[GH-ISSUE #317] [Bug]: Github Backup App settings include sensitive Data #201

Closed
opened 2026-05-06 12:27:10 +02:00 by BreizhHardware · 9 comments

Originally created by @guillaumeparis2000 on GitHub (Feb 10, 2026).
Original GitHub issue: https://github.com/maziggy/bambuddy/issues/317

Originally assigned to: @maziggy on GitHub.

Bug Description

If you select to back up 'App Settings', it includes sensitive data such as ha_token, ha_url, and other URLs configured in BamBuddy

Image

Expected Behavior

It must not include sensitive data such as ha_token, ha_url and other url or emails

Steps to Reproduce

Go to Settings -> Backup -> configure Github backup -> Select app settings -> generate a backup

In the repository you will find in settings/app_settings.json ha_token, ha_url and other urls and emails

Printer Model

A1

Bambuddy Version

v0.1.8.1

Printer Firmware Version

01.07.02.00

Installation Method

Docker

Operating System

Linux (Ubuntu/Debian)

Relevant Logs / Support Package


Screenshots

Image

Additional Context

No response

Checklist

  • I have searched existing issues to ensure this bug hasn't already been reported
  • I am using the latest version of Bambuddy
  • My printer is set to LAN Only mode
Originally created by @guillaumeparis2000 on GitHub (Feb 10, 2026). Original GitHub issue: https://github.com/maziggy/bambuddy/issues/317 Originally assigned to: @maziggy on GitHub. ### Bug Description If you select to back up 'App Settings', it includes sensitive data such as ha_token, ha_url, and other URLs configured in BamBuddy <img width="527" height="209" alt="Image" src="https://github.com/user-attachments/assets/920fd996-5ba1-40a0-9ad9-e4403fe17ab3" /> ### Expected Behavior It must not include sensitive data such as ha_token, ha_url and other url or emails ### Steps to Reproduce Go to Settings -> Backup -> configure Github backup -> Select app settings -> generate a backup In the repository you will find in settings/app_settings.json ha_token, ha_url and other urls and emails ### Printer Model A1 ### Bambuddy Version v0.1.8.1 ### Printer Firmware Version 01.07.02.00 ### Installation Method Docker ### Operating System Linux (Ubuntu/Debian) ### Relevant Logs / Support Package ```shell ``` ### Screenshots <img width="953" height="1014" alt="Image" src="https://github.com/user-attachments/assets/78711d10-2dd9-4ae3-b008-63c60d52036c" /> ### Additional Context _No response_ ### Checklist - [x] I have searched existing issues to ensure this bug hasn't already been reported - [x] I am using the latest version of Bambuddy - [x] My printer is set to LAN Only mode
BreizhHardware 2026-05-06 12:27:10 +02:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@maziggy commented on GitHub (Feb 10, 2026):

The idea is, to be able to completely restore you Bambuddy data. Just set your backup repository to private!

<!-- gh-comment-id:3876507547 --> @maziggy commented on GitHub (Feb 10, 2026): The idea is, to be able to completely restore you Bambuddy data. Just set your backup repository to private!
Author
Owner

@guillaumeparis2000 commented on GitHub (Feb 10, 2026):

I understand the backup's purpose, but I think some critical data must be encrypted in this case.

<!-- gh-comment-id:3876552106 --> @guillaumeparis2000 commented on GitHub (Feb 10, 2026): I understand the backup's purpose, but I think some critical data must be encrypted in this case.
Author
Owner

@maziggy commented on GitHub (Feb 10, 2026):

Why don't you just set your repo to private?

<!-- gh-comment-id:3876563280 --> @maziggy commented on GitHub (Feb 10, 2026): Why don't you just set your repo to private?
Author
Owner

@guillaumeparis2000 commented on GitHub (Feb 10, 2026):

My repo is private, but as it's explained in the interface, it will exclude sensitive data, ha_token and other urls or emails are sensitive data.

<!-- gh-comment-id:3876590901 --> @guillaumeparis2000 commented on GitHub (Feb 10, 2026): My repo is private, but as it's explained in the interface, it will exclude sensitive data, ha_token and other urls or emails are sensitive data.
Author
Owner

@maziggy commented on GitHub (Feb 10, 2026):

Explained in interface?

<!-- gh-comment-id:3876611988 --> @maziggy commented on GitHub (Feb 10, 2026): Explained in interface?
Author
Owner

@guillaumeparis2000 commented on GitHub (Feb 10, 2026):

Image
<!-- gh-comment-id:3876619685 --> @guillaumeparis2000 commented on GitHub (Feb 10, 2026): <img width="527" height="209" alt="Image" src="https://github.com/user-attachments/assets/9c2c2f2f-12eb-44ad-8db9-426fe138dc05" />
Author
Owner

@guillaumeparis2000 commented on GitHub (Feb 10, 2026):

You can close the issue if it's not a bug

<!-- gh-comment-id:3876625557 --> @guillaumeparis2000 commented on GitHub (Feb 10, 2026): You can close the issue if it's not a bug
Author
Owner

@maziggy commented on GitHub (Feb 10, 2026):

The text is wrong. Need to fix that.

<!-- gh-comment-id:3876647540 --> @maziggy commented on GitHub (Feb 10, 2026): The text is wrong. Need to fix that.
Author
Owner

@maziggy commented on GitHub (Feb 10, 2026):

Fixed in branch 0.1.9b. Thanks for pointing this out!


If you find Bambuddy useful, please consider giving it a on GitHub — it helps others discover the project!

<!-- gh-comment-id:3876907800 --> @maziggy commented on GitHub (Feb 10, 2026): Fixed in branch 0.1.9b. Thanks for pointing this out! ----- If you find Bambuddy useful, please consider giving it a ⭐ on [GitHub](https://github.com/bambuman/bambuddy) — it helps others discover the project!
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/bambuddy#201
No description provided.