The administrator's page backs up, downloads, uploads and restores
/clientapi/admin/backups (owner decision 2026-10-07, approving these endpoints in production): the list with what runs, the restore waiting and the last restore's report; back up now; delete; a download for the password, through a ticket good for ten minutes in the link's path, as one tar whose length is known first and which honours Range (BackupTar); an upload in pieces of at most 32 MB, each at the offset already received or refused with it, so a broken upload resumes, read into a backup only when it holds nothing but plain files under one backup's folder; and a restore for the password and the host typed out. Every call checks the administrator against the database. nginx streams downloads for an hour and takes upload pieces unbuffered, rate-limited. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
fba57318fa
commit
bc5f2beaf7
8 files changed
+987
No files matched your search
@@ -526,6 +526,19 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
it was; failed midway, the process exits 1 and the next start tries again; after 3 failures it exits 75, which the
|
||||
unit's `RestartPreventExitStatus` leaves down for someone to look. While `restore.json` exists, commands exit 75 (but
|
||||
`admin restore --status`) and the deploy refuses to run.
|
||||
- **The administrator's page** (`BackupController`, `/clientapi/admin/backups`; owner decision 2026-10-07, which approved
|
||||
these endpoints in production): the list (with what runs, the restore waiting, the last restore's report, logins
|
||||
deleted since each backup), back up now (202; the page polls), delete, and:
|
||||
- **download** for the password: a ticket good for ten minutes in the link's path (`/download/{ticket}`, anonymous, so a
|
||||
browser saves it to disk), the backup as one tar (`BackupTar`: its exact length known first, written from the
|
||||
files, `Range` honoured);
|
||||
- **upload** in pieces of at most 32 MB (`TransferStore`): each `PUT ?offset=` must start where the upload stands, else
|
||||
409 with what was received, so a broken upload resumes; `finish` reads it into a backup (`kind` uploaded), refusing
|
||||
anything but plain files under one backup's folder, a path leaving it, or more than the disk holds;
|
||||
- **restore** for the password and the server's host typed out.
|
||||
|
||||
Every call checks the administrator against the database, not only the token. nginx streams downloads for an hour and
|
||||
takes upload pieces unbuffered (`deploy/nginx`, applied by `setup.sh`).
|
||||
|
||||
## Code style
|
||||
|
||||
|
||||
Reference in new issue
Block a user