Omahub
← All plugins
L

Omarchy OctoPrint

by Luxore

An OctoPrint plugin for Omarchy.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
a1af5a3
Scanned
1 week ago
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n\x00\x00\x00\rIHDR" + (9000).to_bytes(4, "big") + (9000).to_bytes(4, "big")
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n"):

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a1af5a3
Reviewed
1 week ago

The plugin is a well-structured OctoPrint monitoring widget with a Python companion that stores API keys in the system keyring, validates URLs, and enforces same-origin redirects. The deterministic 'obfuscation' findings are false positives—they are PNG magic-number checks in test and client code, not hidden behavior. No malicious or destructive actions were found.

  • The plugin stores an OctoPrint API key in Secret Service; users should be aware it is stored locally and can be removed via the 'forget' command.
  • Camera frames are written to the user's runtime directory; the code correctly enforces owner-only permissions and rejects symlinked/shared directories.
  • The companion uses xdg-open to open the OctoPrint URL, which is standard and safe.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/luxore/omarchy-octoprint --enable
Hardware #bar #quickshell
<p align="center"> <img src="assets/octoprint.svg" width="76" alt="OctoPrint"> </p> <h1 align="center">Omarchy OctoPrint</h1> <p align="center"> An OctoPrint plugin for Omarchy </p> <p align="center"> <a href="https://omarchy.org"><img alt="Omarchy 4" src="https://img.shields.io/badge/Omarchy-4.0-8bd450?style=flat-square&labelColor=111111"></a> <a href="https://github.com/luxore/omarchy-octoprint/releases"><img alt="Release 0.6.3" src="https://img.shields.io/badge/release-0.6.3-8bd450?style=flat-square&labelColor=111111"></a> <a href="LICENSE"><img alt="MIT license" src="https://img.shields.io/badge/license-MIT-f5f5f5?style=flat-square&labelColor=111111"></a> </p> <table> <tr> <td width="50%" align="center"><img src="assets/screenshots/monitor.png" alt="OctoPrint monitoring an operational printer from the Omarchy bar"></td> <td width="50%" align="center"><img src="assets/screenshots/preferences.png" alt="OctoPrint camera, bar, and notification preferences in Omarchy"></td> </tr> <tr> <td align="center"><sub>Camera, state, temperatures, and the actions that matter</sub></td> <td align="center"><sub>One camera mode and a handful of useful preferences</sub></td> </tr> </table>

Omarchy OctoPrint is a camera-first widget for the Omarchy bar. It stays quiet while the printer is idle, shows progress and finish time during a job, and opens into a focused monitor when the printer needs a closer look.

It is deliberately not another OctoPrint control panel. Uploads, movement, terminal commands, preheating, and printer configuration remain in OctoPrint, where their context and safeguards already exist.

Install

omarchy plugin add https://github.com/luxore/omarchy-octoprint.git --enable

Open the OctoPrint mark in the bar. First run opens Setup:

  1. Enter an IP address, DNS name, or full URL. Bare hosts use http://; explicit HTTP, HTTPS, ports, and reverse-proxy paths are preserved.
  2. Choose Connect in browser to approve a dedicated OctoPrint application key, or paste an existing application/user API key and choose Use key.

The key travels to the helper over standard input and is stored in Secret Service. It never enters shell.json, a URL, a process argument, or a file.

At a glance

  • Optional progress rail and finish ETA in horizontal and vertical bars.
  • Camera-first popup with MJPEG stream, periodic snapshots, or camera off.
  • Job name, remaining time, expected finish, nozzle, and bed temperature.
  • Distinct printing, paused, cancelling, error, offline, and stale states.
  • One notification per finished, paused, or failed transition.
  • Immediate pause/resume and a deliberate two-step cancel.
  • Automatic settings, browser authorization, and a masked manual-key fallback.
  • One shared status poll across every display, with no camera traffic while the popup is closed.

