v0.289.0: off-site key cannot delete — append-only rclone transport, box sends only its public key (hub registrar), retention only inside a hub window behind the fake-snapshot guard (decisions 68-69, R-820, R-822)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 17:01:36 +02:00
parent 09453325d1
commit 55bb6c3d32
15 changed files with 1039 additions and 386 deletions
@@ -99,6 +99,11 @@ func (s *Server) offboxConfigHandler(w http.ResponseWriter, r *http.Request) {
Host: host, Port: port, User: user, RepoPath: repoPath,
Schedule: "daily",
}
if prev != nil && prev.Pinned() && prev.Host == host && prev.User == user {
// A hand edit of the hub-provisioned tier keeps its append-only transport (decision 69); a
// different host/user is the household's own NAS and starts as SFTP.
tgt.Transport = prev.Transport
}
if prev != nil { // preserve runtime status fields across an edit
tgt.LastRun, tgt.LastStatus, tgt.LastError = prev.LastRun, prev.LastStatus, prev.LastError
// R-100: LastSuccess is runtime status like the rest — an edit to the host/path/schedule must