- New "backup" and "update" schedule types for manually tracked tasks,
plumbed through the form, filters, group labels, and API validation.
- Copy buttons next to the agent token and install/uninstall commands
on the Servers page, so they don't need to be selected by hand.
- Cron jobs now show an estimated "next run" (via cron-parser),
computed client-side and clearly marked with "~" plus a tooltip,
since the agent has no way to compute this for cron (unlike systemd
timers, which report a real value from systemctl).
- Dependency updates: fixes a high-severity SQL injection advisory in
drizzle-orm (0.38.4 -> 0.45.2, plus drizzle-kit 0.31.10), a qs
vulnerability pinned past body-parser's own range via an npm
"overrides" entry, a leftover vulnerable esbuild pulled in
transitively by drizzle-kit (also via override), and cron-parser
4 -> 5 (v4 is unmaintained; updated its call site for the new
CronExpressionParser API). `npm audit` is now clean. Re-verified the
DB layer end-to-end (migrations, CRUD, agent sync, stale-marking)
and the cron estimate against the new cron-parser API after the
upgrade.
Lets users log tasks the Linux agent can't discover on its own (e.g.
Docker-based backup jobs) directly in the UI. Tasks now carry an
origin ('agent' | 'manual') so the agent's report-sync logic only
ever creates/updates/stale-marks agent-sourced rows, leaving manual
entries untouched; the API rejects edits/deletes of agent-sourced
tasks to keep that boundary enforced server-side too.