#include "CrossPointWebServer.h" #include #include #include #include #include #include #include #include #include #include "CrossPointSettings.h" #include "FontInstaller.h" #include "OpdsServerStore.h" #include "SdCardFontGlobals.h" #include "SdCardFontRegistry.h" #include "SettingsList.h" #include "SystemStatus.h" #include "WebDAVHandler.h" #include "WifiCredentialStore.h" #include "html/FilesPageHtml.generated.h" #include "html/FontsPageHtml.generated.h" #include "html/HomePageHtml.generated.h" #include "html/SettingsPageHtml.generated.h" #include "html/WelcomePageHtml.generated.h" #include "html/js/jszip_minJs.generated.h" #include "network/HttpDownloader.h" namespace { // Folders/files to hide from the web interface file browser // Note: Items starting with "." are automatically hidden const char* HIDDEN_ITEMS[] = {"System Volume Information", "XTCache"}; constexpr size_t HIDDEN_ITEMS_COUNT = sizeof(HIDDEN_ITEMS) / sizeof(HIDDEN_ITEMS[0]); constexpr uint16_t UDP_PORTS[] = {54982, 48123, 39001, 44044, 59678}; constexpr uint16_t LOCAL_UDP_PORT = 8134; #ifndef FONT_MANIFEST_URL #define FONT_MANIFEST_URL "https://github.com/jpirnay/crosspoint-reader/blob/master/assets/sd-fonts/sd-fonts.yaml" #endif // Static pointer for WebSocket callback (WebSocketsServer requires C-style callback) CrossPointWebServer* wsInstance = nullptr; // WebSocket upload state FsFile wsUploadFile; String wsUploadFileName; String wsUploadPath; size_t wsUploadSize = 0; size_t wsUploadReceived = 0; unsigned long wsUploadStartTime = 0; bool wsUploadInProgress = false; uint8_t wsUploadClientNum = 255; // 255 = no active upload client size_t wsLastProgressSent = 0; String wsLastCompleteName; size_t wsLastCompleteSize = 0; unsigned long wsLastCompleteAt = 0; // Helper function to clear epub cache after upload void clearEpubCacheIfNeeded(const String& filePath) { if (FsHelpers::hasEpubExtension(filePath)) { Epub(filePath.c_str(), "/.crosspoint").clearCache(); LOG_DBG("WEB", "Cleared epub cache for: %s", filePath.c_str()); } } // Recursively clear epub caches for all EPUBs inside a directory void clearEpubCachesInDirectory(const String& dirPath) { esp_task_wdt_reset(); yield(); FsFile dir = Storage.open(dirPath.c_str()); if (!dir || !dir.isDirectory()) { if (dir) dir.close(); return; } char name[500]; FsFile entry = dir.openNextFile(); while (entry) { esp_task_wdt_reset(); yield(); entry.getName(name, sizeof(name)); String childPath = dirPath; if (!childPath.endsWith("/")) childPath += "/"; childPath += name; if (entry.isDirectory()) { entry.close(); clearEpubCachesInDirectory(childPath); } else { entry.close(); clearEpubCacheIfNeeded(childPath); } entry = dir.openNextFile(); } dir.close(); } String normalizeWebPath(const String& inputPath) { if (inputPath.isEmpty() || inputPath == "/") { return "/"; } std::string normalized = FsHelpers::normalisePath(inputPath.c_str()); String result = normalized.c_str(); if (result.isEmpty()) { return "/"; } if (!result.startsWith("/")) { result = "/" + result; } if (result.length() > 1 && result.endsWith("/")) { result = result.substring(0, result.length() - 1); } return result; } bool isProtectedItemName(const String& name) { if (name.startsWith(".")) { return true; } for (size_t i = 0; i < HIDDEN_ITEMS_COUNT; i++) { if (name.equals(HIDDEN_ITEMS[i])) { return true; } } return false; } } // namespace // File listing page template - now using generated headers: // - HomePageHtml (from html/HomePage.html) // - FilesPageHeaderHtml (from html/FilesPageHeader.html) // - FilesPageFooterHtml (from html/FilesPageFooter.html) CrossPointWebServer::CrossPointWebServer() {} CrossPointWebServer::~CrossPointWebServer() { stop(); } void CrossPointWebServer::begin() { if (running) { LOG_DBG("WEB", "Web server already running"); return; } // Check if we have a valid network connection (either STA connected or AP mode) const wifi_mode_t wifiMode = WiFi.getMode(); const bool isStaConnected = (wifiMode & WIFI_MODE_STA) && (WiFi.status() == WL_CONNECTED); const bool isInApMode = (wifiMode & WIFI_MODE_AP) && (WiFi.softAPgetStationNum() >= 0); // AP is running if (!isStaConnected && !isInApMode) { LOG_DBG("WEB", "Cannot start webserver - no valid network (mode=%d, status=%d)", wifiMode, WiFi.status()); return; } // Store AP mode flag for later use (e.g., in handleStatus) apMode = isInApMode; LOG_DBG("WEB", "[MEM] Free heap before begin: %d bytes", ESP.getFreeHeap()); LOG_DBG("WEB", "Network mode: %s", apMode ? "AP" : "STA"); LOG_DBG("WEB", "Creating web server on port %d...", port); server.reset(new WebServer(port)); // Disable WiFi sleep to improve responsiveness and prevent 'unreachable' errors. // This is critical for reliable web server operation on ESP32. WiFi.setSleep(false); // Note: WebServer class doesn't have setNoDelay() in the standard ESP32 library. // We rely on disabling WiFi sleep for responsiveness. LOG_DBG("WEB", "[MEM] Free heap after WebServer allocation: %d bytes", ESP.getFreeHeap()); if (!server) { LOG_ERR("WEB", "Failed to create WebServer!"); return; } // Setup routes LOG_DBG("WEB", "Setting up routes..."); server->on("/", HTTP_GET, [this] { handleWelcomePage(); }); server->on("/systeminfo", HTTP_GET, [this] { handleSystemInfoPage(); }); server->on("/files", HTTP_GET, [this] { handleRoot(); }); server->on("/js/jszip.min.js", HTTP_GET, [this] { handleJszip(); }); server->on("/api/status", HTTP_GET, [this] { handleStatus(); }); server->on("/api/status/fast", HTTP_GET, [this] { handleStatusFast(); }); server->on("/api/files", HTTP_GET, [this] { handleFileListData(); }); server->on("/download", HTTP_GET, [this] { handleDownload(); }); // Upload endpoint with special handling for multipart form data server->on("/upload", HTTP_POST, [this] { handleUploadPost(upload); }, [this] { handleUpload(upload); }); // Create folder endpoint server->on("/mkdir", HTTP_POST, [this] { handleCreateFolder(); }); // Rename file endpoint server->on("/rename", HTTP_POST, [this] { handleRename(); }); // Move file endpoint server->on("/move", HTTP_POST, [this] { handleMove(); }); // Delete file/folder endpoint server->on("/delete", HTTP_POST, [this] { handleDelete(); }); // Settings endpoints server->on("/settings", HTTP_GET, [this] { handleSettingsPage(); }); server->on("/api/settings", HTTP_GET, [this] { handleGetSettings(); }); server->on("/api/settings", HTTP_POST, [this] { handlePostSettings(); }); // Font management endpoints server->on("/fonts", HTTP_GET, [this] { handleFontsPage(); }); server->on("/api/fonts", HTTP_GET, [this] { handleFontList(); }); server->on("/api/fonts/manifest", HTTP_GET, [this] { handleFontManifest(); }); server->on("/api/fonts/download", HTTP_POST, [this] { handleFontDownload(); }); server->on("/api/fonts/upload", HTTP_POST, [this] { handleFontUpload(); }, [this] { handleFontUploadData(); }); server->on("/api/fonts/delete", HTTP_POST, [this] { handleFontDelete(); }); // OPDS server endpoints server->on("/api/opds", HTTP_GET, [this] { handleGetOpdsServers(); }); server->on("/api/opds", HTTP_POST, [this] { handlePostOpdsServer(); }); server->on("/api/opds/delete", HTTP_POST, [this] { handleDeleteOpdsServer(); }); // Wi-Fi credential endpoints server->on("/api/wifi", HTTP_GET, [this] { handleGetWifiNetworks(); }); server->on("/api/wifi", HTTP_POST, [this] { handlePostWifiNetwork(); }); server->on("/api/wifi/delete", HTTP_POST, [this] { handleDeleteWifiNetwork(); }); server->onNotFound([this] { handleNotFound(); }); LOG_DBG("WEB", "[MEM] Free heap after route setup: %d bytes", ESP.getFreeHeap()); // Collect WebDAV headers and register handler const char* davHeaders[] = {"Depth", "Destination", "Overwrite", "If", "Lock-Token", "Timeout"}; server->collectHeaders(davHeaders, 6); server->addHandler(new WebDAVHandler()); // Note: WebDAVHandler will be deleted by WebServer when server is stopped LOG_DBG("WEB", "WebDAV handler initialized"); server->begin(); // Start WebSocket server for fast binary uploads LOG_DBG("WEB", "Starting WebSocket server on port %d...", wsPort); wsServer.reset(new WebSocketsServer(wsPort)); wsInstance = const_cast(this); wsServer->begin(); wsServer->onEvent(wsEventCallback); LOG_DBG("WEB", "WebSocket server started"); udpActive = udp.begin(LOCAL_UDP_PORT); LOG_DBG("WEB", "Discovery