release: v2.1.12 reliability and security hardening
CI / verify (push) Waiting to run

Verify update artifacts with exact metadata and SHA-512, require host-confirmed upload completion before cleanup, harden credentials and backups, improve queue recovery and skipped-state reporting, expand Windows path coverage, and add CI packaging checks.
This commit is contained in:
Sucukdeluxe
2026-08-11 22:36:21 +02:00
parent 2c124c848c
commit 2ba0106ef0
47 changed files with 2069 additions and 1192 deletions
+12
View File
@@ -70,4 +70,16 @@ describe('backup-crypto', () => {
// but both decrypt to same result
assert.deepStrictEqual(decrypt(a), decrypt(b));
});
it('password-protected backups require the exact password', () => {
const buf = encrypt(sampleConfig, 'correct horse battery staple');
assert.equal(buf.subarray(0, 4).toString('ascii'), 'MHU2');
assert.throws(() => decrypt(buf), (error) => error.needsPassword === true);
assert.throws(() => decrypt(buf, 'wrong password'), /Falsches Passwort/);
assert.deepStrictEqual(decrypt(buf, 'correct horse battery staple'), sampleConfig);
});
it('rejects an empty password instead of silently using the built-in key', () => {
assert.throws(() => encrypt(sampleConfig, ' '), /Passwort/);
});
});