging.h>#include <WiFi.h>#include <esp_efuse.h>#include <esp_efuse_table.h>
#include <algorithm>#include <cctype>
#include "CrossPointSettings.h"#include "FontInstaller.h"#include "OpdsServerStore.h"#include "SdCardFontSystem.h"#include "SettingsList.h"#include "WebDAVHandler.h"#include "WifiCredentialStore.h"#include "html/FilesPageHtml.generated.h"#include "html/FontsPageHtml.generated.h"#include "html/HomePageHtml.generated.h"#include "html/SettingsPageHtml.generated.h"#include "html/js/jszip_minJs.generated.h"#include "util/BookCacheUtils.h"#include "util/TaskWatchdog.h"
namespace {// Folders/files to hide from the web interface file browser// Note: Items starting with "." are automatically hiddenconstexpr const char* HIDDEN_ITEMS[] = {"System Volume Information", "XTCache"};
// Formats the library index tracks (LibraryIndex isBookName): an upload of any// of these must mark the index dirty so the next Library entry rebuilds it.bool isLibraryBookFile(const String& filename) { return FsHelpers::checkFileExtension(filename, ".epub") || FsHelpers::checkFileExtension(filename, ".txt") || FsHelpers::checkFileExtension(filename, ".md") || FsHelpers::checkFileExtension(filename, ".xtc");}constexpr uint16_t UDP_PORTS[] = {54982, 48123, 39001, 44044, 59678};constexpr uint16_t LOCAL_UDP_PORT = 8134;
// Static pointer for WebSocket callback (WebSocketsServer requires C-style callback)CrossPointWebServer* wsInstance = nullptr;
// WebSocket upload stateHalFile wsUploadFile;String wsUploadFileName;String wsUploadPath;size_t wsUploadSize = 0;size_t wsUploadReceived = 0;unsigned long wsUploadStartTime = 0;bool wsUploadInProgress = false;uint8_t wsUploadClientNum = 255; // 255 = no active upload clientsize_t wsLastProgressSent = 0;String wsLastCompleteName;size_t wsLastCompleteSize = 0;unsigned long wsLastCompleteAt = 0;
String normalizeWebPath(const String& inputPath) { if (inputPath.isEmpty() || inputPath == "/") { return "/"; } std::string normalized = FsHelpers::normalisePath(inputPath.c_str()); String result = normalized.c_str(); if (result.isEmpty()) { return "/"; } if (!result.startsWith("/")) { result = "/" + result; } if (result.length() > 1 && result.endsWith("/")) { result = result.substring(0, result.length() - 1); } return result;}
bool isProtectedItemName(const String& name) { if (name.startsWith(".")) { return true; } for (const auto* item : HIDDEN_ITEMS) { if (name.equals(item)) { return true; } } return false;}
} // namespace
// File listing page template - now using generated headers:// - HomePageHtml (from html/HomePage.html)// - FilesPageHeaderHtml (from html/FilesPageHeader.html)// - FilesPageFooterHtml (from html/FilesPageFooter.html)CrossPointWebServer::CrossPointWebServer() {}
CrossPointWebServer::~CrossPointWebServer() { stop(); }
void CrossPointWebServer::begin() { if (running) { LOG_DBG("WEB", "Web server already running"); return; }
// Check if we have a valid network connection (either STA connected or AP mode) const wifi_mode_t wifiMode = WiFi.getMode(); const bool isStaConnected = (wifiMode & WIFI_MODE_STA) && (WiFi.status() == WL_CONNECTED); const bool isInApMode = (wifiMode & WIFI_MODE_AP) && (WiFi.softAPgetStationNum() >= 0); // AP is running
if (!isStaConnected && !isInApMode) { LOG_DBG("WEB", "Cannot start webserver - no valid network (mode=%d, status=%d)", wifiMode, WiFi.status()); return; }
// Store AP mode flag for later use (e.g., in handleStatus) apMode = isInApMode;
LOG_DBG("WEB", "[MEM] Free heap before begin: %d bytes", ESP.getFreeHeap()); LOG_DBG("WEB", "Network mode: %s", apMode ? "AP" : "STA");
LOG_DBG("WEB", "Creating web server on port %d...", port); server.reset(new WebServer(port));
// Disable WiFi sleep to improve responsiveness and prevent 'unreachable' errors. // This is critical for reliable web server operation on ESP32. WiFi.setSleep(false); // Default varies by ESP32 core version. The activity's loss-recovery loop // relies on driver retries during transient disconnects. WiFi.setAutoReconnect(true);
// Note: WebServer class doesn't have setNoDelay() in the standard ESP32 library. // We rely on disabling WiFi sleep for responsiveness.
LOG_DBG("WEB", "[MEM] Free heap after WebServer allocation: %d bytes", ESP.getFreeHeap());
if (!server) { LOG_ERR("WEB", "Failed to create WebServer!"); return; }
// Add Access-Control-Allow-* headers to every response so web-based clients // and PWAs on other origins can use the HTTP API. Preflight OPTIONS requests // are answered in handleNotFound(). server->enableCORS(true);
// Setup routes LOG_DBG("WEB", "Setting up routes..."); server->on("/", HTTP_GET, [this] { handleRoot(); }); server->on("/files", HTTP_GET, [this] { handleFileList(); }); server->on("/js/jszip.min.js", HTTP_GET, [this] { handleJszip(); });
server->on("/api/status", HTTP_GET, [this] { handleStatus(); }); server->on("/api/files", HTTP_GET, [this] { handleFileListData(); }); server->on("/download", HTTP_GET, [this] { handleDownload(); });
// Upload endpoint with special handling for multipart form data server->on("/upload", HTTP_POST, [this] { handleUploadPost(upload); }, [this] { handleUpload(upload); });
// Create folder endpoint server->on("/mkdir", HTTP_POST, [this] { handleCreateFolder(); });
// Rename file endpoint server->on("/rename", HTTP_POST, [this] { handleRename(); });
// Move file endpoint server->on("/move", HTTP_POST, [this] { handleMove(); });
// Delete file/folder endpoint server->on("/delete", HTTP_POST, [this] { handleDelete(); });
// Settings endpoints server->on("/settings", HTTP_GET, [this] { handleSettingsPage(); }); server->on("/api/settings", HTTP_GET, [this] { handleGetSettings(); }); server->on("/api/settings", HTTP_POST, [this] { handlePostSettings(); });
// Font management endpoints server->on("/fonts", HTTP_GET, [this] { handleFontsPage(); }); server->on("/api/fonts", HTTP_GET, [this] { handleFontList(); }); server->on("/api/fonts/upload", HTTP_POST, [this] { handleFontUpload(); }, [this] { handleFontUploadData(); }); server->on("/api/fonts/delete", HTTP_POST, [this] { handleFontDelete(); });
// OPDS server endpoints server->on("/api/opds", HTTP_GET, [this] { handleGetOpdsServers(); }); server->on("/api/opds", HTTP_POST, [this] { handlePostOpdsServer(); }); server->on("/api/opds/delete", HTTP_POST, [this] { handleDeleteOpdsServer(); });
// Wi-Fi credential endpoints server->on("/api/wifi", HTTP_GET, [this] { handleGetWifiNetworks(); }); server->on("/api/wifi", HTTP_POST, [this] { handlePostWifiNetwork(); }); server->on("/api/wifi/delete", HTTP_POST, [this] { handleDeleteWifiNetwork(); });
server->onNotFound([this] { handleNotFound(); }); LOG_DBG("WEB", "[MEM] Free heap after route setup: %d bytes", ESP.getFreeHeap());
// Collect WebDAV headers and register handler // If-None-Match is collected so the static-page handlers can answer conditional GETs with 304 const char* collectedHeaders[] = {"Depth", "Destination", "Overwrite", "If", "Lock-Token", "Timeout", "If-None-Match"}; server->collectHeaders(collectedHeaders, 7); server->addHandler(new WebDAVHandler()); // Note: WebDAVHandler will be deleted by WebServer when server is stopped LOG_DBG("WEB", "WebDAV handler initialized");
server->begin();
// Start WebSocket server for fast binary uploads LOG_DBG("WEB", "Starting WebSocket server on port %d...", wsPort); wsServer.reset(new WebSocketsServer(wsPort)); wsInstance = const_cast<CrossPointWebServer*>(this); wsServer->begin(); wsServer->onEvent(wsEventCallback); LOG_DBG("WEB", "WebSocket server started");
udpActive = udp.begin(LOCAL_UDP_PORT); LOG_DBG("WEB", "Discovery UDP %s on port %d", udpActive ? "enabled" : "failed", LOCAL_UDP_PORT);
// Do not subscribe the serving task to the task watchdog. Arduino WebServer // permits five-second client and ACK waits, which can consume the entire // default watchdog window on a weak connection. The interrupt watchdog still // catches hard CPU lockups, matching the rest of the application lifecycle.