UDP %s on port %d", udpActive ? "enabled" : "failed", LOCAL_UDP_PORT); running = true; LOG_DBG("WEB", "Web server started on port %d", port); // Show the correct IP based on network mode const String ipAddr = apMode ? WiFi.softAPIP().toString() : WiFi.localIP().toString(); LOG_DBG("WEB", "Access at http://%s/", ipAddr.c_str()); LOG_DBG("WEB", "WebSocket at ws://%s:%d/", ipAddr.c_str(), wsPort); LOG_DBG("WEB", "[MEM] Free heap after server.begin(): %d bytes", ESP.getFreeHeap()); } void CrossPointWebServer::abortWsUpload(const char* tag) { wsUploadFile.close(); String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName; if (Storage.remove(filePath.c_str())) { LOG_DBG(tag, "Deleted incomplete upload: %s", filePath.c_str()); } else { LOG_DBG(tag, "Failed to delete incomplete upload: %s", filePath.c_str()); } wsUploadInProgress = false; wsUploadClientNum = 255; wsLastProgressSent = 0; } void CrossPointWebServer::stop() { if (!running || !server) { LOG_DBG("WEB", "stop() called but already stopped (running=%d, server=%p)", running, server.get()); return; } LOG_DBG("WEB", "STOP INITIATED - setting running=false first"); running = false; // Set this FIRST to prevent handleClient from using server LOG_DBG("WEB", "[MEM] Free heap before stop: %d bytes", ESP.getFreeHeap()); // Close any in-progress WebSocket upload and remove partial file if (wsUploadInProgress && wsUploadFile) { abortWsUpload("WEB"); } // Stop WebSocket server if (wsServer) { LOG_DBG("WEB", "Stopping WebSocket server..."); wsServer->close(); wsServer.reset(); wsInstance = nullptr; LOG_DBG("WEB", "WebSocket server stopped"); } if (udpActive) { udp.stop(); udpActive = false; } // Brief delay to allow any in-flight handleClient() calls to complete delay(20); server->stop(); LOG_DBG("WEB", "[MEM] Free heap after server->stop(): %d bytes", ESP.getFreeHeap()); // Brief delay before deletion delay(10); server.reset(); LOG_DBG("WEB", "Web server stopped and deleted"); LOG_DBG("WEB", "[MEM] Free heap after delete server: %d bytes", ESP.getFreeHeap()); // Note: Static upload variables (uploadFileName, uploadPath, uploadError) are declared // later in the file and will be cleared when they go out of scope or on next upload LOG_DBG("WEB", "[MEM] Free heap final: %d bytes", ESP.getFreeHeap()); } void CrossPointWebServer::handleClient() { static unsigned long lastDebugPrint = 0; // Check running flag FIRST before accessing server if (!running) { return; } // Double-check server pointer is valid if (!server) { LOG_DBG("WEB", "WARNING: handleClient called with null server!"); return; } // Print debug every 10 seconds to confirm handleClient is being called if (millis() - lastDebugPrint > 10000) { LOG_DBG("WEB", "handleClient active, server running on port %d", port); lastDebugPrint = millis(); } server->handleClient(); // Handle WebSocket events if (wsServer) { wsServer->loop(); } // Respond to discovery broadcasts if (udpActive) { int packetSize = udp.parsePacket(); if (packetSize > 0) { char buffer[16]; int len = udp.read(buffer, sizeof(buffer) - 1); if (len > 0) { buffer[len] = '\0'; if (strcmp(buffer, "hello") == 0) { String hostname = WiFi.getHostname(); if (hostname.isEmpty()) { hostname = "crosspoint"; } String message = "crosspoint (on " + hostname + ");" + String(wsPort); udp.beginPacket(udp.remoteIP(), udp.remotePort()); udp.write(reinterpret_cast(message.c_str()), message.length()); udp.endPacket(); } } } } } CrossPointWebServer::WsUploadStatus CrossPointWebServer::getWsUploadStatus() const { WsUploadStatus status; status.inProgress = wsUploadInProgress; status.received = wsUploadReceived; status.total = wsUploadSize; status.filename = wsUploadFileName.c_str(); status.lastCompleteName = wsLastCompleteName.c_str(); status.lastCompleteSize = wsLastCompleteSize; status.lastCompleteAt = wsLastCompleteAt; return status; } static void sendHtmlContent(WebServer* server, const char* data, size_t len) { server->sendHeader("Content-Encoding", "gzip"); server->send_P(200, "text/html", data, len); } void CrossPointWebServer::handleRoot() const { int32_t t0 = millis(); sendHtmlContent(server.get(), FilesPageHtml, sizeof(FilesPageHtml)); int32_t t1 = millis(); LOG_DBG("WEB", "Served file manager page in %d ms", t1 - t0); } void CrossPointWebServer::handleWelcomePage() const { int32_t t0 = millis(); sendHtmlContent(server.get(), WelcomePageHtml, sizeof(WelcomePageHtml)); int32_t t1 = millis(); LOG_DBG("WEB", "Served welcome page in %d ms", t1 - t0); } void CrossPointWebServer::handleSystemInfoPage() const { int32_t t0 = millis(); sendHtmlContent(server.get(), HomePageHtml, sizeof(HomePageHtml)); int32_t t1 = millis(); LOG_DBG("WEB", "Served system info page in %d ms", t1 - t0); } void CrossPointWebServer::handleJszip() const { server->sendHeader("Content-Encoding", "gzip"); server->send_P(200, "application/javascript", jszip_minJs, jszip_minJsCompressedSize); LOG_DBG("WEB", "Served jszip.min.js"); } void CrossPointWebServer::handleNotFound() const { String message = "404 Not Found\n\n"; message += "URI: " + server->uri() + "\n"; server->send(404, "text/plain", message); } void CrossPointWebServer::handleStatus() const { const bool fastOnly = server->hasArg("phase") && server->arg("phase").equalsIgnoreCase("fast"); LOG_DBG("SYSINFO", "handleStatus request received (fastOnly=%d)", fastOnly); int32_t t0 = millis(); SystemStatus status = SystemStatus::collectFast(); int32_t t1 = millis(); LOG_DBG("SYSINFO", "Collected fast status in %d ms (fastOnly=%d)", t1 - t0, fastOnly); if (!fastOnly) { LOG_DBG("SYSINFO", "handleStatus will collect SD stats"); SystemStatus::fillSdStatus(status); } JsonDocument doc; doc["version"] = status.version; doc["deviceType"] = status.deviceType; doc["displayWidth"] = status.displayWidth; doc["displayHeight"] = status.displayHeight; doc["chipVersion"] = status.chipVersion; doc["cpuMHz"] = status.cpuFreqMHz; doc["ip"] = status.ip; doc["mode"] = status.wifiMode; doc["rssi"] = status.rssi; doc["macAddress"] = status.macAddress; doc["freeHeap"] = status.freeHeapBytes; doc["minFreeHeap"] = status.minFreeHeapBytes; doc["maxAllocHeap"] = status.maxAllocHeapBytes; doc["flashTotal"] = status.flashBytes; doc["appPartitionSize"] = status.flashAppPartitionSize; doc["batteryPercent"] = status.batteryPercent; doc["charging"] = status.charging; doc["uptime"] = status.uptimeSeconds; doc["sdReady"] = !fastOnly; doc["sdTotal"] = status.sdTotalBytes; doc["sdUsed"] = status.sdUsedBytes; doc["sdFree"] = status.sdFreeBytes; String json; serializeJson(doc, json); server->send(200, "application/json", json); } void CrossPointWebServer::handleStatusFast() const { LOG_DBG("SYSINFO", "handleStatusFast request received"); int32_t t0 = millis(); SystemStatus status = SystemStatus::collectFast(); int32_t t1 = millis(); LOG_DBG("SYSINFO", "Collected fast-only status in %d ms", t1 - t0); JsonDocument doc; doc["version"] = status.version; doc["deviceType"] = status.deviceType; doc["displayWidth"] = status.displayWidth; doc["displayHeight"] = status.displayHeight; doc["chipVersion"] = status.chipVersion; doc["cpuMHz"] = status.cpuFreqMHz; doc["ip"] = status.ip; doc["mode"] = status.wifiMode; doc["rssi"] = status.rssi; doc["macAddress"] = status.macAddress; doc["freeHeap"] = status.freeHeapBytes; doc["minFreeHeap"] = status.minFreeHeapBytes; doc["maxAllocHeap"] = status.maxAllocHeapBytes; doc["flashTotal"] = status.flashBytes; doc["appPartitionSize"] = status.flashAppPartitionSize; doc["batteryPercent"] = status.batteryPercent; doc["charging"] = status.charging; doc["uptime"] = status.uptimeSeconds; doc["sdReady"] = false; // Still include SD stats in response, but client should ignore them when sdReady=false doc["sdTotal"] = status.sdTotalBytes; doc["sdUsed"] = status.sdUsedBytes; doc["sdFree"] = status.sdFreeBytes; String json; serializeJson(doc, json); server->send(200, "application/json", json); } void CrossPointWebServer::scanFiles(const char* path, const std::function& callback) const { FsFile root = Storage.open(path); if (!root) { LOG_DBG("WEB", "Failed to open directory: %s", path); return; } if (!root.isDirectory()) { LOG_DBG("WEB", "Not a directory: %s", path); root.close(); return; } LOG_DBG("WEB", "Scanning files in: %s", path); FsFile file = root.openNextFile(); char