- New "n8n workflow" schedule type for manually tracked tasks, plumbed
through the form, filters, group labels, and API validation, same as
the earlier backup/update types.
- Dates (cron next-run, server last-seen) now render in Swedish
standard format (YYYY-MM-DD, 24-hour clock) via a shared formatter
instead of the browser's default locale.
- New Data & Privacy page describing what's stored, where, how long,
and how to remove it, linked from a footer shown on every page
alongside a "By bobbantech" credit linking to bobbantech.com.
- New "backup" and "update" schedule types for manually tracked tasks,
plumbed through the form, filters, group labels, and API validation.
- Copy buttons next to the agent token and install/uninstall commands
on the Servers page, so they don't need to be selected by hand.
- Cron jobs now show an estimated "next run" (via cron-parser),
computed client-side and clearly marked with "~" plus a tooltip,
since the agent has no way to compute this for cron (unlike systemd
timers, which report a real value from systemctl).
- Dependency updates: fixes a high-severity SQL injection advisory in
drizzle-orm (0.38.4 -> 0.45.2, plus drizzle-kit 0.31.10), a qs
vulnerability pinned past body-parser's own range via an npm
"overrides" entry, a leftover vulnerable esbuild pulled in
transitively by drizzle-kit (also via override), and cron-parser
4 -> 5 (v4 is unmaintained; updated its call site for the new
CronExpressionParser API). `npm audit` is now clean. Re-verified the
DB layer end-to-end (migrations, CRUD, agent sync, stale-marking)
and the cron estimate against the new cron-parser API after the
upgrade.
curl ... | API_URL=... bash runs as the invoking user, not root, so
"sudo" has to go right after the pipe (elevating bash) rather than
before curl — the old commands in the app UI, README, and scripts'
own usage comments put it in a spot that still failed the root check.
Also have install.sh/report-tasks.sh suggest the right package-manager
command (apt/dnf/yum/apk/pacman/zypper) when curl or jq is missing
instead of just failing, and bring the README up to date with both.
Lets a server be cleanly removed from agent management: uninstall.sh
stops/disables the systemd timer and deletes the unit files, the
installed script, and the credentials env file, without touching the
server's entry or task history in the app. install.sh now prints the
uninstall command on success, and the Servers page has an "Uninstall"
button that reveals the same command (safe to show anytime since it
carries no secret).
Lets users log tasks the Linux agent can't discover on its own (e.g.
Docker-based backup jobs) directly in the UI. Tasks now carry an
origin ('agent' | 'manual') so the agent's report-sync logic only
ever creates/updates/stale-marks agent-sourced rows, leaving manual
entries untouched; the API rejects edits/deletes of agent-sourced
tasks to keep that boundary enforced server-side too.