running = true;
LOG_DBG("WEB", "Web server started on port %d", port); // Show the correct IP based on network mode const String ipAddr = apMode ? WiFi.softAPIP().toString() : WiFi.localIP().toString(); LOG_DBG("WEB", "Access at http://%s/", ipAddr.c_str()); LOG_DBG("WEB", "WebSocket at ws://%s:%d/", ipAddr.c_str(), wsPort); LOG_DBG("WEB", "[MEM] Free heap after server.begin(): %d bytes", ESP.getFreeHeap());}
void CrossPointWebServer::abortWsUpload(const char* tag) { // Explicit close() required: file-scope global persists beyond function scope wsUploadFile.close(); String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName; if (Storage.remove(filePath.c_str())) { LOG_DBG(tag, "Deleted incomplete upload: %s", filePath.c_str()); } else { LOG_DBG(tag, "Failed to delete incomplete upload: %s", filePath.c_str()); } wsUploadInProgress = false; wsUploadClientNum = 255; wsLastProgressSent = 0;}
void CrossPointWebServer::stop() { if (!running || !server) { LOG_DBG("WEB", "stop() called but already stopped (running=%d, server=%p)", running, server.get()); return; }
LOG_DBG("WEB", "STOP INITIATED - setting running=false first"); running = false; // Set this FIRST to prevent handleClient from using server
LOG_DBG("WEB", "[MEM] Free heap before stop: %d bytes", ESP.getFreeHeap());
// Close any in-progress WebSocket upload and remove partial file if (wsUploadInProgress && wsUploadFile) { abortWsUpload("WEB"); }
// Stop WebSocket server if (wsServer) { LOG_DBG("WEB", "Stopping WebSocket server..."); wsServer->close(); wsServer.reset(); wsInstance = nullptr; LOG_DBG("WEB", "WebSocket server stopped"); }
if (udpActive) { udp.stop(); udpActive = false; }
// Brief delay to allow any in-flight handleClient() calls to complete delay(20);
server->stop(); LOG_DBG("WEB", "[MEM] Free heap after server->stop(): %d bytes", ESP.getFreeHeap());
// Brief delay before deletion delay(10);
server.reset(); LOG_DBG("WEB", "Web server stopped and deleted"); LOG_DBG("WEB", "[MEM] Free heap after delete server: %d bytes", ESP.getFreeHeap());
// Note: Static upload variables (uploadFileName, uploadPath, uploadError) are declared // later in the file and will be cleared when they go out of scope or on next upload LOG_DBG("WEB", "[MEM] Free heap final: %d bytes", ESP.getFreeHeap());}
void CrossPointWebServer::handleClient() { static unsigned long lastDebugPrint = 0;
// Check running flag FIRST before accessing server if (!running) { return; }
// Double-check server pointer is valid if (!server) { LOG_DBG("WEB", "WARNING: handleClient called with null server!"); return; }
// Print debug every 10 seconds to confirm handleClient is being called if (millis() - lastDebugPrint > 10000) { LOG_DBG("WEB", "handleClient active, server running on port %d", port); lastDebugPrint = millis(); }
server->handleClient();
// Handle WebSocket events if (wsServer) { wsServer->loop(); }
// Respond to discovery broadcasts if (udpActive) { int packetSize = udp.parsePacket(); if (packetSize > 0) { char buffer[16]; int len = udp.read(buffer, sizeof(buffer) - 1); if (len > 0) { buffer[len] = '\0'; if (strcmp(buffer, "hello") == 0) { String hostname = WiFi.getHostname(); if (hostname.isEmpty()) { hostname = "crosspoint"; } String message = "crosspoint (on " + hostname + ");" + String(wsPort); udp.beginPacket(udp.remoteIP(), udp.remotePort()); udp.write(reinterpret_cast<const uint8_t*>(message.c_str()), message.length()); udp.endPacket(); } } } }}
CrossPointWebServer::WsUploadStatus CrossPointWebServer::getWsUploadStatus() const { WsUploadStatus status; status.inProgress = wsUploadInProgress; status.received = wsUploadReceived; status.total = wsUploadSize; status.filename = wsUploadFileName.c_str(); status.lastCompleteName = wsLastCompleteName.c_str(); status.lastCompleteSize = wsLastCompleteSize; status.lastCompleteAt = wsLastCompleteAt; return status;}
static void sendStaticContent(WebServer* server, const char* data, size_t len, const char* etag, const char* contentType) { // Content is baked into flash at build time, so the ETag is stable for the // lifetime of a firmware image. Honor If-None-Match with a 304 so browsers // reuse their cache instead of re-downloading on every navigation. if (server->header("If-None-Match") == etag) { server->sendHeader("ETag", etag); server->sendHeader("Cache-Control", "no-cache"); server->send(304); return; } server->sendHeader("Content-Encoding", "gzip"); server->sendHeader("ETag", etag); // no-cache: the browser may cache, but must revalidate (conditional GET) // before reuse — this is what unlocks 304 responses. server->sendHeader("Cache-Control", "no-cache"); server->send_P(200, contentType, data, len);}
void CrossPointWebServer::handleRoot() const { sendStaticContent(server.get(), HomePageHtml, sizeof(HomePageHtml), HomePageHtmlETag, "text/html"); LOG_DBG("WEB", "Served root page");}
void CrossPointWebServer::handleJszip() const { sendStaticContent(server.get(), jszip_minJs, jszip_minJsCompressedSize, jszip_minJsETag, "application/javascript"); LOG_DBG("WEB", "Served jszip.min.js");}
void CrossPointWebServer::handleNotFound() const { // CORS preflight: routes are registered per-method, so OPTIONS requests land // here. The Access-Control-Allow-* headers are added by enableCORS(). if (server->method() == HTTP_OPTIONS) { server->send(204, "text/plain", ""); return; }
// in AP mode, redirect unmatched browser/captive-portal requests to "/" so the OS auto-opens the browser // API requests (/api/*) still return 404 so XHR errors surface correctly // see https://en.wikipedia.org/wiki/Captive_portal#Detection if (apMode && !server->uri().startsWith("/api/")) { server->sendHeader("Location", "/", true); server->send(302, "text/plain", ""); return; }
String message = "404 Not Found\n\n"; message += "URI: " + server->uri() + "\n"; server->send(404, "text/plain", message);}
void CrossPointWebServer::handleStatus() const { // Get correct IP based on AP vs STA mode const String ipAddr = apMode ? WiFi.softAPIP().toString() : WiFi.localIP().toString();
JsonDocument doc; doc["version"] = CROSSPOINT_VERSION; doc["ip"] = ipAddr; doc["mode"] = apMode ? "AP" : "STA"; doc["rssi"] = apMode ? 0 : WiFi.RSSI(); doc["freeHeap"] = ESP.getFreeHeap(); doc["uptime"] = millis() / 1000;#if FREEINK_DEVICE_X4 || FREEINK_DEVICE_X3 doc["device"] = gpio.deviceIsX3() ? "X3" : "X4";#else doc["device"] = BoardConfig::ACTIVE.name;#endif
char snBuf[33] = {0}; bool valid = false;#if !CONFIG_IDF_TARGET_ESP32 // Classic ESP32's efuse table has no USER_DATA block (C3/S3 only) if (esp_efuse_read_field_blob(ESP_EFUSE_USER_DATA, snBuf, 256) == ESP_OK) { valid = snBuf[0] != '\0' && snBuf[0] != (char)0xFF; for (int i = 0; i < 32 && snBuf[i] != '\0'; i++) { if (!std::isprint(static_cast<unsigned char>(snBuf[i]))) { valid = false; break; } } }#endif
if (valid) { doc["serial"] = snBuf; } else { doc["serial"] = "Not found"; }
