Releases: YigitCittan/mongorescue
Releases · YigitCittan/mongorescue
Release list
v0.5.0
Added
- Dashboard: the build version (for example
v0.4.1, as reported byGET /api/v1/health) is shown next to the brand in the header. - Desktop app: while an optional update is available, an Update button stays in the header, also after Later hid the bar; it shows the bar again and starts the update, or opens the release page when the release has no file for your system. See docs/desktop.md.
Changed
- Release workflow: can sign the Windows desktop exe and installer through SignPath once the
SIGNPATH_API_TOKENsecret andSIGNPATH_ORGANIZATION_IDvariable are configured; until then Windows builds stay unsigned as before. See docs/desktop.md.
Fixed
mongodump not foundwhen the MongoDB Database Tools are installed but not on the app'sPATH(the Windows MSI installs them toC:\Program Files\MongoDB\Tools\<version>\binwithout adding it toPATH; the macOS desktop app launched from Finder gets a minimalPATHwithout Homebrew): afterPATH, MongoRescue also searches well-known install directories (/opt/homebrew/bin,/usr/local/bin,/opt/local/binon macOS;%ProgramW6432%/%ProgramFiles%\MongoDB\Tools\<version>\binon Windows, newest version first;/usr/local/bin,/usr/bin,/snap/binon Linux). See docs/configuration.md.- Windows desktop shortcuts and taskbar pins kept showing the default Wails "W" icon of an older install: the installer (and uninstaller) now tells the shell to refresh its icon cache (
SHChangeNotify(SHCNE_ASSOCCHANGED)). See docs/desktop.md.
Security
- Dashboard: the storage provider shown for an S3 target is derived from the endpoint's host name (exact domain or subdomain match) instead of a substring anywhere in the URL.
- Stored credentials: sealing a value larger than 16 MiB fails with
secretbox.ErrTooLargeinstead of risking an oversized allocation. - Logs: importing the deprecated static API key no longer logs the key's lookup prefix, and the "deprecated" warnings take the source name from constants rather than from the configuration next to the key.
- Docker image: the
golangandalpinebase images are pinned by digest; the release workflow installs a fixed NSIS version with checksums required.
v0.4.0
Added
-tools-dirflag andMONGORESCUE_TOOLS_DIRenvironment variable: an absolute directory searched first formongodumpandmongorestore. Without it, MongoRescue looks intools/next to its executable, inContents/Resources/tools/of a macOS.app, then onPATH, and logs the paths found at startup. See docs/configuration.md.- Dashboard: a "New" button next to the storage target list in the "Back up now" dialog and the job form opens the storage target form on top of the dialog and selects the new target once it is saved; cancelling leaves the choice unchanged.
- Releases:
MongoRescue-desktop_<version>_checksums.txt, the SHA-256 sums of the desktop installer and archives insha256sumformat. See docs/desktop.md. - Desktop app: checks GitHub for a new release at startup and every 6 hours, and updates itself. A higher major version with installable files is mandatory (a blocking "Update required" screen, also after a reload); minor and patch updates, and releases without a file for your system, are offered in a dismissible bar. Both show the release notes. The installer (Windows) or archive (macOS, Linux) is downloaded over HTTPS and verified against the release's SHA-256 checksums before it is used; on Windows it stays locked against changes until the installer has started. Offline, the app starts as usual. See docs/desktop.md.
- Release: GitHub releases are created as drafts and published once the desktop builds and their checksums are attached.
Changed
- Releases: the GitHub release notes are the version's
CHANGELOG.mdsection (scripts/changelog-section.sh) instead of a generated commit list; a release without a section fails. - Desktop app: the setup form fills in the one-time setup code itself and hides the field, so the first administrator only chooses a username and a password. The setup-code banner and the clipboard copy are gone; the server still verifies the code. If setup fails, the code field reappears and can be edited.
Fixed
- Backups and restores no longer depend on the MongoDB Database Tools being on
PATH: tools bundled next to the executable (such as with the desktop app on Windows) are found, and a missing tool fails with an actionablemongodump not found: install MongoDB Database Tools or set MONGORESCUE_TOOLS_DIR(searched locations are logged) instead ofexecutable file not found in %PATH%. - Desktop app: the window, taskbar,
.exe, macOS.app, Linux window and the Windows installer and uninstaller show the MongoRescue logo instead of the Wails default. - Windows installer: no longer looks hung while it installs the Microsoft Edge WebView2 runtime (typical on Windows Server, which ships without it). It detects per-machine and per-user runtimes, shows what it is doing and the bootstrapper's progress window, and reports a failed runtime install instead of ignoring it. See docs/desktop.md.
v0.3.1
Changelog
- e9fda57 fix(release): put NSIS on PATH for the Windows desktop build
v0.3.0
v0.2.0
Changelog
- f076b60 build: require Go 1.26 and update golang.org/x dependencies (#3)
- 7edc26c deps: Bump golang in the docker-minor-patch group (#1)
- ed0da41 feat(auth): API key scopes
- c435b0c feat(mcp): MCP server with scoped tools, audit log and stdio bridge
- bad41a9 feat(ui): API key scopes, MCP toggle and recent API/MCP activity
- 50bef74 fix(auth): audit MCP resource reads, prompts and API key REST requests
- 22f10b4 fix(auth): explain who may restore a backup without a source connection
- 6ef0d00 fix(auth): keep the distinct IDs of coalesced audit entries
- 4909fdf fix(auth): make the user list and cross-connection restores admin-only
- 0d26923 fix(auth): sanitize client-influenced values before logging them
- 7cf4cb5 fix(mcp): keep untrusted text out of tool summaries
- d54e31e fix(mcp): never send the bridge's API key to another host
- 627ae42 fix(mcp): rate limit before the scope check and coalesce refused calls
- a0e0d58 fix(scheduler): apply retention only on scheduled runs, with floors
- 627d783 fix(scheduler): prune only a job's own scheduled backups
- 758166c fix(scheduler): store a job's run timestamps before the final record
- 9b30da0 test(integration): cover read-scoped API keys in the end-to-end test