name[500]; while (file) { file.getName(name, sizeof(name)); auto fileName = String(name); // Skip hidden items (starting with ".") bool shouldHide = !SETTINGS.showHiddenFiles && fileName.startsWith("."); // Check against explicitly hidden items list if (!shouldHide) { for (size_t i = 0; i < HIDDEN_ITEMS_COUNT; i++) { if (fileName.equals(HIDDEN_ITEMS[i])) { shouldHide = true; break; } } } if (!shouldHide) { FileInfo info; info.name = fileName; info.isDirectory = file.isDirectory(); if (info.isDirectory) { info.size = 0; info.isEpub = false; } else { info.size = file.size(); info.isEpub = isEpubFile(info.name); } callback(info); } file.close(); yield(); // Yield to allow WiFi and other tasks to process during long scans esp_task_wdt_reset(); // Reset watchdog to prevent timeout on large directories file = root.openNextFile(); } root.close(); } bool CrossPointWebServer::isEpubFile(const String& filename) const { return FsHelpers::hasEpubExtension(filename); } void CrossPointWebServer::handleFileList() const { sendHtmlContent(server.get(), FilesPageHtml, sizeof(FilesPageHtml)); } void CrossPointWebServer::handleFileListData() const { // Get current path from query string (default to root) String currentPath = "/"; if (server->hasArg("path")) { currentPath = server->arg("path"); // Ensure path starts with / if (!currentPath.startsWith("/")) { currentPath = "/" + currentPath; } // Remove trailing slash unless it's root if (currentPath.length() > 1 && currentPath.endsWith("/")) { currentPath = currentPath.substring(0, currentPath.length() - 1); } } server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("["); char output[512]; constexpr size_t outputSize = sizeof(output); bool seenFirst = false; JsonDocument doc; scanFiles(currentPath.c_str(), [this, &output, &doc, seenFirst](const FileInfo& info) mutable { doc.clear(); doc["name"] = info.name; doc["size"] = info.size; doc["isDirectory"] = info.isDirectory; doc["isEpub"] = info.isEpub; const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) { // JSON output truncated; skip this entry to avoid sending malformed JSON LOG_DBG("WEB", "Skipping file entry with oversized JSON for name: %s", info.name.c_str()); return; } if (seenFirst) { server->sendContent(","); } else { seenFirst = true; } server->sendContent(output); }); server->sendContent("]"); // End of streamed response, empty chunk to signal client server->sendContent(""); LOG_DBG("WEB", "Served file listing page for path: %s", currentPath.c_str()); } void CrossPointWebServer::handleDownload() const { if (!server->hasArg("path")) { server->send(400, "text/plain", "Missing path"); return; } String itemPath = server->arg("path"); if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; } if (!itemPath.startsWith("/")) { itemPath = "/" + itemPath; } const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (itemName.startsWith(".")) { server->send(403, "text/plain", "Cannot access system files"); return; } for (size_t i = 0; i < HIDDEN_ITEMS_COUNT; i++) { if (itemName.equals(HIDDEN_ITEMS[i])) { server->send(403, "text/plain", "Cannot access protected items"); return; } } if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; } FsFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } if (file.isDirectory()) { file.close(); server->send(400, "text/plain", "Path is a directory"); return; } String contentType = "application/octet-stream"; if (isEpubFile(itemPath)) { contentType = "application/epub+zip"; } char nameBuf[128] = {0}; String filename = "download"; if (file.getName(nameBuf, sizeof(nameBuf))) { filename = nameBuf; } server->setContentLength(file.size()); server->sendHeader("Content-Disposition", "attachment; filename=\"" + filename + "\""); server->send(200, contentType.c_str(), ""); NetworkClient client = server->client(); const size_t chunkSize = 4096; uint8_t buffer[chunkSize]; bool downloadOk = true; while (downloadOk && file.available()) { int result = file.read(buffer, chunkSize); if (result <= 0) break; size_t bytesRead = static_cast(result); size_t totalWritten = 0; while (totalWritten < bytesRead) { esp_task_wdt_reset(); size_t wrote = client.write(buffer + totalWritten, bytesRead - totalWritten); if (wrote == 0) { downloadOk = false; break; } totalWritten += wrote; } } client.clear(); file.close(); } // Diagnostic counters for upload performance analysis static unsigned long uploadStartTime = 0; static unsigned long totalWriteTime = 0; static size_t writeCount = 0; static bool flushUploadBuffer(CrossPointWebServer::UploadState& state) { if (state.bufferPos > 0 && state.file) { esp_task_wdt_reset(); // Reset watchdog before potentially slow SD write const unsigned long writeStart = millis(); const size_t written = state.file.write(state.buffer.data(), state.bufferPos); totalWriteTime += millis() - writeStart; writeCount++; esp_task_wdt_reset(); // Reset watchdog after SD write if (written != state.bufferPos) { LOG_DBG("WEB", "[UPLOAD] Buffer flush failed: expected %d, wrote %d", state.bufferPos, written); state.bufferPos = 0; return false; } state.bufferPos = 0; } return true; } void CrossPointWebServer::handleUpload(UploadState& state) const { static size_t lastLoggedSize = 0; // Reset watchdog at start of every upload callback - HTTP parsing can be slow esp_task_wdt_reset(); // Safety check: ensure server is still valid if (!running || !server) { LOG_DBG("WEB", "[UPLOAD] ERROR: handleUpload called but server not running!"); return; } const HTTPUpload& upload = server->upload(); if (upload.status == UPLOAD_FILE_START) { // Reset watchdog - this is the critical 1% crash point esp_task_wdt_reset(); state.fileName = upload.filename; state.size = 0; state.success = false; state.error = ""; uploadStartTime = millis(); lastLoggedSize = 0; state.bufferPos = 0; totalWriteTime = 0; writeCount = 0; // Get upload path from query parameter (defaults to root if not specified) // Note: We use query parameter instead of form data because multipart form // fields aren't available until after file upload completes if (server->hasArg("path")) { state.path = server->arg("path"); // Ensure path starts with / if (!state.path.startsWith("/")) { state.path = "/" + state.path; } // Remove trailing slash unless it's root if (state.path.length() > 1 && state.path.endsWith("/")) { state.path = state.path.substring(0, state.path.length() - 1); } } else { state.path = "/"; } LOG_DBG("WEB", "[UPLOAD] START: %s to path: %s", state.fileName.c_str(), state.path.c_str()); LOG_DBG("WEB", "[UPLOAD] Free heap: %d bytes", ESP.getFreeHeap()); // Create file path String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName; // Check if file already exists - SD operations can be slow esp_task_wdt_reset(); if (Storage.exists(filePath.c_str())) { LOG_DBG("WEB", "[UPLOAD] Overwriting existing file: %s", filePath.c_str()); esp_task_wdt_reset(); Storage.remove(filePath.c_str()); } // Open file for writing - this can be slow due to FAT cluster allocation esp_task_wdt_reset(); if (!Storage.openFileForWrite("WEB", filePath, state.file)) { state.error = "Failed to create file on SD card"; LOG_DBG("WEB", "[UPLOAD] FAILED to create file: %s", filePath.c_str()); return; } esp_task_wdt_reset(); LOG_DBG("WEB", "[UPLOAD] File created successfully: %s", filePath.c_str()); } else if (upload.status == UPLOAD_FILE_WRITE) { if (state.file && state.error.isEmpty()) { // Buffer incoming data and flush when buffer is full // This reduces SD card write operations and improves throughput const uint8_t* data = upload.buf; size_t remaining = upload.currentSize; while (remaining > 0) { const size_t space = UploadState::UPLOAD_BUFFER_SIZE - state.bufferPos; const size_t toCopy = (remaining < space) ? remaining : space; memcpy(state.buffer.data() + state.bufferPos, data, toCopy); state.bufferPos += toCopy; data += toCopy; remaining -= toCopy; // Flush buffer when full if (state.bufferPos >= UploadState::UPLOAD_BUFFER_SIZE) { if (!flushUploadBuffer(state)) { state.error = "Failed to write to SD card - disk may be full"; state.file.close(); return; } } } state.size += upload.currentSize; // Log progress every 100KB if (state.size - lastLoggedSize >= 102400) { const unsigned long elapsed = millis() - uploadStartTime; const float kbps = (elapsed > 