String response; serializeJson(doc, response); server->send(200, "application/json", response);}
void CrossPointWebServer::scanFiles(const char* path, const std::function<void(FileInfo)>& callback) const { HalFile root = Storage.open(path); if (!root) { LOG_DBG("WEB", "Failed to open directory: %s", path); return; }
if (!root.isDirectory()) { LOG_DBG("WEB", "Not a directory: %s", path); root.close(); return; }
LOG_DBG("WEB", "Scanning files in: %s", path);
HalFile file = root.openNextFile(); char name[500]; while (file) { file.getName(name, sizeof(name)); auto fileName = String(name);
// Skip hidden items (starting with ".") bool shouldHide = !SETTINGS.showHiddenFiles && fileName.startsWith(".");
// Check against explicitly hidden items list if (!shouldHide) { for (const auto* item : HIDDEN_ITEMS) { if (fileName.equals(item)) { shouldHide = true; break; } } }
if (!shouldHide) { FileInfo info; info.name = fileName; info.isDirectory = file.isDirectory();
if (info.isDirectory) { info.size = 0; info.isEpub = false; } else { info.size = file.size(); info.isEpub = isEpubFile(info.name); }
callback(info); }
file.close(); yield(); // Yield to allow WiFi and other tasks to process during long scans resetTaskWatchdogIfSubscribed(); // Reset watchdog to prevent timeout on large directories file = root.openNextFile(); } root.close();}
bool CrossPointWebServer::isEpubFile(const String& filename) const { return FsHelpers::hasEpubExtension(filename); }
void CrossPointWebServer::handleFileList() const { sendStaticContent(server.get(), FilesPageHtml, sizeof(FilesPageHtml), FilesPageHtmlETag, "text/html");}
void CrossPointWebServer::handleFileListData() const { // Get current path from query string (default to root) String currentPath = "/"; if (server->hasArg("path")) { currentPath = normalizeWebPath(server->arg("path")); }
server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("["); char output[512]; constexpr size_t outputSize = sizeof(output); bool seenFirst = false; JsonDocument doc;
scanFiles(currentPath.c_str(), [this, &output, &doc, seenFirst](const FileInfo& info) mutable { doc.clear(); doc["name"] = info.name; doc["size"] = info.size; doc["isDirectory"] = info.isDirectory; doc["isEpub"] = info.isEpub;
const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) { // JSON output truncated; skip this entry to avoid sending malformed JSON LOG_DBG("WEB", "Skipping file entry with oversized JSON for name: %s", info.name.c_str()); return; }
if (seenFirst) { server->sendContent(","); } else { seenFirst = true; } server->sendContent(output); }); server->sendContent("]"); // End of streamed response, empty chunk to signal client server->sendContent(""); LOG_DBG("WEB", "Served file listing page for path: %s", currentPath.c_str());}
void CrossPointWebServer::handleDownload() const { if (!server->hasArg("path")) { server->send(400, "text/plain", "Missing path"); return; }
String itemPath = normalizeWebPath(server->arg("path")); if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; }
const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (itemName.startsWith(".")) { server->send(403, "text/plain", "Cannot access system files"); return; } for (const auto* item : HIDDEN_ITEMS) { if (itemName.equals(item)) { server->send(403, "text/plain", "Cannot access protected items"); return; } }
if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; }
HalFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } if (file.isDirectory()) { file.close(); server->send(400, "text/plain", "Path is a directory"); return; }
String contentType = "application/octet-stream"; if (isEpubFile(itemPath)) { contentType = "application/epub+zip"; }
char nameBuf[128] = {0}; String filename = "download"; if (file.getName(nameBuf, sizeof(nameBuf))) { filename = nameBuf; }
server->setContentLength(file.size()); server->sendHeader("Content-Disposition", "attachment; filename=\"" + filename + "\""); server->send(200, contentType.c_str(), "");
NetworkClient client = server->client(); const size_t chunkSize = 4096; uint8_t buffer[chunkSize];
bool downloadOk = true; while (downloadOk && file.available()) { int result = file.read(buffer, chunkSize); if (result <= 0) break; size_t bytesRead = static_cast<size_t>(result); size_t totalWritten = 0; while (totalWritten < bytesRead) { resetTaskWatchdogIfSubscribed(); size_t wrote = client.write(buffer + totalWritten, bytesRead - totalWritten); if (wrote == 0) { downloadOk = false; break; } totalWritten += wrote; } } client.clear(); file.close();}
// Diagnostic counters for upload performance analysisstatic unsigned long uploadStartTime = 0;static unsigned long totalWriteTime = 0;static size_t writeCount = 0;
static bool flushUploadBuffer(CrossPointWebServer::UploadState& state) { if (state.bufferPos > 0 && state.file) { resetTaskWatchdogIfSubscribed(); // Reset watchdog before potentially slow SD write const unsigned long writeStart = millis(); const size_t written = state.file.write(state.buffer.data(), state.bufferPos); totalWriteTime += millis() - writeStart; writeCount++; resetTaskWatchdogIfSubscribed(); // Reset watchdog after SD write
if (written != state.bufferPos) { LOG_DBG("WEB", "[UPLOAD] Buffer flush failed: expected %d, wrote %d", state.bufferPos, written); state.bufferPos = 0; return false; } state.bufferPos = 0; } return true;}
void CrossPointWebServer::handleUpload(UploadState& state) const { static size_t lastLoggedSize = 0;
// Reset watchdog at start of every upload callback - HTTP parsing can be slow resetTaskWatchdogIfSubscribed();
// Safety check: ensure server is still valid if (!running || !server) { LOG_DBG("WEB", "[UPLOAD] ERROR: handleUpload called but server not running!"); return; }
const HTTPUpload& upload = server->upload();
if (upload.status == UPLOAD_FILE_START) { // Reset watchdog - this is the critical 1% crash point resetTaskWatchdogIfSubscribed();
state.fileName = upload.filename; state.size = 0; state.success = false; state.error = ""; uploadStartTime = millis(); lastLoggedSize = 0; state.bufferPos = 0; totalWriteTime = 0; writeCount = 0;
if (!FsHelpers::isSafePathComponent(state.fileName)) { state.error = "Invalid file name"; LOG_DBG("WEB", "[UPLOAD] Rejected unsafe filename: %s", state.fileName.c_str()); return; }
// Get upload path from query parameter (defaults to root if not specified) // Note: We use query parameter instead of form data because multipart form // fields aren't available until after file upload completes if (server->hasArg("path")) { state.path = normalizeWebPath(server->arg("path")); } else { state.path = "/"; }
LOG_DBG("WEB", "[UPLOAD] START: %s to path: %s", state.fileName.c_str(), state.path.c_str()); LOG_DBG("WEB", "[UPLOAD] Free heap: %d bytes", ESP.getFreeHeap());
String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName;
