v0.245.0 — R-543: the household is asked for the recovery code, the page says "szunetel" until then
gates / gates (push) Successful in 14s
gates / gates (push) Successful in 14s
Off-site backup is ON by default and does not RUN until the household creates its recovery code. The pause is the zero-knowledge escrow design and is untouched here; what was missing is that nothing ASKED, while the app-backup page promised the very copy that had never run. - a reminder bar on every authenticated page while the off-site tier is configured and its escrow is not complete, linking /backup/escrow. It is the R-241 bar, second instance: same session-cookie dismissal, back next visit, gone for good when escrowed. No second banner system. It hangs off executeTemplate, the single render choke point, so it cannot reach only the pages someone remembered. - the tier-1 file sentence renders by tier3State's own vocabulary instead of the app's shape: active -> "vedi", escrow_pending -> "vedene ... szunetel" + the route, no copy at all -> says so and names both ways out. - both fixes red-proofed: the bar test fails on BOTH pages with the hook removed; the sentence test quotes the exact v0.244.0 promise when the state is ignored. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+10
-1
@@ -1576,6 +1576,15 @@ page renders one of four real states via the pure `tier3State` helper (`internal
|
||||
never a false success) / `active` (status badge + `restic → <host>` + relative last-run). Off-box run
|
||||
status is repo-global (one `LastRun`); no per-app run time is fabricated.
|
||||
|
||||
**The household is ASKED for the recovery code (v0.245.0, R-543).** While the off-site tier is
|
||||
configured and its escrow state is not `escrowed`, every authenticated page carries a reminder bar —
|
||||
„A távoli mentés szünetel, amíg nem hozod létre a helyreállítási kódot." linking `/backup/escrow`.
|
||||
It is the **R-241 bar, second instance** (`internal/web/escrow_banner.go`): same session-cookie
|
||||
dismissal, back at the next visit, gone for good when the state is `escrowed`. It is added in
|
||||
`executeTemplate`, the single render choke point, so it reaches every page; the login and claim
|
||||
pages bypass that function, and a session check keeps it off the public guest share page. The pause
|
||||
itself is UNCHANGED — it is the zero-knowledge escrow design, not a defect.
|
||||
|
||||
#### Restore (`internal/backup/restore.go`)
|
||||
|
||||
Both **Tier 1** (restic) and **Tier 2** (rsync) restores are supported. All deployed apps
|
||||
@@ -1645,7 +1654,7 @@ Every app starts as yellow (1 tier only). Green requires Tier 2 configured with
|
||||
("Kulcsletetre var"), `active` (status badge + "restic -> <host>" + relative last-run)
|
||||
|
||||
**Backup contents per app** (shown per tier):
|
||||
- Apps whose files live on the data drive (class A: calibre-web, immich, nextcloud, paperless-ngx): Tier 1 reads **"DB + Konfig"** — a Tier-1 unit has no file-copy step, so it does not hold them — and a sentence under the row says the files are protected by the off-site copy (and a second drive). Tier 2/3 read "DB + Konfig + Adatok", because those tiers DO carry the file legs.
|
||||
- Apps whose files live on the data drive (class A: calibre-web, immich, nextcloud, paperless-ngx): Tier 1 reads **"DB + Konfig"** — a Tier-1 unit has no file-copy step, so it does not hold them — and a sentence under the row says where the files ARE protected. **That sentence renders by tier-3 STATE, not by the app's shape (v0.245.0, R-543)** (`driveFilesNoteFor`): `active` → „…védi"; `escrow_pending` → „…**védené** — a távoli mentés a helyreállítási kód létrehozásáig szünetel" + the route; no off-site and no second drive → „Az alkalmazás fájljairól jelenleg nincs másolat…" + both ways out. It takes `tier3State`'s own vocabulary, so the row and the sentence cannot disagree. Tier 2/3 read "DB + Konfig + Adatok", because those tiers DO carry the file legs.
|
||||
- Apps whose data is entirely in Docker volumes (45 of 53 templates): "Konfig + DB + Adatok" or "Konfig + Adatok" on every tier — the unit really does hold their data.
|
||||
- Apps with DB only: "DB + Konfig"
|
||||
- **The restore refuses rather than lying (v0.244.0, R-538):** „Visszaállítás indítása" on a unit that cannot return an app's drive-side files is REFUSED before anything is stopped, naming the route that can (the off-site „Teljes visszaállítás (fájlok + adatbázis)", or the second drive's „Fájlok visszaállítása"), and saying plainly when no copy exists. A database-and-settings-only restore is a separately-worded second step.
|
||||
|
||||
Reference in New Issue
Block a user