0) ? (state.size / 1024.0) / (elapsed / 1000.0) : 0; LOG_DBG("WEB", "[UPLOAD] %d bytes (%.1f KB), %.1f KB/s, %d writes", state.size, state.size / 1024.0, kbps, writeCount); lastLoggedSize = state.size; } } } else if (upload.status == UPLOAD_FILE_END) { if (state.file) { // Flush any remaining buffered data if (!flushUploadBuffer(state)) { state.error = "Failed to write final data to SD card"; } state.file.close(); if (state.error.isEmpty()) { state.success = true; const unsigned long elapsed = millis() - uploadStartTime; const float avgKbps = (elapsed > 0) ? (state.size / 1024.0) / (elapsed / 1000.0) : 0; const float writePercent = (elapsed > 0) ? (totalWriteTime * 100.0 / elapsed) : 0; LOG_DBG("WEB", "[UPLOAD] Complete: %s (%d bytes in %lu ms, avg %.1f KB/s)", state.fileName.c_str(), state.size, elapsed, avgKbps); LOG_DBG("WEB", "[UPLOAD] Diagnostics: %d writes, total write time: %lu ms (%.1f%%)", writeCount, totalWriteTime, writePercent); // Clear epub cache to prevent stale metadata issues when overwriting files String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName; clearEpubCacheIfNeeded(filePath); } } } else if (upload.status == UPLOAD_FILE_ABORTED) { state.bufferPos = 0; // Discard buffered data if (state.file) { state.file.close(); // Try to delete the incomplete file String filePath = state.path; if (!filePath.endsWith("/")) filePath += "/"; filePath += state.fileName; Storage.remove(filePath.c_str()); } state.error = "Upload aborted"; LOG_DBG("WEB", "Upload aborted"); } } void CrossPointWebServer::handleUploadPost(UploadState& state) const { if (state.success) { server->send(200, "text/plain", "File uploaded successfully: " + state.fileName); } else { const String error = state.error.isEmpty() ? "Unknown error during upload" : state.error; server->send(400, "text/plain", error); } } void CrossPointWebServer::handleCreateFolder() const { // Get folder name from form data if (!server->hasArg("name")) { server->send(400, "text/plain", "Missing folder name"); return; } const String folderName = server->arg("name"); // Validate folder name if (folderName.isEmpty()) { server->send(400, "text/plain", "Folder name cannot be empty"); return; } // Get parent path String parentPath = "/"; if (server->hasArg("path")) { parentPath = server->arg("path"); if (!parentPath.startsWith("/")) { parentPath = "/" + parentPath; } if (parentPath.length() > 1 && parentPath.endsWith("/")) { parentPath = parentPath.substring(0, parentPath.length() - 1); } } // Build full folder path String folderPath = parentPath; if (!folderPath.endsWith("/")) folderPath += "/"; folderPath += folderName; LOG_DBG("WEB", "Creating folder: %s", folderPath.c_str()); // Check if already exists if (Storage.exists(folderPath.c_str())) { server->send(400, "text/plain", "Folder already exists"); return; } // Create the folder if (Storage.mkdir(folderPath.c_str())) { LOG_DBG("WEB", "Folder created successfully: %s", folderPath.c_str()); server->send(200, "text/plain", "Folder created: " + folderName); } else { LOG_DBG("WEB", "Failed to create folder: %s", folderPath.c_str()); server->send(500, "text/plain", "Failed to create folder"); } } void CrossPointWebServer::handleRename() const { if (!server->hasArg("path") || !server->hasArg("name")) { server->send(400, "text/plain", "Missing path or new name"); return; } String itemPath = normalizeWebPath(server->arg("path")); String newName = server->arg("name"); newName.trim(); if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; } if (newName.isEmpty()) { server->send(400, "text/plain", "New name cannot be empty"); return; } if (newName.indexOf('/') >= 0 || newName.indexOf('\\') >= 0) { server->send(400, "text/plain", "Invalid file name"); return; } if (isProtectedItemName(newName)) { server->send(403, "text/plain", "Cannot rename to protected name"); return; } const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (isProtectedItemName(itemName)) { server->send(403, "text/plain", "Cannot rename protected item"); return; } if (newName == itemName) { server->send(200, "text/plain", "Name unchanged"); return; } if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; } FsFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } const bool isDir = file.isDirectory(); String parentPath = itemPath.substring(0, itemPath.lastIndexOf('/')); if (parentPath.isEmpty()) { parentPath = "/"; } String newPath = parentPath; if (!newPath.endsWith("/")) { newPath += "/"; } newPath += newName; if (Storage.exists(newPath.c_str())) { file.close(); server->send(409, "text/plain", "Target already exists"); return; } if (isDir) { clearEpubCachesInDirectory(itemPath); } else { clearEpubCacheIfNeeded(itemPath); } const bool success = file.rename(newPath.c_str()); file.close(); if (success) { LOG_DBG("WEB", "Renamed: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(200, "text/plain", "Renamed successfully"); } else { LOG_ERR("WEB", "Failed to rename: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(500, "text/plain", "Failed to rename"); } } void CrossPointWebServer::handleMove() const { if (!server->hasArg("path") || !server->hasArg("dest")) { server->send(400, "text/plain", "Missing path or destination"); return; } String itemPath = normalizeWebPath(server->arg("path")); String destPath = normalizeWebPath(server->arg("dest")); if (itemPath.isEmpty() || itemPath == "/") { server->send(400, "text/plain", "Invalid path"); return; } if (destPath.isEmpty()) { server->send(400, "text/plain", "Invalid destination"); return; } const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); if (isProtectedItemName(itemName)) { server->send(403, "text/plain", "Cannot move protected item"); return; } if (!Storage.exists(itemPath.c_str())) { server->send(404, "text/plain", "Item not found"); return; } FsFile file = Storage.open(itemPath.c_str()); if (!file) { server->send(500, "text/plain", "Failed to open file"); return; } const bool isDir = file.isDirectory(); if (isDir) { String destWithSlash = destPath; if (!destWithSlash.endsWith("/")) destWithSlash += "/"; String itemWithSlash = itemPath; if (!itemWithSlash.endsWith("/")) itemWithSlash += "/"; if (destPath == itemPath || destWithSlash.startsWith(itemWithSlash)) { file.close(); server->send(400, "text/plain", "Cannot move folder into itself"); return; } } if (!Storage.exists(destPath.c_str())) { file.close(); server->send(404, "text/plain", "Destination not found"); return; } FsFile destDir = Storage.open(destPath.c_str()); if (!destDir || !destDir.isDirectory()) { if (destDir) { destDir.close(); } file.close(); server->send(400, "text/plain", "Destination is not a folder"); return; } destDir.close(); String newPath = destPath; if (!newPath.endsWith("/")) { newPath += "/"; } newPath += itemName; if (newPath == itemPath) { file.close(); server->send(200, "text/plain", "Already in destination"); return; } if (Storage.exists(newPath.c_str())) { file.close(); server->send(409, "text/plain", "Target already exists"); return; } if (isDir) { clearEpubCachesInDirectory(itemPath); } else { clearEpubCacheIfNeeded(itemPath); } const bool success = file.rename(newPath.c_str()); file.close(); if (success) { LOG_DBG("WEB", "Moved: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(200, "text/plain", "Moved successfully"); } else { LOG_ERR("WEB", "Failed to move: %s -> %s", itemPath.c_str(), newPath.c_str()); server->send(500, "text/plain", "Failed to move"); } } void CrossPointWebServer::handleDelete() const { // To ensure backwards compatibility, plain `path` is mapped // to a single element JSON array. bool hasPathArg = server->hasArg("path"); bool hasPathsArg = server->hasArg("paths"); // Check 'paths' or `path` argument is provided if (!