Commit Graph
872 Commits
Author SHA1 Message Date
Kenneth Skovhede 2634eb3f64 Added support for generating the database.
Added better logging.
2026-03-02 16:39:19 +01:00
Kenneth Skovhede 07cd39af34 Add support for managed TLS
This PR adds support for generating a self-signed CA and then using that CA to generate TLS certificates.

A new tool `duplicati-configure` / `Duplicati.CommandLine.ConfigureTool.exe` is added to manage the certificates.  The tool saves the configuration in the database and is meant to run with elevated privileges for the initial CA installation.

The option `--configure-https` can be added to server/trayicon, and if the process has permissions, this will automatically install the CA certificate.

If a CA is configured, the server will automatically issue, renew and use a TLS certificate.

With this setup, the TLS is opt-in, but once the flow is well tested, we can switch it to opt-out.
2026-03-01 11:33:05 +01:00
Kenneth Skovhede ea6d94b035 Added support for storing multiple targets in database with backwards compatibility. 2026-02-18 11:06:08 +01:00
Kenneth SkovhedeandGitHub 562cb1199a Merge branch 'master' into feature/add-destination-repo 2026-02-02 11:00:39 +01:00
Kenneth Skovhede cf17d2617e Added a connection string repo
This adds a connection string repo, where connection strings can be stored.

The general idea is that it is possible to store connection strings, say an S3 connection, and then re-use the connection string for multiple backups, editing as needed.

The implementation supports listing connection strings, creating, updating, and deleting them.

The connection strings are masked so sensitive information is not available in the browser, and the logic patches connection strings internally to ensure markers are replaced with the correct values.

The connection string itself is stored in full, such that a Duplicati version roll-back will not make the connectionstring become invalid.

There is also an endpoint that allows updating existing backups using the connection string, so it is easy to rotate keys. The logic for this feature is that it retains: scheme, port, host, path, and any extra settings on the target url.
It does not remove settings from the target, but will overwrite or add settings from the connectionstring.
2026-01-30 13:59:47 +01:00
Kenneth Skovhede 3341794c64 Work on restoring channel messages 2026-01-22 17:01:13 +01:00
Kenneth Skovhede 27dc64121b Implemented cross-tenant email restore 2026-01-16 11:09:13 +01:00
Kenneth Skovhede 1523f730e3 Added support for storing metadata in the database 2026-01-14 10:01:20 +01:00
Kenneth Skovhede 0f81b42146 Add support for remote locks
This PR adds support for locking files if the backend supports it.

To activate locking, set the option `--file-lock-duration=30D` and the backup will lock the files.

If the database is rebuilt with the intention of continuing the backups, use the option `--repair-refresh-lock-info` which will update lock information in the database after recreating the database.

The locking works by asking the backend to lock files after a backup has completed.

The implementation keeps track of which files are currently assigned a lock and prevents attempting to delete the files that are currently locked.

Note that the bucket should not have a default lock policy as Duplicati needs to finish the backup before the locking is applied.

In this initial version, Azure Blob Storage, B2, S3 and iDrive are supported with locking.

The CLI is updated to allow setting locks on a specific version. The backend tool is updated to allow setting locks on specific files.
2025-12-14 17:17:48 +01:00
Kenneth SkovhedeandGitHub 179fd4da47 Merge pull request #6653 from duplicati/feature/secret-provider-write-support
Initial implementation of write-support for SecretProviders
2025-12-05 15:23:32 +01:00
Kenneth SkovhedeandGitHub d4951720a7 Merge pull request #6658 from duplicati/feature/support-extended-import-in-server-util
Added support for settings override in imports
2025-12-03 10:36:08 +01:00
Kenneth Skovhede 1e4a1d3df3 Added support for settings override in imports
This PR adds the option to provide additional settings when importing a backup.

The ServerUtil has been expanded to support passing in the target url and backup passphrase when importing a backup.

Also clarified wording around the import passphrase as there are (at least) two passphrases related to imports.

This fixes #6640
2025-12-02 10:26:45 +01:00
David Kartchner b7a25263e8 Updated RecoveryTool help text to mention --new-passphrase option 2025-12-02 02:24:51 -07:00
David Kartchner 5113d0e989 added an option to supply a new passphrase for reencryption with RecoveryTool recompress command 2025-12-02 02:24:06 -07:00
Kenneth Skovhede ead7b06c05 Better docs and output 2025-12-01 15:33:15 +01:00
Kenneth Skovhede 695d190b91 Updated to allow IsSupported to be async 2025-12-01 15:29:24 +01:00
Kenneth Skovhede 212d6b1148 Fixed getting a better default support result for pass
Better output on info command
Fixed delay on IsSupported for libSecret
2025-12-01 15:14:20 +01:00
Kenneth Skovhede 8b122f8adf Fixed build issue 2025-12-01 14:51:31 +01:00
Kenneth Skovhede 5f8a5bded6 Report supported status for secret provider 2025-12-01 13:38:41 +01:00
Kenneth Skovhede 6d9826df06 Initial implementation of write-support for SecretProviders
This updates the MacOS secret provider to use PInvoke for a more stable API than the secrets tool that was used before.
2025-11-30 23:01:57 +01:00
Kenneth Skovhede 178440f869 Fixed a number of warnings 2025-11-14 16:00:06 +01:00
Kenneth Skovhede 1ea74a3c63 Updated to .NET10 2025-11-14 15:05:39 +01:00
David Kartchner 369a24d112 Made log validation message clearer 2025-11-07 16:02:40 -07:00
David Kartchner e4798dcf66 Added further parsing validation and error messages 2025-11-07 16:00:47 -07:00
David Kartchner 4832df5e15 removed error parsing and added log count validation 2025-11-07 09:55:00 -07:00
David Kartchner afe606edb7 Display status after running backup with ServerUtil 2025-11-07 09:54:29 -07:00
Kenneth Skovhede 012aeed7de Add dynamic streaming toggle
This PR adds a dynamic property so a backend can signal if it supports streaming, based on the settings.