// Check if file already exists - SD operations can be slow resetTaskWatchdogIfSubscribed(); if (Storage.exists(filePath.c_str())) { state.error = "File already exists: " + state.fileName; LOG_DBG("WEB", "[UPLOAD] Collision: %s", filePath.c_str()); return; }
// Open file for writing - this can be slow due to FAT cluster allocation resetTaskWatchdogIfSubscribed(); if (!Storage.openFileForWrite("WEB", filePath, state.file)) { state.error = "Failed to create file on SD card"; LOG_DBG("WEB", "[UPLOAD] FAILED to create file: %s", filePath.c_str()); return; } resetTaskWatchdogIfSubscribed();
LOG_DBG("WEB", "[UPLOAD] File created successfully: %s", filePath.c_str()); } else if (upload.status == UPLOAD_FILE_WRITE) { if (state.file && state.error.isEmpty()) { // Buffer incoming data and flush when buffer is full // This reduces SD card write operations and improves throughput const uint8_t* data = upload.buf; size_t remaining = upload.currentSize;
while (remaining > 0) { const size_t space = UploadState::UPLOAD_BUFFER_SIZE - state.bufferPos; const size_t toCopy = (remaining < space) ? remaining : space;
memcpy(state.buffer.data() + state.bufferPos, data, toCopy); state.bufferPos += toCopy; data += toCopy; remaining -= toCopy;
// Flush buffer when full if (state.bufferPos >= UploadState::UPLOAD_BUFFER_SIZE) { if (!flushUploadBuffer(state)) { state.error = "Failed to write to SD card - disk may be full"; state.file.close(); return; } } }
state.size += upload.currentSize;
// Log progress every 100KB if (state.size - lastLoggedSize >= 102400) { const unsigned long elapsed = millis() - uploadStartTime; const float kbps = (elapsed > 0) ? (state.size / 1024.0) / (elapsed / 1000.0) : 0; LOG_DBG("WEB", "[UPLOAD] %d bytes (%.1f KB), %.1f KB/s, %d writes", state.size, state.size / 1024.0, kbps, writeCount); lastLoggedSize = state.size; } } } else if (upload.status == UPLOAD_FILE_END) { if (state.file) { // Flush any remaining buffered data if (!flushUploadBuffer(state)) { state.error = "Failed to write final data to SD card"; } state.file.close();
if (state.error.isEmpty()) { state.success = true; const unsigned long elapsed = millis() - uploadStartTime; const float avgKbps = (elapsed > 0) ? (state.size / 1024.0) / (elapsed / 1000.0) : 0; const float writePercent = (elapsed > 0) ? (totalWriteTime * 100.0 / elapsed) : 0; LOG_DBG("WEB", "[UPLOAD] Complete: %s (%d bytes in %lu ms, avg %.1f KB/s)", state.fileName.c_str(), state.size, elapsed, avgKbps); LOG_DBG("WEB", "[UPLOAD] Diagnostics: %d writes, total write time: %lu ms (%.1f%%)", writeCount, totalWriteTime, writePercent);
// Clear epub cache after uploading the file String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName; clearBookCache(filePath.c_str()); if (isLibraryBookFile(state.fileName)) library::markLibraryIndexDirty(); } } } else if (upload.status == UPLOAD_FILE_ABORTED) { state.bufferPos = 0; // Discard buffered data if (state.file) { state.file.close(); // Try to delete the incomplete file String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName; Storage.remove(filePath.c_str()); } state.error = "Upload aborted"; LOG_DBG("WEB", "Upload aborted"); }}
void CrossPointWebServer::handleUploadPost(UploadState& state) const { if (state.success) { server->send(200, "text/plain", "File uploaded successfully: " + state.fileName); } else { const String error = state.error.isEmpty() ? "Unknown error during upload" : state.error; server->send(400, "text/plain", error); }}
void CrossPointWebServer::handleCreateFolder() const { // Get folder name from form data if (!server->hasArg("name")) { server->send(400, "text/plain", "Missing folder name"); return; }
const String folderName = server->arg("name");
// Validate folder name if (folderName.isEmpty()) { server->send(400, "text/plain", "Folder name cannot be empty"); return; } if (!FsHelpers::isSafePathComponent(folderName)) { LOG_DBG("WEB", "Rejected unsafe folder name: %s", folderName.c_str()); server->send(400, "text/plain", "Invalid folder name"); return; } if (isProtectedItemName(folderName)) { LOG_DBG("WEB", "Rejected protected folder name: %s", folderName.c_str()); server->send(403, "text/plain", "Cannot create protected item"); return; }
// Get parent path String parentPath = "/"; if (server->hasArg("path")) { parentPath = normalizeWebPath(server->arg("path")); }
// Build full folder path String folderPath = parentPath; if (!folderPath.endsWith("/")) folderPath += "/"; folderPath += folderName;
LOG_DBG("WEB", "Creating folder: %s", folderPath.c_str());
// Check if already exists if (Storage.exists(folderPath.c_str())) { server->send(400, "text/plain", "Folder already exists"); return; }
// Create the folder if (Storage.mkdir(folderPath.c_str())) { LOG_DBG("WEB", "Folder created successfully: %s", folderPath.c_str()); server->send(200, "text/plain", "Folder created: " + folderName); } else { LOG_DBG("WEB", "Failed to create folder: %s", folderPath.c_str()); server->send(500, "text/plain", "Failed to create folder"); }}
void CrossPointWebServer::handleRename() const { if (!server->hasArg("path") || !server->hasArg("name")) { server->send(400, "text/plain", "Missing path or new name"); return; }
String itemPath = normalizeWebPath(server->arg("path")); String newName = server->arg("name"); newName.trim();
if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; } if (newName.isEmpty()) { server->send(400, "text/plain", "New name cannot be empty"); return; } if (newName.indexOf('/') >= 0 || newName.indexOf('\\') >= 0) { server->send(400, "text/plain", "Invalid file name"); return; } if (isProtectedItemName(newName)) { server->send(403, "text/plain", "Cannot rename to protected name"); return; }
const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (isProtectedItemName(itemName)) { server->send(403, "text/plain", "Cannot rename protected item"); return; } if (newName == itemName) { server->send(200, "text/plain", "Name unchanged"); return; }
if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; }
HalFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } if (file.isDirectory()) { file.close(); server->send(400, "text/plain", "Only files can be renamed"); return; }
String parentPath = itemPath.substring(0, itemPath.lastIndexOf('/')); if (parentPath.isEmpty()) { parentPath = "/"; } String newPath = parentPath; if (!newPath.endsWith("/")) { newPath += "/"; } newPath += newName;
if (Storage.exists(newPath.c_str())) { file.close(); server->send(409, "text/plain", "Target already exists"); return; }
clearBookCache(itemPath.c_str()); const bool success = file.rename(newPath.c_str()); file.close();
if (success) { LOG_DBG("WEB", "Renamed file: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(200, "text/plain", "Renamed successfully"); } else { LOG_ERR("WEB", "Failed to rename file: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(500, "text/plain", "Failed to rename file"); }}
