Backup: export everything (hosts, groups, keys, passwords, snippets, forwards, VPNs, known hosts, history, settings), optionally encrypted with a password (scrypt + AES-256-GCM); import asks for the password, can merge or replace existing data and optionally restore settings; old backups still import; shared module for desktop, web and Android (src/core/backup.js)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 14:45:31 +02:00
co-authored by Claude Opus 5.5
parent 408b4bd9d0
commit 93d7130bfa
7 changed files with 197 additions and 21 deletions
+61 -2
View File
@@ -1072,8 +1072,8 @@ async function viewSettings(page) {
const dataCard = h(`<div class="settings-card"><h3>${T('Data')}</h3><p style="color:var(--muted);margin-top:0">${WEB ? T('Your vault is stored on the server, encrypted with a key that only your login password can unlock.') : S.vault.encrypted ? T('The vault is encrypted with the operating system keyring (Windows DPAPI / libsecret or KWallet).') : T('The vault is not encrypted because no keyring is available. On Arch/CachyOS: install <code>gnome-keyring</code> or <code>kwallet</code>.')}</p><div class="row" style="flex-wrap:wrap"></div></div>`);
const btns = [
...(WEB ? [] : [[T('Import ~/.ssh/config'), importSshConfig]]),
[T('Export backup'), async () => { const p = await call('vault:export'); if (p) toast(T('Exported to {path}', { path: p }), 'ok'); }],
[T('Import backup'), async () => { if (await call('vault:import')) { toast(T('Import complete'), 'ok'); reload(); } }],
[T('Export backup'), exportBackup],
[T('Import backup'), importBackup],
];
btns.forEach(([l, fn]) => { const b = h(`<button class="btn">${esc(l)}</button>`); b.onclick = fn; $('.row', dataCard).append(b); });
@@ -1416,6 +1416,65 @@ async function importRdm() {
$('[data-view=hosts]').click();
}
// ============================================================ Backup
const BACKUP_ERRORS = () => ({ INVALID: T('This file is not a MrTerm backup.'), WRONG_PASSWORD: T('Wrong password.'), PASSWORD_REQUIRED: T('This backup is encrypted. Please enter the password.') });
const backupError = (e) => BACKUP_ERRORS()[e.message] || e.message;
async function exportBackup() {
let err = '';
for (;;) {
const r = await modal({
title: T('Export backup'),
body: `<p style="margin-top:0;color:var(--muted)">${T('Exports all hosts, groups, SSH keys, passwords, snippets, port forwards, VPNs, known hosts and settings.')}</p>
${err ? `<p style="color:var(--red)">${esc(err)}</p>` : ''}
${field(T('Password'), 'pw', '', { type: 'password', hint: T('Recommended. Without a password, keys and passwords are stored in plain text in the file.') }).outerHTML}
${field(T('Repeat password'), 'pw2', '', { type: 'password' }).outerHTML}
${check(T('Include settings'), 'settings', true).outerHTML}`,
buttons: [{ label: T('Cancel'), value: null, cls: 'ghost' }, { label: T('Export'), value: 'form', cls: 'primary' }],
});
if (!r) return;
if (r.pw !== r.pw2) { err = T('The passwords do not match.'); continue; }
if (r.pw && r.pw.length < 8) { err = T('The password must be at least 8 characters long.'); continue; }
if (!r.pw && !(await confirmBox(T('Export without password?'), T('Private keys and passwords will be readable by anyone who gets the file.'), T('Export')))) continue;
try {
const content = await api.call('backup:export', { password: r.pw, settings: r.settings });
const name = `mrterm-backup-${new Date().toISOString().slice(0, 10)}${r.pw ? '-encrypted' : ''}.json`;
const p = await call('backup:saveFile', content, name);
if (p) toast(T('Exported to {path}', { path: p }), 'ok');
} catch (e) { toast(backupError(e), 'error'); }
return;
}
}
async function importBackup() {
const f = await call('import:pickFile', 'MrTerm Backup', ['json']);
if (!f) return;
let info;
try { info = await api.call('backup:inspect', f.content); } catch (e) { return toast(backupError(e), 'error'); }
const c = info.counts;
const summary = c ? T('{hosts} hosts, {keys} keys, {snippets} snippets, {vpns} VPNs', c) : T('Contents are encrypted.');
let err = '';
for (;;) {
const r = await modal({
title: T('Import backup'),
body: `<p style="margin-top:0;color:var(--muted)">${esc(f.name)}${info.createdAt ? ' · ' + esc(new Date(info.createdAt).toLocaleString()) : ''}<br>${esc(summary)}</p>
${err ? `<p style="color:var(--red)">${esc(err)}</p>` : ''}
${info.encrypted ? field(T('Password'), 'pw', '', { type: 'password' }).outerHTML : ''}
${check(T('Import settings'), 'settings', false).outerHTML}
${check(T('Replace existing data (entries not contained in the backup are deleted)'), 'replace', false).outerHTML}`,
buttons: [{ label: T('Cancel'), value: null, cls: 'ghost' }, { label: T('Import'), value: 'form', cls: 'primary' }],
});
if (!r) return;
if (r.replace && !(await confirmBox(T('Replace existing data?'), T('Hosts, keys, snippets and other entries that are not in the backup will be deleted.'), T('Replace')))) continue;
try {
const n = await api.call('backup:import', f.content, r.pw || '', { replace: r.replace, settings: r.settings });
toast(T('Import complete: {hosts} hosts, {keys} keys, {snippets} snippets', n), 'ok');
reload();
return;
} catch (e) { err = backupError(e); }
}
}
// ============================================================ Updates
let updateInfo = null;
let updateDialogOpen = false; // Auto-Prüfung beim Start und manuelle Prüfung sollen keine zwei Dialoge stapeln