Security
- Remote SSH host fields are now validated (GHSA-4jqx-9f92-rc8p). Values entered for a Remote SSH host's address, user and Remote Borg Path could be misused by an admin to run commands on the BBS server, and through borg on clients that back up to that host. They're now checked when saved and again when used, and any stored Remote Borg Path that fails the check is cleared. Installs that give admin logins to people who shouldn't have server access should update. Hosted servers were not affected. Thanks to @dutchypoo for the report.
Fixes
- Restoring a repository as a copy from Offsite Sync (#523). The copy shares the original's borg ID, so downloads, deletes and catalog builds on it failed with "multiple repos with same ID", and the file browser showed the wrong contents. A copy is now read-only (browse, restore and download only) and gets its own borg ID, its folders and size show correctly, and existing copies are fixed automatically. The copy button says the copy is read-only. The API returns
read_onlyon repositories. - Offsite Sync naming (#522). The job page, notifications, emails and a few messages still said "S3" for Offsite Sync jobs. They now say "Offsite sync".
No agent change; agent stays 2.98.0.