void CrossPointWebServer::handleMove() const { if (!server->hasArg("path") || !server->hasArg("dest")) { server->send(400, "text/plain", "Missing path or destination"); return; }
String itemPath = normalizeWebPath(server->arg("path")); String destPath = normalizeWebPath(server->arg("dest"));
if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; } if (destPath.isEmpty()) { server->send(400, "text/plain", "Invalid destination"); return; }
const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (isProtectedItemName(itemName)) { server->send(403, "text/plain", "Cannot move protected item"); return; } if (destPath != "/") { const String destName = destPath.substring(destPath.lastIndexOf('/') + 1); if (isProtectedItemName(destName)) { server->send(403, "text/plain", "Cannot move into protected folder"); return; } }
if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; }
HalFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } if (file.isDirectory()) { file.close(); server->send(400, "text/plain", "Only files can be moved"); return; }
if (!Storage.exists(destPath.c_str())) { file.close(); server->send(404, "text/plain", "Destination not found"); return; } HalFile destDir = Storage.open(destPath.c_str()); if (!destDir || !destDir.isDirectory()) { if (destDir) { destDir.close(); } file.close(); server->send(400, "text/plain", "Destination is not a folder"); return; } destDir.close();
String newPath = destPath; if (!newPath.endsWith("/")) { newPath += "/"; } newPath += itemName;
if (newPath == itemPath) { file.close(); server->send(200, "text/plain", "Already in destination"); return; } if (Storage.exists(newPath.c_str())) { file.close(); server->send(409, "text/plain", "Target already exists"); return; }
clearBookCache(itemPath.c_str()); const bool success = file.rename(newPath.c_str()); file.close();
if (success) { LOG_DBG("WEB", "Moved file: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(200, "text/plain", "Moved successfully"); } else { LOG_ERR("WEB", "Failed to move file: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(500, "text/plain", "Failed to move file"); }}
void CrossPointWebServer::handleDelete() const { // To ensure backwards compatibility, plain `path` is mapped // to a single element JSON array. bool hasPathArg = server->hasArg("path"); bool hasPathsArg = server->hasArg("paths"); // Check 'paths' or `path` argument is provided if (!(hasPathArg || hasPathsArg)) { server->send(400, "text/plain", "Missing `path` or `paths` argument"); return; } if (hasPathArg && hasPathsArg) { server->send(400, "text/plain", "Provide either 'path' or 'paths', not both"); return; }
// Parse paths String pathsArg; JsonDocument doc; DeserializationError error = DeserializationError(DeserializationError::Code::Ok); if (hasPathsArg) { pathsArg = server->arg("paths"); error = deserializeJson(doc, pathsArg); } else { pathsArg = server->arg("path"); doc.add(pathsArg); } if (error) { server->send(400, "text/plain", "Invalid paths format"); return; }
auto paths = doc.as<JsonArray>(); if (paths.isNull() || paths.size() == 0) { server->send(400, "text/plain", "No paths provided"); return; }
// Iterate over paths and delete each item bool allSuccess = true; String failedItems;
for (const auto& p : paths) { auto itemPath = normalizeWebPath(p.as<String>());
// Validate path if (itemPath.isEmpty() || itemPath == "/") { failedItems += itemPath + " (cannot delete root); "; allSuccess = false; continue; }
// Security check: prevent deletion of protected items const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1);
// Hidden/system files are protected if (itemName.startsWith(".")) { failedItems += itemPath + " (hidden/system file); "; allSuccess = false; continue; }
// Check against explicitly protected items bool isProtected = false; for (const auto* item : HIDDEN_ITEMS) { if (itemName.equals(item)) { isProtected = true; break; } } if (isProtected) { failedItems += itemPath + " (protected file); "; allSuccess = false; continue; }
// Check if item exists if (!Storage.exists(itemPath.c_str())) { failedItems += itemPath + " (not found); "; allSuccess = false; continue; }
// Decide whether it's a directory or file by opening it bool success = false; HalFile f = Storage.open(itemPath.c_str()); if (f && f.isDirectory()) { // For folders, ensure empty before removing HalFile entry = f.openNextFile(); if (entry) { entry.close(); f.close(); failedItems += itemPath + " (folder not empty); "; allSuccess = false; continue; } f.close(); success = Storage.rmdir(itemPath.c_str()); } else { // It's a file (or couldn't open as dir) — remove file if (f) f.close(); success = Storage.remove(itemPath.c_str()); clearBookCache(itemPath.c_str()); }
if (!success) { failedItems += itemPath + " (deletion failed); "; allSuccess = false; } }
if (allSuccess) { server->send(200, "text/plain", "All items deleted successfully"); } else { server->send(500, "text/plain", "Failed to delete some items: " + failedItems); }}
void CrossPointWebServer::handleSettingsPage() const { sendStaticContent(server.get(), SettingsPageHtml, sizeof(SettingsPageHtml), SettingsPageHtmlETag, "text/html"); LOG_DBG("WEB", "Served settings page");}
void CrossPointWebServer::handleGetSettings() const { // Pass the SD font registry so the fontFamily setting's enumStringValues // includes SD-resident families — otherwise the web API only exposes the // three built-in fonts. const auto& settings = getSettingsList(&sdFontSystem.registry());
server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("[");
char output[512]; constexpr size_t outputSize = sizeof(output); bool seenFirst = false; JsonDocument doc;
for (const auto& s : settings) { if (!s.key) continue; // Skip ACTION-only entries
doc.clear(); doc["key"] = s.key; doc["name"] = I18N.get(s.nameId); doc["category"] = I18N.get(s.category);
switch (s.type) { case SettingType::TOGGLE: { doc["type"] = "toggle"; if (s.valuePtr) { doc["value"] = static_cast<int>(SETTINGS.*(s.valuePtr)); } break; } case SettingType::ENUM: { doc["type"] = "enum"; if (s.valuePtr) { doc["value"] = static_cast<int>(SETTINGS.*(s.valuePtr)); } else if (s.valueGetter) { doc["value"] = static_cast<int>(s.valueGetter()); } JsonArray options = doc["options"].to<JsonArray>(); if (!s.enumStringValues.empty()) { for (const auto& opt : s.enumStringValues) { options.add(opt); } } else { for (const auto& opt : s.enumLabels()) { options.add(I18N.get(opt)); } } break; } case SettingType::VALUE: { doc["type"] = "value"; if (s.valuePtr) { doc["value"] = static_cast<int>(SETTINGS.*(s.valuePtr)); } doc["min"] = s.valueRange.min; doc["max"] = s.valueRange.max; doc["step"] = s.valueRange.step; break; } case SettingType::STRING: { doc["type"] = "string"; if (s.stringGetter) { doc["value"] = s.stringGetter(); } else if (s.stringMaxLen > 0) { doc["value"] = reinterpret_cast<const char*>(&SETTINGS) + s.stringOffset; } break; } default: continue; }
