This PR adds a `--detailed` flag to ServerUtil that reports additional data for each backup. The JSON output now also includes the schedule and any metadata.
This adds a nonce to the refresh token such that each request to obtain a refresh token must now also provide a matching nonce.
When using non-persisted logins, the request to the server is the same, but the "remember me" flag toggles a shorter duration for the refresh token.
The FE can then store the nonce in either local storage for persisted logins or in session storage for non-persisted logins.
The default is currently to always issue refresh tokens with a nonce, but this can be toggled with the JWT configuration.
The ngax client does not have the non-persisted login so it stores the nonce in local storage, using a name that is compatible with ngclient so the user can swap between them without needing to re-login.
The server util was updated to also store the nonce.
This fixes#6451
This PR updates the probing logic to not try the database if a password is supplied on the commandline.
It also fixes a crash that could happen at an unwanted place, if the user does not have write access to the supplied data folder. After this, the application will still crash due to not having a place to write information, but it does not crash in the preloader logic. This also prevents creating the folder while probing for the database.
This PR also fixes a case where the database could become encrypted, if the ServerUtil was providing an encryption key to an unencrypted database. Before this fix, the database would be encrypted with the key provided to ServerUtil, which would most likely cause the Server/TrayIcon to fail starting and perhaps crash.
This fixes#6377
This addresses [Issue](https://github.com/duplicati/duplicati/issues/6114).
Whenever in non-write context, the permissions of the folder are not set.
Changing pattern from static constructor execution.
This comes from suggestion on issue https://github.com/duplicati/duplicati/issues/6056
The chosen argument was --json which produces a json that wraps the result with extended properties such as in example:
``
{
"Timestamp": "2025-03-28T15:47:01.3368160-03:00",
"UnixTimestamp": 1743187621,
"Command": "import",
"Success": true,
"ExitCode": 0,
"Messages": [
"Importing backup configuration from ../2-firstbacku.json",
"Connecting to http://127.0.0.1:8200/...",
"No database found in../data/",
"Imported \"firstbackup (5)\" with ID 8"
],
"Exceptions": [],
"Imported": {
"Id": "8",
"Name": "firstbackup (5)"
}
}
``
The documentation will reflect all commands and schemas as this makes its way into Canary
Added support for `--portable-mode` and `--server-datafolder` for the CLI, ServerUtil, and Agent.
Fixed a few places where file reads were not cached properly.
Moved some responsibilities of UpdaterManager into DataFolderManager.
This now supports storing `machineid.txt` and `installation.txt` inside the path pointed to by `--server-datafolder` or alternatively with `--portable-mode`.
It is possible that some fringe backwards compatibility is lost with this update.
Fixed an issue with AutoUpdater crashing on check/download.
This fixes#5902
* Implemented support for emitting intermediate certificates from pfx files
* Added certificate check to crash earlier
* Fixed loading certificate on Windows
Kept the infrastructure to allow re-introducing it later if a better source for a device key is found.
Added support for not having any valid settings encryption key.
Added warnings if the user is running without a settings encryption key.
Added additional checks during startup to help with troubleshooting and configuring a setup with a settings encryption key.
Docker builds will now warn if no encryption key is set.
This fixes#5518