This is currently used for the File backend, so that toggling `--use-move-for-put` will disable streaming on the backend instead of relying on the `--disable-streaming-transfers` flag.
2025-11-03 12:48:37 +01:00
Kenneth Skovhede 6ed507c0b3 Add option to limit modules
This PR adds the option to limit the available modules to just the set of specified choices.

If no option is set, all modules are available (default).
If the option is set, only those in the list are available (whitelisting).

The options are:
- `--allowed-backend-modules`
- `--allowed-encryption-modules`
- `--allowed-compression-modules`
2025-10-17 10:01:31 +02:00
Kenneth Skovhede 1d772127df Fixed wrong downgrade script 2025-09-22 14:29:52 +02:00
Kenneth Skovhede 34b6f9ea55 Implemented remotely managed backup configurations
This PR adds the ability to manage backup configurations outside of the the client.

The implementation ensures that locally created configurations cannot be affected by the remotely managed backups.

If the instance is not connected to a remote console, this has no effect.

This PR updates the local database to add the column `ExternalID` that tracks backups that are managed remotely.
2025-09-17 15:07:09 +02:00
Kenneth Skovhede 31eeebd69b Added support for retries in backend tester
This PR adds support for retries in the backend tester.

The CI tests have been updated to retry operations 3 times, which will hopefully make the CI tests more stable.
2025-09-10 14:47:23 +02:00
Kenneth SkovhedeandGitHub b732374d87 Merge pull request #6473 from duplicati/feature/improve-non-persisted-login
Implemented a nonce for refresh tokens
2025-08-08 13:09:04 +02:00
Kenneth Skovhede dc3b7fc56c Add detailed output to backup lists
This PR adds a `--detailed` flag to ServerUtil that reports additional data for each backup. The JSON output now also includes the schedule and any metadata.
2025-08-08 10:52:45 +02:00
Kenneth Skovhede eef7eb3191 Fixed server-util wait with refresh token.
This fixes #5904
2025-08-08 08:29:52 +02:00
Kenneth Skovhede 6b9788b239 Fixed issue with saving non-persistent tokens 2025-08-08 08:27:04 +02:00
Kenneth Skovhede e3f1aefec2 Implemented a nonce for refresh tokens
This adds a nonce to the refresh token such that each request to obtain a refresh token must now also provide a matching nonce.

When using non-persisted logins, the request to the server is the same, but the "remember me" flag toggles a shorter duration for the refresh token.

The FE can then store the nonce in either local storage for persisted logins or in session storage for non-persisted logins.

The default is currently to always issue refresh tokens with a nonce, but this can be toggled with the JWT configuration.

The ngax client does not have the non-persisted login so it stores the nonce in local storage, using a name that is compatible with ngclient so the user can swap between them without needing to re-login.

The server util was updated to also store the nonce.

This fixes #6451
2025-08-07 23:10:54 +02:00
Marcelo C. 02d0c12e14 Moves timeout output to correct location
Ensures that the timeout value is correctly applied either from environment variables or command line areguments before the output to console.
2025-07-29 08:48:31 -03:00
Kenneth Skovhede fc478146f3 Update ServerUtil probing
This PR updates the probing logic to not try the database if a password is supplied on the commandline.

It also fixes a crash that could happen at an unwanted place, if the user does not have write access to the supplied data folder. After this, the application will still crash due to not having  a place to write information, but it does not crash in the preloader logic. This also prevents creating the folder while probing for the database.

This PR also fixes a case where the database could become encrypted, if the ServerUtil was providing an encryption key to an unencrypted database. Before this fix, the database would be encrypted with the key provided to ServerUtil, which would most likely cause the Server/TrayIcon to fail starting and perhaps crash.

This fixes #6377
2025-07-10 21:03:16 +02:00
Carl Johnsen 2412800c0c Removed the sqlite page cache option. It should be set through the environment variable, or some other way of providing a custom database configurotion 2025-06-19 11:41:39 +02:00
Carl Johnsen 9b0d89363b Removed whitespace 2025-06-19 11:40:23 +02:00
Carl Johnsen 78d649f5a3 All of the non-internal-library methods calling the database functions forwards CancellationToken.None 2025-06-19 11:00:24 +02:00
Carl Johnsen 9ac583db94 Made all relevant using statements use await to use DisposeAsync 2025-06-18 11:53:11 +02:00
Carl Johnsen f221098c28 Formatted SQL queries - mainly adding double quotes where they were missing. 2025-06-18 10:42:08 +02:00
Carl Johnsen e81100de04 Started on adding docstrings 2025-06-17 09:59:22 +02:00
Carl Johnsen 3d11a05400 Added .ConfigureAwait(false) to all of the await statements 2025-06-12 08:34:29 +02:00
Carl Johnsen 17cabeb329 Updated the DatabaseTool to use the new async database backend 2025-06-11 08:57:14 +02:00
Carl Johnsen eda3d5321b Removed whitespace 2025-06-11 08:56:58 +02:00
Kenneth Skovhede d62b3e540b Removed old defunct manual test files 2025-05-27 12:13:40 +02:00
Kenneth Skovhede 9ea0ab673f Added explanation for using parameters file to hide passphrases.
This fixes #2312
2025-05-21 12:50:31 +02:00
Kenneth SkovhedeandGitHub 8a2f028f7a Merge branch 'master' into feature/add-blocksetentry-index 2025-05-16 19:02:26 +02:00