const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) { LOG_DBG("WEB", "Skipping oversized setting JSON for: %s", s.key); continue; }
if (seenFirst) { server->sendContent(","); } else { seenFirst = true; } server->sendContent(output); yield(); // Yield to allow WiFi and other tasks to process during a slow send resetTaskWatchdogIfSubscribed(); // Reset watchdog: each sendContent() is a blocking network write }
server->sendContent("]"); server->sendContent(""); LOG_DBG("WEB", "Served settings API");}
void CrossPointWebServer::handlePostSettings() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; }
const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; }
const auto& settings = getSettingsList(&sdFontSystem.registry()); int applied = 0;
for (const auto& s : settings) { if (!s.key) continue; if (!doc[s.key].is<JsonVariant>()) continue;
switch (s.type) { case SettingType::TOGGLE: { const int val = doc[s.key].as<int>() ? 1 : 0; if (s.valuePtr) { SETTINGS.*(s.valuePtr) = val; } applied++; break; } case SettingType::ENUM: { const int val = doc[s.key].as<int>(); const int maxVal = s.enumStringValues.empty() ? static_cast<int>(s.enumLabels().size()) : static_cast<int>(s.enumStringValues.size()); if (val >= 0 && val < maxVal) { if (s.valuePtr) { SETTINGS.*(s.valuePtr) = static_cast<uint8_t>(val); } else if (s.valueSetter) { s.valueSetter(static_cast<uint8_t>(val)); } applied++; } break; } case SettingType::VALUE: { const int val = doc[s.key].as<int>(); if (val >= s.valueRange.min && val <= s.valueRange.max) { if (s.valuePtr) { SETTINGS.*(s.valuePtr) = static_cast<uint8_t>(val); } applied++; } break; } case SettingType::STRING: { const std::string val = doc[s.key].as<std::string>(); if (s.stringSetter) { s.stringSetter(val); } else if (s.stringMaxLen > 0) { char* ptr = reinterpret_cast<char*>(&SETTINGS) + s.stringOffset; strncpy(ptr, val.c_str(), s.stringMaxLen - 1); ptr[s.stringMaxLen - 1] = '\0'; } applied++; break; } default: break; } }
SETTINGS.saveToFile();
LOG_DBG("WEB", "Applied %d setting(s)", applied); server->send(200, "text/plain", String("Applied ") + String(applied) + " setting(s)");}
// ---- OPDS Server API ----
void CrossPointWebServer::handleGetOpdsServers() const { const auto& servers = OPDS_STORE.getServers();
// Stream JSON array incrementally to avoid allocating the full response in memory server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("[");
char output[512]; constexpr size_t outputSize = sizeof(output); JsonDocument doc;
for (size_t i = 0; i < servers.size(); i++) { doc.clear(); doc["index"] = i; doc["name"] = servers[i].name; doc["url"] = servers[i].url; doc["username"] = servers[i].username; // Never expose passwords over the API — only indicate whether one is set doc["hasPassword"] = !servers[i].password.empty();
const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) continue;
if (i > 0) server->sendContent(","); server->sendContent(output); yield(); // Yield to allow WiFi and other tasks to process during a slow send resetTaskWatchdogIfSubscribed(); // Reset watchdog: each sendContent() is a blocking network write }
server->sendContent("]"); server->sendContent(""); LOG_DBG("WEB", "Served OPDS servers API (%zu servers)", servers.size());}
void CrossPointWebServer::handlePostOpdsServer() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; }
const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; }
OpdsServer opdsServer; opdsServer.name = doc["name"] | std::string(""); opdsServer.url = doc["url"] | std::string(""); opdsServer.username = doc["username"] | std::string("");
// The password field is optional in the JSON payload. When absent (vs. present but empty), // we preserve the existing password — the web UI omits it when the user hasn't changed it. bool hasPasswordField = doc["password"].is<const char*>() || doc["password"].is<std::string>(); std::string password = doc["password"] | std::string("");
if (doc["index"].is<int>()) { int idx = doc["index"].as<int>(); if (idx < 0 || idx >= static_cast<int>(OPDS_STORE.getCount())) { server->send(400, "text/plain", "Invalid server index"); return; } // Preserve existing password if not explicitly provided if (!hasPasswordField) { const auto* existing = OPDS_STORE.getServer(static_cast<size_t>(idx)); if (existing) password = existing->password; } opdsServer.password = password; OPDS_STORE.updateServer(static_cast<size_t>(idx), opdsServer); LOG_DBG("WEB", "Updated OPDS server at index %d", idx); } else { opdsServer.password = password; if (!OPDS_STORE.addServer(opdsServer)) { server->send(400, "text/plain", "Cannot add server (limit reached)"); return; } LOG_DBG("WEB", "Added new OPDS server: %s", opdsServer.name.c_str()); }
server->send(200, "text/plain", "OK");}
// Uses POST (not HTTP DELETE) because ESP32 WebServer doesn't support DELETE with body.void CrossPointWebServer::handleDeleteOpdsServer() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; }
const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; }
if (!doc["index"].is<int>()) { server->send(400, "text/plain", "Missing index"); return; }
int idx = doc["index"].as<int>(); if (idx < 0 || idx >= static_cast<int>(OPDS_STORE.getCount())) { server->send(400, "text/plain", "Invalid server index"); return; }
OPDS_STORE.removeServer(static_cast<size_t>(idx)); LOG_DBG("WEB", "Deleted OPDS server at index %d", idx); server->send(200, "text/plain", "OK");}
// ---- Wi-Fi Credentials API ----
void CrossPointWebServer::handleGetWifiNetworks() const { const auto credentials = WIFI_STORE.getCredentialSummaries();
// Stream JSON array incrementally to avoid allocating the full response in memory server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("[");
char output[320]; constexpr size_t outputSize = sizeof(output); JsonDocument doc;
for (size_t i = 0; i < credentials.size(); i++) { doc.clear(); doc["index"] = i; doc["ssid"] = credentials[i].ssid; // Never expose Wi-Fi passwords over the API — only indicate whether one is set doc["hasPassword"] = credentials[i].hasPassword; doc["isLastConnected"] = credentials[i].isLastConnected;
const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) continue;
if (i > 0) server->sendContent(","); server->sendContent(output); yield(); // Yield to allow WiFi and other tasks to process during a slow send resetTaskWatchdogIfSubscribed(); // Reset watchdog: each sendContent() is a blocking network write }
server->sendContent("]"); server->sendContent(""); LOG_DBG("WEB", "Served Wi-Fi credentials API (%zu network(s))", credentials.size());}
void CrossPointWebServer::handlePostWifiNetwork() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; }
const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; }
std::string ssid = doc["ssid"] | std::string(""); if (ssid.empty()) { server->send(400, "text/plain", "SSID is required"); return; }
