The auto-import wipes the database, destroying the cronJobLog record
created at the start of the job. Now duration is calculated from a
local variable instead of querying the DB, and if the record is gone
a fresh log entry is created in the restored database.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
applyMissingMigrations ran the entire migration SQL as one transaction,
which rolled back all changes when any statement failed (e.g. adding a
NOT NULL column to a non-empty table). Replaced with prisma db push
which compares the schema and applies only what's needed. Also added
support for importing .sql files (not just .zip) in auto-import.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Requests from outside 10.x, 192.168.x, 172.16-31.x, 127.x are rejected
with 403 before the API key is even checked. This prevents the database
dump endpoint from being reachable from the internet even if the key leaked.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The /network-backup and /network-backup-files routes use their own
X-Network-Backup-Key authentication. Mounting them behind authenticateJWT
blocked all receiver sync requests before they could be validated.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Side effects inside queryFn caused the enabled toggle and other fields to
reset on refetch because SyncStatus shares the same query key with a
different queryFn, making formLoaded unreliable.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Copy-paste often adds trailing whitespace that breaks the API key comparison.
Updated placeholder and description to show the correct URL format (no port number).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>