(hasPathArg || hasPathsArg)) { server->send(400, "text/plain", "Missing `path` or `paths` argument"); return; } if (hasPathArg && hasPathsArg) { server->send(400, "text/plain", "Provide either 'path' or 'paths', not both"); return; } // Parse paths String pathsArg; JsonDocument doc; DeserializationError error = DeserializationError(DeserializationError::Code::Ok); if (hasPathsArg) { pathsArg = server->arg("paths"); error = deserializeJson(doc, pathsArg); } else { pathsArg = server->arg("path"); doc.add(pathsArg); } if (error) { server->send(400, "text/plain", "Invalid paths format"); return; } auto paths = doc.as(); if (paths.isNull() || paths.size() == 0) { server->send(400, "text/plain", "No paths provided"); return; } // Iterate over paths and delete each item bool allSuccess = true; String failedItems; for (const auto& p : paths) { auto itemPath = p.as(); // Validate path if (itemPath.isEmpty() || itemPath == "/") { failedItems += itemPath + " (cannot delete root); "; allSuccess = false; continue; } // Ensure path starts with / if (!itemPath.startsWith("/")) { itemPath = "/" + itemPath; } // Security check: prevent deletion of protected items const String itemName = itemPath.substring(itemPath.lastIndexOf('/') + 1); // Hidden/system files are protected if (itemName.startsWith(".")) { failedItems += itemPath + " (hidden/system file); "; allSuccess = false; continue; } // Check against explicitly protected items bool isProtected = false; for (size_t i = 0; i < HIDDEN_ITEMS_COUNT; i++) { if (itemName.equals(HIDDEN_ITEMS[i])) { isProtected = true; break; } } if (isProtected) { failedItems += itemPath + " (protected file); "; allSuccess = false; continue; } // Check if item exists if (!Storage.exists(itemPath.c_str())) { failedItems += itemPath + " (not found); "; allSuccess = false; continue; } // Decide whether it's a directory or file by opening it bool success = false; FsFile f = Storage.open(itemPath.c_str()); if (f && f.isDirectory()) { // For folders, ensure empty before removing FsFile entry = f.openNextFile(); if (entry) { entry.close(); f.close(); failedItems += itemPath + " (folder not empty); "; allSuccess = false; continue; } f.close(); success = Storage.rmdir(itemPath.c_str()); } else { // It's a file (or couldn't open as dir) — remove file if (f) f.close(); success = Storage.remove(itemPath.c_str()); clearEpubCacheIfNeeded(itemPath); } if (!success) { failedItems += itemPath + " (deletion failed); "; allSuccess = false; } } if (allSuccess) { server->send(200, "text/plain", "All items deleted successfully"); } else { server->send(500, "text/plain", "Failed to delete some items: " + failedItems); } } void CrossPointWebServer::handleSettingsPage() const { sendHtmlContent(server.get(), SettingsPageHtml, sizeof(SettingsPageHtml)); LOG_DBG("WEB", "Served settings page"); } void CrossPointWebServer::handleGetSettings() const { const auto& settings = getSettingsList(); String result; result.reserve(4096); result += "["; char output[512]; constexpr size_t outputSize = sizeof(output); bool seenFirst = false; JsonDocument doc; for (const auto& sBase : settings) { if (!sBase.key) continue; // Skip ACTION-only entries // Enrich the font-family entry with current SD card families. SettingInfo sLocal; const SettingInfo* sPtr = &sBase; if (std::strcmp(sBase.key, "fontFamily") == 0) { sLocal = sBase; const uint8_t n = fontFamilyOptionCount(); sLocal.enumLabels.clear(); sLocal.enumLabels.reserve(n); for (uint8_t i = 0; i < n; i++) sLocal.enumLabels.push_back(fontFamilyOptionLabel(i)); sPtr = &sLocal; } const SettingInfo& s = *sPtr; doc.clear(); doc["key"] = s.key; doc["name"] = I18N.get(s.nameId); doc["category"] = I18N.get(s.category); doc["subcategory"] = s.subcategory != StrId::STR_NONE_OPT ? I18N.get(s.subcategory) : ""; doc["submenu"] = s.submenu != StrId::STR_NONE_OPT ? I18N.get(s.submenu) : ""; switch (s.type) { case SettingType::TOGGLE: { doc["type"] = "toggle"; if (s.valuePtr) { doc["value"] = static_cast(SETTINGS.*(s.valuePtr)); } break; } case SettingType::ENUM: { doc["type"] = "enum"; if (s.valuePtr) { doc["value"] = static_cast(SETTINGS.*(s.valuePtr)); } else if (s.valueGetter) { doc["value"] = static_cast(s.callValueGetter()); } JsonArray options = doc["options"].to(); if (!s.enumLabels.empty()) { for (const auto& opt : s.enumLabels) { options.add(opt); } } else { for (const auto& opt : s.enumValues) { options.add(I18N.get(opt)); } } break; } case SettingType::VALUE: { doc["type"] = "value"; if (s.valuePtr) { doc["value"] = static_cast(SETTINGS.*(s.valuePtr)); } doc["min"] = s.valueRange.min; doc["max"] = s.valueRange.max; doc["step"] = s.valueRange.step; break; } case SettingType::STRING: { doc["type"] = "string"; if (s.stringGetter) { doc["value"] = s.callStringGetter(); } else if (s.stringMaxLen > 0) { doc["value"] = reinterpret_cast(&SETTINGS) + s.stringOffset; } break; } default: continue; } const size_t written = serializeJson(doc, output, outputSize); const char* jsonEntry = output; String dynBuffer; if (written >= outputSize) { serializeJson(doc, dynBuffer); jsonEntry = dynBuffer.c_str(); } if (seenFirst) { result += ","; } else { seenFirst = true; } result += jsonEntry; } result += "]"; server->send(200, "application/json", result); LOG_DBG("WEB", "Served settings API"); } void CrossPointWebServer::handlePostSettings() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; } const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; } const auto& settings = getSettingsList(); int applied = 0; for (const auto& s : settings) { if (!s.key) continue; if (!doc[s.key].is()) continue; switch (s.type) { case SettingType::TOGGLE: { const int val = doc[s.key].as() ? 1 : 0; if (s.valuePtr) { SETTINGS.*(s.valuePtr) = val; } applied++; break; } case SettingType::ENUM: { const int val = doc[s.key].as(); // For fontFamily the enumLabels in the static list are empty by design // (built lazily by handleGetSettings); use the dynamic option count instead. const int count = (std::strcmp(s.key, "fontFamily") == 0) ? static_cast(fontFamilyOptionCount()) : static_cast(s.enumLabels.empty() ? s.enumValues.size() : s.enumLabels.size()); if (val >= 0 && val < count) { if (s.valuePtr) { SETTINGS.*(s.valuePtr) = static_cast(val); } else if (s.valueSetter) { s.callValueSetter(static_cast(val)); } applied++; } break; } case SettingType::VALUE: { const int val = doc[s.key].as(); if (val >= s.valueRange.min && val <= s.valueRange.max) { if (s.valuePtr) { SETTINGS.*(s.valuePtr) = static_cast(val); } applied++; } break; } case SettingType::STRING: { const std::string val = doc[s.key].as(); if (s.stringSetter) { s.callStringSetter(val); } else if (s.stringMaxLen > 0) { char* ptr = reinterpret_cast(&SETTINGS) + s.stringOffset; strncpy(ptr, val.c_str(), s.stringMaxLen - 1); ptr[s.stringMaxLen - 1] = '\0'; } applied++; break; } default: break; } } SETTINGS.saveToFile(); LOG_DBG("WEB", "Applied %d setting(s)", applied); server->send(200, "text/plain", String("Applied ") + String(applied) + " setting(s)"); } // ---- Font Management API ---- namespace { struct RemoteManifestFile { std::string name; size_t size = 0; }; struct RemoteManifestFamily { std::string name; std::string description; std::vector files; size_t totalSize = 0; bool installed = false; bool hasUpdate = false; }; bool fetchRemoteFontManifest(FontInstaller& installer, std::vector& outFamilies, std::string& outBaseUrl, std::string& outError) { static constexpr const char* MANIFEST_TMP = "/fonts_manifest_web.tmp"; auto result = HttpDownloader::downloadToFile(FONT_MANIFEST_URL, MANIFEST_TMP, nullptr); if (result != HttpDownloader::OK) { outError = "Failed to fetch font manifest"; Storage.remove(MANIFEST_TMP); return false; } FsFile manifestFile; if (!Storage.openFileForRead("WEB", MANIFEST_TMP, manifestFile)) { outError = "Failed to open downloaded manifest"; Storage.remove(MANIFEST_TMP); return false; } JsonDocument doc; DeserializationError err = deserializeJson(doc, manifestFile); manifestFile.close(); Storage.remove(MANIFEST_TMP); if (err) { outError = "Failed to parse font manifest"; return false; } const int version = doc["version"] | 0; if (version != 1) { outError = "Unsupported manifest version"; return false; } outBaseUrl = doc["baseUrl"] | ""; outFamilies.clear(); JsonArray familiesArr = doc["families"].as(); outFamilies.reserve(familiesArr.size()); for (JsonObject fObj : familiesArr) { RemoteManifestFamily family; family.name = fObj["name"] | ""; family.description = fObj["description"] | ""; for (JsonObject fileObj : fObj["files"].as()) { RemoteManifestFile file; file.name = fileObj["name"] | ""; file.size = static_cast(fileObj["size"] | 0); family.totalSize += file.size; family.files.push_back(std::move(file)); } family.installed = installer.isFamilyInstalled(family.name.c_str()); family.hasUpdate = false; if (family.installed) { for (const auto& file : family.files) { char path[128]; FontInstaller::buildFontPath(family.name.c_str(), file.name.c_str(), path, sizeof(path)); FsFile f; if (Storage.openFileForRead("WEB", path, f)) { const size_t actual = static_cast(f.size()); f.close(); if (actual != file.size) { family.hasUpdate = true; break; } } else { family.hasUpdate = true; break; } } } outFamilies.push_back(std::move(family)); } return true; } bool installRemoteFamily(const RemoteManifestFamily& family, const std::string& baseUrl, FontInstaller& installer, std::string& outError) { char liveDir[128]; char stagingDir[128]; char backupDir[128]; snprintf(liveDir, sizeof(liveDir), "%s/%s", SdCardFontRegistry::FONTS_DIR, family.name.c_str()); snprintf(stagingDir, sizeof(stagingDir), "%s/%s__staging", SdCardFontRegistry::FONTS_DIR, family.name.c_str()); snprintf(backupDir, sizeof(backupDir), "%s/%s__backup", SdCardFontRegistry::FONTS_DIR, family.name.c_str()); if (Storage.exists(stagingDir) && !Storage.removeDir(stagingDir)) { outError = "Failed to prepare staging area"; return false; } if (!Storage.mkdir(stagingDir)) { outError = "Failed to create staging area"; return false; } for (const auto& file : family.files) { esp_task_wdt_reset(); char stagedPath[128]; snprintf(stagedPath, sizeof(stagedPath), "%s/%s", stagingDir, file.name.c_str()); const std::string url = baseUrl + file.name; auto result = HttpDownloader::downloadToFile(url, stagedPath, nullptr); if (result != HttpDownloader::OK) { Storage.removeDir(stagingDir); outError = std::string("Download failed: ") + file.name; return false; } if (!installer.validateCpfontFile(stagedPath)) { Storage.removeDir(stagingDir); outError = std::string("Invalid font file: ") + file.name; return false; } } const bool hadLiveDir = Storage.exists(liveDir); if (Storage.exists(backupDir) && !Storage.removeDir(backupDir)) { Storage.removeDir(stagingDir); outError = "Failed to prepare backup area"; return false; } if (hadLiveDir && !Storage.rename(liveDir, backupDir)) { Storage.removeDir(stagingDir); outError = "Failed to replace installed font"; return false; } if (!Storage.rename(stagingDir, liveDir)) { if (hadLiveDir && Storage.exists(backupDir)) { Storage.rename(backupDir, liveDir); } Storage.removeDir(stagingDir); outError = "Failed to finalize font install"; return false; } if (Storage.exists(backupDir)) { Storage.removeDir(backupDir); } return true; } } // namespace void CrossPointWebServer::handleFontsPage() const { sendHtmlContent(server.get(), FontsPageHtml, sizeof(FontsPageHtml)); LOG_DBG("WEB", "Served fonts page"); } void CrossPointWebServer::handleFontList() { FontInstaller installer(sdFontSystem.registry()); installer.refreshRegistry(); const auto& families = sdFontSystem.registry().getFamilies(); JsonDocument doc; JsonArray arr = doc["families"].to(); doc["maxFamilies"] = SdCardFontRegistry::MAX_SD_FAMILIES; for (const auto& family : families) { JsonObject fObj = arr.add(); fObj["name"] = family.name; JsonArray sizes = fObj["sizes"].to(); for (uint8_t s : family.availableSizes()) { sizes.add(s); } JsonArray files = fObj["files"].to(); for (const auto& file : family.files) { JsonObject fileObj = files.add(); const char* name = strrchr(file.path.c_str(), '/'); fileObj["name"] = name ? name + 1 : file.path.c_str(); FsFile f; if (Storage.openFileForRead("WEB", file.path.c_str(), f)) { fileObj["size"] = static_cast(f.size()); f.close(); } else { fileObj["size"] = 0; } } } String json; serializeJson(doc, json); server->send(200, "application/json", json); } void CrossPointWebServer::handleFontManifest() { FontInstaller installer(sdFontSystem.registry()); installer.refreshRegistry(); std::vector families; std::string baseUrl; std::string error; if (!fetchRemoteFontManifest(installer, families, baseUrl, error)) { JsonDocument errDoc; errDoc["ok"] = false; errDoc["error"] = error; String out; serializeJson(errDoc, out); server->send(500, "application/json", out); return; } JsonDocument doc; doc["ok"] = true; doc["baseUrl"] = baseUrl; JsonArray arr = doc["families"].to(); for (const auto& family : families) { JsonObject obj = arr.add(); obj["name"] = family.name; obj["description"] = family.description; obj["installed"] = family.installed; obj["hasUpdate"] = family.hasUpdate; obj["totalSize"] = static_cast(family.totalSize); obj["fileCount"] = static_cast(family.files.size()); } String out; serializeJson(doc, out); server->send(200, "application/json", out); } void CrossPointWebServer::handleFontDownload() { String body = server->arg("plain"); JsonDocument req; if (deserializeJson(req, body)) { server->send(400, "application/json", "{\"ok\":false,\"error\":\"Invalid request\"}"); return; } const bool installAll = req["all"] | false; const std::string requestedFamily = req["family"] | ""; if (!installAll && requestedFamily.empty()) { server->send(400, "application/json", "{\"ok\":false,\"error\":\"Missing family\"}"); return; } FontInstaller installer(sdFontSystem.registry()); installer.refreshRegistry(); std::vector families; std::string baseUrl; std::string error; if (!fetchRemoteFontManifest(installer, families, baseUrl, error)) { JsonDocument errDoc; errDoc["ok"] = false; errDoc["error"] = error; String out; serializeJson(errDoc, out); server->send(500, "application/json", out); return; } std::vector targets; if (installAll) { for (auto& family : families) { if (!family.installed || family.hasUpdate) { targets.push_back(&family); } } } else { for (auto& family : families) { if (family.name == requestedFamily) { targets.push_back(&family); break; } } if (targets.empty()) { server->send(404, "application/json", "{\"ok\":false,\"error\":\"Family not found in manifest\"}"); return; } } size_t installedCount = 0; for (auto* family : targets) { esp_task_wdt_reset(); if (!installRemoteFamily(*family, baseUrl, installer, error)) { JsonDocument errDoc; errDoc["ok"] = false; errDoc["error"] = error; errDoc["family"] = family->name; errDoc["installedCount"] = static_cast(installedCount); String out; serializeJson(errDoc, out); server->send(500, "application/json", out); return; } installedCount++; } installer.refreshRegistry(); JsonDocument res; res["ok"] = true; res["installedCount"] = static_cast(installedCount); String out; serializeJson(res, out); server->send(200, "application/json", out); } void CrossPointWebServer::handleFontUploadData() { HTTPUpload& up = server->upload(); switch (up.status) { case UPLOAD_FILE_START: { esp_task_wdt_reset(); String family = server->arg("family"); fontUpload.valid = false; fontUpload.magicChecked = false; fontUpload.headerBytesReceived = 0; fontUpload.bytesWritten = 0; fontUpload.bufferPos = 0; if (!FontInstaller::isValidFamilyName(family.c_str())) { LOG_ERR("WEB", "Invalid font family name: %s", family.c_str()); break; } String filename = up.filename; if (!filename.endsWith(".cpfont")) { LOG_ERR("WEB", "Not a .cpfont file: %s", filename.c_str()); break; } if (filename.indexOf('/') >= 0 || filename.indexOf('\\') >= 0 || filename.indexOf("..") >= 0) { LOG_ERR("WEB", "Invalid font filename: %s", filename.c_str()); break; } fontUpload.familyName = family.c_str(); FontInstaller installer(sdFontSystem.registry()); if (!installer.ensureFamilyDir(family.c_str())) { LOG_ERR("WEB", "Failed to create font family dir"); break; } char path[128]; FontInstaller::buildFontPath(family.c_str(), filename.c_str(), path, sizeof(path)); fontUpload.filePath = path; if (!Storage.openFileForWrite("WEB", path, fontUpload.file)) { LOG_ERR("WEB", "Failed to open font file for write: %s", path); break; } fontUpload.valid = true; LOG_DBG("WEB", "Font upload started: %s -> %s", filename.c_str(), path); break; } case UPLOAD_FILE_WRITE: { if (!fontUpload.valid) break; esp_task_wdt_reset(); if (!fontUpload.magicChecked) { size_t needed = 8 - fontUpload.headerBytesReceived; size_t take = (up.currentSize < needed) ? up.currentSize : needed; if (take > 0) { memcpy(fontUpload.header + fontUpload.headerBytesReceived, up.buf, take); fontUpload.headerBytesReceived += take; } if (fontUpload.headerBytesReceived == 8) { if (memcmp(fontUpload.header, "CPFONT\0\0", 8) != 0) { LOG_ERR("WEB", "Invalid .cpfont magic bytes"); fontUpload.valid = false; fontUpload.file.close(); return; } fontUpload.magicChecked = true; } } size_t remaining = up.currentSize; const uint8_t* src = up.buf; while (remaining > 0) { size_t space = FontUploadState::BUFFER_SIZE - fontUpload.bufferPos; size_t chunk = (remaining < space) ? remaining : space; memcpy(fontUpload.buffer.data() + fontUpload.bufferPos, src, chunk); fontUpload.bufferPos += chunk; src += chunk; remaining -= chunk; if (fontUpload.bufferPos >= FontUploadState::BUFFER_SIZE) { const size_t expected = fontUpload.bufferPos; const size_t written = fontUpload.file.write(fontUpload.buffer.data(), expected); fontUpload.bytesWritten += written; if (written != expected) { LOG_ERR("WEB", "Failed writing uploaded font chunk (%u/%u bytes)", static_cast(written), static_cast(expected)); fontUpload.valid = false; fontUpload.file.close(); return; } fontUpload.bufferPos = 0; esp_task_wdt_reset(); } } break; } case UPLOAD_FILE_END: { if (fontUpload.valid && !fontUpload.magicChecked) { LOG_ERR("WEB", "Invalid .cpfont upload: header not fully received"); fontUpload.valid = false; } if (fontUpload.valid && fontUpload.bufferPos > 0) { const size_t expected = fontUpload.bufferPos; const size_t written = fontUpload.file.write(fontUpload.buffer.data(), expected); fontUpload.bytesWritten += written; if (written != expected) { LOG_ERR("WEB", "Failed flushing uploaded font chunk (%u/%u bytes)", static_cast(written), static_cast(expected)); fontUpload.valid = false; } fontUpload.bufferPos = 0; } fontUpload.file.close(); if (!fontUpload.valid && !fontUpload.filePath.empty()) { Storage.remove(fontUpload.filePath.c_str()); } LOG_DBG("WEB", "Font upload end: valid=%d, %zu bytes", fontUpload.valid, fontUpload.bytesWritten); break; } case UPLOAD_FILE_ABORTED: { fontUpload.file.close(); if (!fontUpload.filePath.empty()) { Storage.remove(fontUpload.filePath.c_str()); } fontUpload.valid = false; LOG_DBG("WEB", "Font upload aborted"); break; } } } void CrossPointWebServer::handleFontUpload() { if (fontUpload.valid) { FontInstaller installer(sdFontSystem.registry()); installer.refreshRegistry(); server->send(200, "application/json", "{\"ok\":true}"); LOG_DBG("WEB", "Font upload complete: %s", fontUpload.filePath.c_str()); } else { server->send(400, "application/json", "{\"error\":\"Invalid .cpfont file\"}"); } } void CrossPointWebServer::handleFontDelete() { String body = server->arg("plain"); JsonDocument doc; DeserializationError err = deserializeJson(doc, body); if (err || !doc["family"].is()) { server->send(400, "application/json", "{\"error\":\"Invalid request\"}"); return; } const char* familyName = doc["family"]; FontInstaller installer(sdFontSystem.registry()); auto result = installer.deleteFamily(familyName); if (result == FontInstaller::Error::OK) { installer.refreshRegistry(); server->send(200, "application/json", "{\"ok\":true}"); LOG_DBG("WEB", "Deleted font family: %s", familyName); } else { server->send(500, "application/json", "{\"error\":\"Delete failed\"}"); LOG_ERR("WEB", "Failed to delete font family: %s", familyName); } } // ---- Wi-Fi Credentials API ---- void CrossPointWebServer::handleGetWifiNetworks() const { const auto& credentials = WIFI_STORE.getCredentials(); const std::string& lastConnectedSsid = WIFI_STORE.getLastConnectedSsid(); // Stream JSON array incrementally to avoid allocating the full response in memory server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("["); char output[320]; constexpr size_t outputSize = sizeof(output); JsonDocument doc; for (size_t i = 0; i < credentials.size(); i++) { doc.clear(); doc["index"] = i; doc["ssid"] = credentials[i].ssid; // Never expose Wi-Fi passwords over the API — only indicate whether one is set doc["hasPassword"] = !credentials[i].password.empty(); doc["isLastConnected"] = credentials[i].ssid == lastConnectedSsid; const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) continue; if (i > 0) server->sendContent(","); server->sendContent(output); } server->sendContent("]"); server->sendContent(""); LOG_DBG("WEB", "Served Wi-Fi credentials API (%zu network(s))", credentials.size()); } void CrossPointWebServer::handlePostWifiNetwork() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; } const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; } std::string ssid = doc["ssid"] | std::string(""); if (ssid.empty()) { server->send(400, "text/plain", "SSID is required"); return; } // The password field is optional in the JSON payload. When absent (vs. present but empty), // preserve the existing password for updates. Empty passwords are valid for open networks. bool hasPasswordField = doc["password"].is() || doc["password"].is(); std::string password = doc["password"] | std::string(""); if (doc["index"].is()) { int idx = doc["index"].as(); const auto& credentials = WIFI_STORE.getCredentials(); if (idx < 0 || idx >= static_cast(credentials.size())) { server->send(400, "text/plain", "Invalid network index"); return; } const std::string oldSsid = credentials[static_cast(idx)].ssid; if (!hasPasswordField) { password = credentials[static_cast(idx)].password; } bool ok = true; if (oldSsid != ssid) { ok = WIFI_STORE.removeCredential(oldSsid) && WIFI_STORE.addCredential(ssid, password); } else { ok = WIFI_STORE.addCredential(ssid, password); } if (!ok) { server->send(400, "text/plain", "Failed to update Wi-Fi network"); return; } LOG_DBG("WEB", "Updated Wi-Fi network at index %d (SSID: %s)", idx, ssid.c_str()); } else { if (!WIFI_STORE.addCredential(ssid, password)) { server->send(400, "text/plain", "Cannot add network (limit reached)"); return; } LOG_DBG("WEB", "Added Wi-Fi network: %s", ssid.c_str()); } server->send(200, "text/plain", "OK"); } // Uses POST (not HTTP DELETE) because ESP32 WebServer doesn't support DELETE with body. void CrossPointWebServer::handleDeleteWifiNetwork() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; } const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; } if (!doc["index"].is()) { server->send(400, "text/plain", "Missing index"); return; } int idx = doc["index"].as(); const auto& credentials = WIFI_STORE.getCredentials(); if (idx < 0 || idx >= static_cast(credentials.size())) { server->send(400, "text/plain", "Invalid network index"); return; } const std::string ssid = credentials[static_cast(idx)].ssid; if (!WIFI_STORE.removeCredential(ssid)) { server->send(400, "text/plain", "Failed to delete Wi-Fi network"); return; } LOG_DBG("WEB", "Deleted Wi-Fi network at index %d (SSID: %s)", idx, ssid.c_str()); server->send(200, "text/plain", "OK"); } // ---- OPDS Server API ---- void CrossPointWebServer::handleGetOpdsServers() const { const auto& servers = OPDS_STORE.getServers(); // Stream JSON array incrementally to avoid allocating the full response in memory server->setContentLength(CONTENT_LENGTH_UNKNOWN); server->send(200, "application/json", ""); server->sendContent("["); char output[512]; constexpr size_t outputSize = sizeof(output); JsonDocument doc; bool seenFirst = false; for (size_t i = 0; i < servers.size(); i++) { doc.clear(); doc["index"] = i; doc["name"] = servers[i].name; doc["url"] = servers[i].url; doc["username"] = servers[i].username; // Never expose passwords over the API — only indicate whether one is set doc["hasPassword"] = !servers[i].password.empty(); const size_t written = serializeJson(doc, output, outputSize); if (written >= outputSize) continue; if (seenFirst) { server->sendContent(","); } seenFirst = true; server->sendContent(output); } server->sendContent("]"); server->sendContent(""); LOG_DBG("WEB", "Served OPDS servers API (%zu servers)", servers.size()); } void CrossPointWebServer::handlePostOpdsServer() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; } const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; } const std::string name = doc["name"] | std::string(""); const std::string rawUrl = doc["url"] | std::string(""); const std::string username = doc["username"] | std::string(""); // The password field is optional in the JSON payload. When absent (vs. present but empty), // we preserve the existing password — the web UI omits it when the user hasn't changed it. bool hasPasswordField = doc["password"].is() || doc["password"].is(); std::string password = doc["password"] | std::string(""); const auto