// The password field is optional in the JSON payload. When absent (vs. present but empty), // preserve the existing password for updates. Empty passwords are valid for open networks. bool hasPasswordField = doc["password"].is<const char*>() || doc["password"].is<std::string>(); std::string password = doc["password"] | std::string("");
if (doc["index"].is<int>()) { int idx = doc["index"].as<int>(); if (idx < 0) { server->send(400, "text/plain", "Invalid network index"); return; } const auto credential = WIFI_STORE.getCredentialAt(static_cast<size_t>(idx)); if (!credential) { server->send(400, "text/plain", "Invalid network index"); return; }
const std::string oldSsid = credential->ssid; if (!hasPasswordField) { password = credential->password; }
bool ok = true; if (oldSsid != ssid) { ok = WIFI_STORE.removeCredential(oldSsid) && WIFI_STORE.addCredential(ssid, password); } else { ok = WIFI_STORE.addCredential(ssid, password); }
if (!ok) { server->send(400, "text/plain", "Failed to update Wi-Fi network"); return; }
LOG_DBG("WEB", "Updated Wi-Fi network at index %d (SSID: %s)", idx, ssid.c_str()); } else { if (!WIFI_STORE.addCredential(ssid, password)) { server->send(400, "text/plain", "Cannot add network (limit reached)"); return; } LOG_DBG("WEB", "Added Wi-Fi network: %s", ssid.c_str()); }
server->send(200, "text/plain", "OK");}
// Uses POST (not HTTP DELETE) because ESP32 WebServer doesn't support DELETE with body.void CrossPointWebServer::handleDeleteWifiNetwork() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; }
const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; }
if (!doc["index"].is<int>()) { server->send(400, "text/plain", "Missing index"); return; }
int idx = doc["index"].as<int>(); if (idx < 0) { server->send(400, "text/plain", "Invalid network index"); return; } const auto ssid = WIFI_STORE.getSsidAt(static_cast<size_t>(idx)); if (!ssid) { server->send(400, "text/plain", "Invalid network index"); return; }
if (!WIFI_STORE.removeCredential(*ssid)) { server->send(400, "text/plain", "Failed to delete Wi-Fi network"); return; }
LOG_DBG("WEB", "Deleted Wi-Fi network at index %d (SSID: %s)", idx, ssid->c_str()); server->send(200, "text/plain", "OK");}
// WebSocket callback trampolinevoid CrossPointWebServer::wsEventCallback(uint8_t num, WStype_t type, uint8_t* payload, size_t length) { if (wsInstance) { wsInstance->onWebSocketEvent(num, type, payload, length); }}
// WebSocket event handler for fast binary uploads// Protocol:// 1. Client sends TEXT message: "START:<filename>:<size>:<path>"// 2. Client sends BINARY messages with file data chunks// 3. Server sends TEXT "PROGRESS:<received>:<total>" after each chunk// 4. Server sends TEXT "DONE" or "ERROR:<message>" when completevoid CrossPointWebServer::onWebSocketEvent(uint8_t num, WStype_t type, uint8_t* payload, size_t length) { switch (type) { case WStype_DISCONNECTED: LOG_DBG("WS", "Client %u disconnected", num); // Only clean up if this is the client that owns the active upload. // A new client may have already started a fresh upload before this // DISCONNECTED event fires (race condition on quick cancel + retry). if (num == wsUploadClientNum && wsUploadInProgress && wsUploadFile) { abortWsUpload("WS"); } break;
case WStype_CONNECTED: { LOG_DBG("WS", "Client %u connected", num); break; }
case WStype_TEXT: { // Parse control messages String msg = String((char*)payload); LOG_DBG("WS", "Text from client %u: %s", num, msg.c_str());
if (msg.startsWith("START:")) { // Reject any START while an upload is already active to prevent // leaking the open wsUploadFile handle (owning client re-START included) if (wsUploadInProgress) { wsServer->sendTXT(num, "ERROR:Upload already in progress"); break; }
// Parse: START:<filename>:<size>:<path> int firstColon = msg.indexOf(':', 6); int secondColon = msg.indexOf(':', firstColon + 1);
if (firstColon > 0 && secondColon > 0) { wsUploadFileName = msg.substring(6, firstColon); if (!FsHelpers::isSafePathComponent(wsUploadFileName)) { LOG_DBG("WS", "START rejected: invalid filename '%s'", wsUploadFileName.c_str()); wsServer->sendTXT(num, "ERROR:Invalid file name"); return; } String sizeToken = msg.substring(firstColon + 1, secondColon); bool sizeValid = sizeToken.length() > 0; int digitStart = (sizeValid && sizeToken[0] == '+') ? 1 : 0; if (digitStart > 0 && sizeToken.length() < 2) sizeValid = false; for (int i = digitStart; i < (int)sizeToken.length() && sizeValid; i++) { if (!isdigit((unsigned char)sizeToken[i])) sizeValid = false; } if (!sizeValid) { LOG_DBG("WS", "START rejected: invalid size token '%s'", sizeToken.c_str()); wsServer->sendTXT(num, "ERROR:Invalid START format"); return; } wsUploadSize = sizeToken.toInt(); wsUploadPath = normalizeWebPath(msg.substring(secondColon + 1)); wsUploadReceived = 0; wsLastProgressSent = 0; wsUploadStartTime = millis();
String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName;
resetTaskWatchdogIfSubscribed(); if (Storage.exists(filePath.c_str())) { LOG_DBG("WS", "Upload collision: %s", filePath.c_str()); wsServer->sendTXT(num, "ERROR:File already exists: " + wsUploadFileName); return; }
LOG_DBG("WS", "Starting upload: %s (%d bytes) to %s", wsUploadFileName.c_str(), wsUploadSize, filePath.c_str());
// Open file for writing resetTaskWatchdogIfSubscribed(); if (!Storage.openFileForWrite("WS", filePath, wsUploadFile)) { wsServer->sendTXT(num, "ERROR:Failed to create file"); wsUploadInProgress = false; wsUploadClientNum = 255; return; } resetTaskWatchdogIfSubscribed();
// Zero-byte upload: complete immediately without waiting for BIN frames if (wsUploadSize == 0) { // Explicit close() required: file-scope global persists beyond function scope wsUploadFile.close(); wsLastCompleteName = wsUploadFileName; wsLastCompleteSize = 0; wsLastCompleteAt = millis(); LOG_DBG("WS", "Zero-byte upload complete: %s", filePath.c_str()); clearBookCache(filePath.c_str()); if (isLibraryBookFile(wsUploadFileName)) library::markLibraryIndexDirty(); wsServer->sendTXT(num, "DONE"); wsLastProgressSent = 0; break; }
wsUploadClientNum = num; wsUploadInProgress = true; wsServer->sendTXT(num, "READY"); } else { wsServer->sendTXT(num, "ERROR:Invalid START format"); } } break; }
case WStype_BIN: { if (!wsUploadInProgress || !wsUploadFile || num != wsUploadClientNum) { wsServer->sendTXT(num, "ERROR:No upload in progress"); return; }
// Write binary data directly to file size_t remaining = wsUploadSize - wsUploadReceived; if (length > remaining) { abortWsUpload("WS"); wsServer->sendTXT(num, "ERROR:Upload overflow"); return; } resetTaskWatchdogIfSubscribed(); size_t written = wsUploadFile.write(payload, length); resetTaskWatchdogIfSubscribed();
if (written != length) { abortWsUpload("WS"); wsServer->sendTXT(num, "ERROR:Write failed - disk full?"); return; }
wsUploadReceived += written;
// Send progress update (every 64KB or at end) if (wsUploadReceived - wsLastProgressSent >= 65536 || wsUploadReceived >= wsUploadSize) { String progress = "PROGRESS:" + String(wsUploadReceived) + ":" + String(wsUploadSize); wsServer->sendTXT(num, progress); wsLastProgressSent = wsUploadReceived; }