Use

Input Action
Left click Open or close Omarchy OctoPrint
Middle click Refresh status
R Refresh status
P Pause or resume the active print
C twice Cancel within a five-second confirmation window
O Open OctoPrint
S Open Preferences

Summon the popup from a script or Hyprland binding:

omarchy-shell shell toggle io.github.luxore.octoprint '{}'

The widget uses Omarchy's native bar geometry and can be dragged into place or moved precisely:

omarchy bar move io.github.luxore.octoprint --section left
omarchy bar move io.github.luxore.octoprint --section center --index 0
omarchy bar move io.github.luxore.octoprint --section right

Camera and refresh behavior

Preferences offers one camera choice: Stream, Snapshots, or Off. Stream mode keeps one MJPEG connection open at five displayed frames per second. Snapshot mode refreshes every 1.5 seconds. Either mode stops when the popup closes.

Status refreshes every five seconds while printing, paused, or open and every 60 seconds while idle. Independent OctoPrint endpoints are fetched concurrently, and every display shares the same poll.

Standard OctoPrint camera routes work without setup. Unusual reverse-proxy routes remain available through manifest settings or the CLI.

Security

Camera frames are written atomically inside verified owner-only runtime directories. The helper rejects symlinked or shared directories and creates private temporary files exclusively; a failed update preserves the last frame.

Use OctoPrint's application-key authorization whenever possible. The helper stores one key per canonical server URL in the desktop keyring and retrieves it directly for each request. Camera credentials are sent only to the configured OctoPrint origin, and same-origin redirects are enforced.

Prefer HTTPS when the server supports it. HTTP sends the API key without transport encryption and is suitable only for a trusted local network. Enable OctoPrint Access Control before using this plugin.

Forget saved key removes the local credential. Revoke the application key inside OctoPrint when it must also become invalid on the server.

Older OctoPrint installations without the Application Keys plugin can accept a user-specific key interactively:

~/.config/omarchy/plugins/io.github.luxore.octoprint/bin/octoprint-companion \
  --url http://octopi.local authorize --manual

Do not use OctoPrint's global API key.

CLI

The bar and scripts share a small JSON interface:

companion=~/.config/omarchy/plugins/io.github.luxore.octoprint/bin/octoprint-companion

"$companion" --url http://octopi.local status
"$companion" --url http://octopi.local snapshot
"$companion" --url http://octopi.local stream
"$companion" --url http://octopi.local command pause
"$companion" --url http://octopi.local command resume
"$companion" --url http://octopi.local command cancel
"$companion" --url http://octopi.local setting cameraMode snapshots
"$companion" --url http://octopi.local setting showProgress false
"$companion" --url http://octopi.local forget
"$companion" --url http://octopi.local configure \
  --snapshot-path /custom/snapshot --stream-path /custom/stream

Successful commands write one JSON object to standard output. stream writes one JSON line per displayed frame until interrupted. Snapshot and stream files remain mode 0600 in the user's runtime directory.

Remove

Forget the local credential, revoke the matching application key in OctoPrint, then remove the plugin:

companion=~/.config/omarchy/plugins/io.github.luxore.octoprint/bin/octoprint-companion
"$companion" --url http://octopi.local forget
omarchy plugin remove io.github.luxore.octoprint

Development

Omarchy OctoPrint uses QML and Python's standard library. Its runtime dependencies are already present in Omarchy: python3, secret-tool, and xdg-open.

omarchy plugin validate .
python3 -m unittest discover -s test -v
test/lint

Changes should preserve the companion boundary, the secret-handling contract, and truthful state transitions. Open an issue before widening the product into printer setup, file management, movement, heating, or arbitrary G-code.

License and trademarks

Code is MIT. The bundled OctoPrint mark is reproduced from the official mask-theme.svg without changing its shape or colors and is not covered by the code license.

This plugin is compatible with OctoPrint but is not affiliated with, supported by, or endorsed by the OctoPrint project or Gina Häußge. OctoPrint is a registered trademark.