normalizedUrl = OpdsServerValidation::normalizeUrl(rawUrl); if (!normalizedUrl) { server->send(400, "text/plain", "Invalid URL"); return; } if (name.size() > OpdsServerStore::MAX_NAME_LENGTH) { server->send(400, "text/plain", "Server name too long"); return; } if (normalizedUrl->size() > OpdsServerStore::MAX_URL_LENGTH) { server->send(400, "text/plain", "URL too long"); return; } if (username.size() > OpdsServerStore::MAX_USERNAME_LENGTH) { server->send(400, "text/plain", "Username too long"); return; } OpdsServer opdsServer; opdsServer.name = name; opdsServer.url = *normalizedUrl; opdsServer.username = username; if (doc["index"].is()) { int idx = doc["index"].as(); if (idx < 0 || idx >= static_cast(OPDS_STORE.getCount())) { server->send(400, "text/plain", "Invalid server index"); return; } // Preserve existing password if not explicitly provided if (!hasPasswordField) { const auto* existing = OPDS_STORE.getServer(static_cast(idx)); if (existing) password = existing->password; } if (password.size() > OpdsServerStore::MAX_PASSWORD_LENGTH) { server->send(400, "text/plain", "Password too long"); return; } opdsServer.password = password; if (!OPDS_STORE.updateServer(static_cast(idx), opdsServer)) { server->send(500, "text/plain", "Failed to save server"); return; } LOG_DBG("WEB", "Updated OPDS server at index %d", idx); } else { if (OPDS_STORE.getCount() >= OpdsServerStore::MAX_SERVERS) { server->send(400, "text/plain", "Cannot add server (limit reached)"); return; } if (password.size() > OpdsServerStore::MAX_PASSWORD_LENGTH) { server->send(400, "text/plain", "Password too long"); return; } opdsServer.password = password; const auto insertedIndex = OPDS_STORE.addServer(opdsServer); if (!insertedIndex) { server->send(500, "text/plain", "Failed to save server"); return; } LOG_DBG("WEB", "Added new OPDS server at index %zu: %s", *insertedIndex, opdsServer.name.c_str()); } server->send(200, "text/plain", "OK"); } // Uses POST (not HTTP DELETE) because ESP32 WebServer doesn't support DELETE with body. void CrossPointWebServer::handleDeleteOpdsServer() { if (!server->hasArg("plain")) { server->send(400, "text/plain", "Missing JSON body"); return; } const String body = server->arg("plain"); JsonDocument doc; const DeserializationError err = deserializeJson(doc, body); if (err) { server->send(400, "text/plain", String("Invalid JSON: ") + err.c_str()); return; } if (!doc["index"].is()) { server->send(400, "text/plain", "Missing index"); return; } int idx = doc["index"].as(); if (idx < 0 || idx >= static_cast(OPDS_STORE.getCount())) { server->send(400, "text/plain", "Invalid server index"); return; } if (!OPDS_STORE.removeServer(static_cast(idx))) { server->send(500, "text/plain", "Failed to delete server"); return; } LOG_DBG("WEB", "Deleted OPDS server at index %d", idx); server->send(200, "text/plain", "OK"); } // WebSocket callback trampoline void CrossPointWebServer::wsEventCallback(uint8_t num, WStype_t type, uint8_t* payload, size_t length) { if (wsInstance) { wsInstance->onWebSocketEvent(num, type, payload, length); } } // WebSocket event handler for fast binary uploads // Protocol: // 1. Client sends TEXT message: "START:::" // 2. Client sends BINARY messages with file data chunks // 3. Server sends TEXT "PROGRESS::" after each chunk // 4. Server sends TEXT "DONE" or "ERROR:" when complete void CrossPointWebServer::onWebSocketEvent(uint8_t num, WStype_t type, uint8_t* payload, size_t length) { switch (type) { case WStype_DISCONNECTED: LOG_DBG("WS", "Client %u disconnected", num); // Only clean up if this is the client that owns the active upload. // A new client may have already started a fresh upload before this // DISCONNECTED event fires (race condition on quick cancel + retry). if (num == wsUploadClientNum && wsUploadInProgress && wsUploadFile) { abortWsUpload("WS"); } break; case WStype_CONNECTED: { LOG_DBG("WS", "Client %u connected", num); break; } case WStype_TEXT: { // Parse control messages String msg = String((char*)payload); LOG_DBG("WS", "Text from client %u: %s", num, msg.c_str()); if (msg.startsWith("START:")) { // Reject any START while an upload is already active to prevent // leaking the open wsUploadFile handle (owning client re-START included) if (wsUploadInProgress) { wsServer->sendTXT(num, "ERROR:Upload already in progress"); break; } // Parse: START::: int firstColon = msg.indexOf(':', 6); int secondColon = msg.indexOf(':', firstColon + 1); if (firstColon > 0 && secondColon > 0) { wsUploadFileName = msg.substring(6, firstColon); String sizeToken = msg.substring(firstColon + 1, secondColon); bool sizeValid = sizeToken.length() > 0; int digitStart = (sizeValid && sizeToken[0] == '+') ? 1 : 0; if (digitStart > 0 && sizeToken.length() < 2) sizeValid = false; for (int i = digitStart; i < (int)sizeToken.length() && sizeValid; i++) { if (!isdigit((unsigned char)sizeToken[i])) sizeValid = false; } if (!sizeValid) { LOG_DBG("WS", "START rejected: invalid size token '%s'", sizeToken.c_str()); wsServer->sendTXT(num, "ERROR:Invalid START format"); return; } wsUploadSize = sizeToken.toInt(); wsUploadPath = msg.substring(secondColon + 1); wsUploadReceived = 0; wsLastProgressSent = 0; wsUploadStartTime = millis(); // Ensure path is valid if (!wsUploadPath.startsWith("/")) wsUploadPath = "/" + wsUploadPath; if (wsUploadPath.length() > 1 && wsUploadPath.endsWith("/")) { wsUploadPath = wsUploadPath.substring(0, wsUploadPath.length() - 1); } // Build file path String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName; LOG_DBG("WS", "Starting upload: %s (%d bytes) to %s", wsUploadFileName.c_str(), wsUploadSize, filePath.c_str()); // Check if file exists and remove it esp_task_wdt_reset(); if (Storage.exists(filePath.c_str())) { Storage.remove(filePath.c_str()); } // Open file for writing esp_task_wdt_reset(); if (!Storage.openFileForWrite("WS", filePath, wsUploadFile)) { wsServer->sendTXT(num, "ERROR:Failed to create file"); wsUploadInProgress = false; wsUploadClientNum = 255; return; } esp_task_wdt_reset(); // Zero-byte upload: complete immediately without waiting for BIN frames if (wsUploadSize == 0) { wsUploadFile.close(); wsLastCompleteName = wsUploadFileName; wsLastCompleteSize = 0; wsLastCompleteAt = millis(); LOG_DBG("WS", "Zero-byte upload complete: %s", filePath.c_str()); clearEpubCacheIfNeeded(filePath); wsServer->sendTXT(num, "DONE"); wsLastProgressSent = 0; break; } wsUploadClientNum = num; wsUploadInProgress = true; wsServer->sendTXT(num, "READY"); } else { wsServer->sendTXT(num, "ERROR:Invalid START format"); } } break; } case WStype_BIN: { if (!wsUploadInProgress || !wsUploadFile || num != wsUploadClientNum) { wsServer->sendTXT(num, "ERROR:No upload in progress"); return; } // Write binary data directly to file size_t remaining = wsUploadSize - wsUploadReceived; if (length > remaining) { abortWsUpload("WS"); wsServer->sendTXT(num, "ERROR:Upload overflow"); return; } esp_task_wdt_reset(); size_t written = wsUploadFile.write(payload, length); esp_task_wdt_reset(); if (written != length) { abortWsUpload("WS"); wsServer->sendTXT(num, "ERROR:Write failed - disk full?"); return; } wsUploadReceived += written; // Send progress update (every 64KB or at end) if (wsUploadReceived - wsLastProgressSent >= 65536 || wsUploadReceived >= wsUploadSize) { String progress = "PROGRESS:" + String(wsUploadReceived) + ":" + String(wsUploadSize); wsServer->sendTXT(num, progress); wsLastProgressSent = wsUploadReceived; } // Check if upload complete if (wsUploadReceived >= wsUploadSize) { wsUploadFile.close(); wsUploadInProgress = false; wsUploadClientNum = 255; wsLastCompleteName = wsUploadFileName; wsLastCompleteSize = wsUploadSize; wsLastCompleteAt = millis(); unsigned long elapsed = millis() - wsUploadStartTime; float kbps = (elapsed > 0) ? (wsUploadSize / 1024.0) / (elapsed / 1000.0) : 0; LOG_DBG("WS", "Upload complete: %s (%d bytes in %lu ms, %.1f KB/s)", wsUploadFileName.c_str(), wsUploadSize, elapsed, kbps); // Clear epub cache to prevent stale metadata issues when overwriting files String filePath = wsUploadPath; if (!filePath.endsWith("/")) filePath += "/"; filePath += wsUploadFileName; clearEpubCacheIfNeeded(filePath); wsServer->sendTXT(num, "DONE"); wsLastProgressSent = 0; } break; } default: break; } }