// Check if upload complete if (wsUploadReceived >= wsUploadSize) { // Explicit close() required: file-scope global persists beyond function scope wsUploadFile.close(); wsUploadInProgress = false; wsUploadClientNum = 255;
wsLastCompleteName = wsUploadFileName; wsLastCompleteSize = wsUploadSize; wsLastCompleteAt = millis();
unsigned long elapsed = millis() - wsUploadStartTime; float kbps = (elapsed > 0) ? (wsUploadSize / 1024.0) / (elapsed / 1000.0) : 0;
LOG_DBG("WS", "Upload complete: %s (%d bytes in %lu ms, %.1f KB/s)", wsUploadFileName.c_str(), wsUploadSize, elapsed, kbps);
// Clear epub cache after uploading the file String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName; clearBookCache(filePath.c_str()); if (isLibraryBookFile(wsUploadFileName)) library::markLibraryIndexDirty();
wsServer->sendTXT(num, "DONE"); wsLastProgressSent = 0; } break; }
default: break; }}
// --- Font management handlers ---
void CrossPointWebServer::handleFontsPage() const { sendStaticContent(server.get(), FontsPageHtml, sizeof(FontsPageHtml), FontsPageHtmlETag, "text/html"); LOG_DBG("WEB", "Served fonts page");}
void CrossPointWebServer::handleFontList() const { // Pick up any uploads/deletes that happened since the last reader load. const_cast<SdCardFontSystem&>(sdFontSystem).refreshIfDirty(); const auto& families = sdFontSystem.registry().getFamilies();
JsonDocument doc; JsonArray arr = doc["families"].to<JsonArray>(); doc["maxFamilies"] = SdCardFontRegistry::MAX_SD_FAMILIES;
for (const auto& family : families) { JsonObject fObj = arr.add<JsonObject>(); fObj["name"] = family.name;
JsonArray sizes = fObj["sizes"].to<JsonArray>(); for (uint8_t s : family.availableSizes()) { sizes.add(s); }
JsonArray files = fObj["files"].to<JsonArray>(); for (const auto& file : family.files) { JsonObject fileObj = files.add<JsonObject>(); // Extract filename from full path const char* name = strrchr(file.path.c_str(), '/'); fileObj["name"] = name ? name + 1 : file.path.c_str();
// Stat the file for size HalFile f; if (Storage.openFileForRead("WEB", file.path.c_str(), f)) { fileObj["size"] = static_cast<unsigned long>(f.size()); f.close(); } else { fileObj["size"] = 0; } } }
String json; serializeJson(doc, json); server->send(200, "application/json", json);}
void CrossPointWebServer::handleFontUploadData() { HTTPUpload& upload = server->upload();
switch (upload.status) { case UPLOAD_FILE_START: { resetTaskWatchdogIfSubscribed(); String family = server->arg("family"); fontUpload.file = HalFile(); fontUpload.familyName.clear(); fontUpload.filePath.clear(); fontUpload.valid = false; fontUpload.magicChecked = false; fontUpload.bytesWritten = 0; fontUpload.bufferPos = 0;
if (!FontInstaller::isValidFamilyName(family.c_str())) { LOG_ERR("WEB", "Invalid font family name: %s", family.c_str()); break; }
String filename = upload.filename; filename.replace(' ', '_'); // Validate filename: rejects path traversal (../, /, \) and enforces // a .cpfont basename of alphanumeric + hyphen + underscore. Without // this an attacker could supply "../../.crosspoint/settings.json" as // a "filename" and have it written outside the fonts directory. if (!FontInstaller::isValidCpfontFilename(filename.c_str())) { LOG_ERR("WEB", "Invalid font filename: %s", filename.c_str()); break; }
fontUpload.familyName = family.c_str();
// Create a temporary FontInstaller for directory creation FontInstaller installer(sdFontSystem.registry()); if (!installer.ensureFamilyDir(family.c_str())) { LOG_ERR("WEB", "Failed to create font family dir"); break; }
char path[128]; FontInstaller::buildFontPath(family.c_str(), filename.c_str(), path, sizeof(path)); fontUpload.filePath = path;
if (!Storage.openFileForWrite("WEB", path, fontUpload.file)) { LOG_ERR("WEB", "Failed to open font file for write: %s", path); break; }
fontUpload.valid = true; LOG_DBG("WEB", "Font upload started: %s -> %s", filename.c_str(), path); break; }
case UPLOAD_FILE_WRITE: { if (!fontUpload.valid) break; resetTaskWatchdogIfSubscribed();
// Validate magic bytes on first chunk only if (!fontUpload.magicChecked && upload.currentSize >= 8) { if (memcmp(upload.buf, "CPFONT\0\0", 8) != 0) { LOG_ERR("WEB", "Invalid .cpfont magic bytes"); fontUpload.valid = false; break; } fontUpload.magicChecked = true; }
// Buffer writes for efficiency size_t remaining = upload.currentSize; const uint8_t* src = upload.buf; while (remaining > 0) { size_t space = FontUploadState::BUFFER_SIZE - fontUpload.bufferPos; size_t chunk = (remaining < space) ? remaining : space; memcpy(fontUpload.buffer.data() + fontUpload.bufferPos, src, chunk); fontUpload.bufferPos += chunk; src += chunk; remaining -= chunk;
if (fontUpload.bufferPos >= FontUploadState::BUFFER_SIZE) { fontUpload.file.write(fontUpload.buffer.data(), fontUpload.bufferPos); fontUpload.bytesWritten += fontUpload.bufferPos; fontUpload.bufferPos = 0; resetTaskWatchdogIfSubscribed(); } } break; }
case UPLOAD_FILE_END: { // Flush remaining buffer if (fontUpload.valid && fontUpload.bufferPos > 0) { fontUpload.file.write(fontUpload.buffer.data(), fontUpload.bufferPos); fontUpload.bytesWritten += fontUpload.bufferPos; fontUpload.bufferPos = 0; } if (fontUpload.file.isOpen()) { fontUpload.file.close(); }
if (!fontUpload.valid && !fontUpload.filePath.empty()) { Storage.remove(fontUpload.filePath.c_str()); }
LOG_DBG("WEB", "Font upload end: valid=%d, %zu bytes", fontUpload.valid, fontUpload.bytesWritten); break; }
case UPLOAD_FILE_ABORTED: { if (fontUpload.file) { fontUpload.file.close(); } if (!fontUpload.filePath.empty()) { Storage.remove(fontUpload.filePath.c_str()); } fontUpload.valid = false; LOG_DBG("WEB", "Font upload aborted"); break; } }}
void CrossPointWebServer::handleFontUpload() { if (fontUpload.valid) { sdFontSystem.markRegistryDirty(); server->send(200, "application/json", "{\"ok\":true}"); LOG_DBG("WEB", "Font upload complete: %s", fontUpload.filePath.c_str()); } else { server->send(400, "application/json", "{\"error\":\"Invalid .cpfont file\"}"); }}
void CrossPointWebServer::handleFontDelete() { String body = server->arg("plain"); JsonDocument doc; DeserializationError err = deserializeJson(doc, body);
if (err || !doc["family"].is<const char*>()) { server->send(400, "application/json", "{\"error\":\"Invalid request\"}"); return; }
const char* familyName = doc["family"]; FontInstaller installer(sdFontSystem.registry()); auto result = installer.deleteFamily(familyName);
if (result == FontInstaller::Error::OK) { sdFontSystem.markRegistryDirty(); server->send(200, "application/json", "{\"ok\":true}"); LOG_DBG("WEB", "Deleted font family: %s", familyName); } else { server->send(500, "application/json", "{\"error\":\"Delete failed\"}"); LOG_ERR("WEB", "Failed to delete font family: %s", familyName); }}