Version 1.5.0
Overview
Version 1.5.0 introduces new features including an optional Daily Summary email notification, scoped API keys with IP allowlists for external API access, per-user server access controls, and Duplicati version badges displayed on the dashboard. Notification emails are now formatted in Markdown. The cron service defaults to binding to localhost. Additionally, the database schema is upgraded to version 4.3 during startup.
New features
Daily Summary
- One status email per day: Settings → Daily Summary (off by default) sends a single localised snapshot of every known backup job at a time you choose in your browser timezone. The schedule is stored as UTC. The default for new installations is 01:00 UTC. The cron task runs once a day at that time.
- What is paused: While Daily Summary is on, backup and overdue emails to the default Email recipient are not sent. Additional email destinations in Backup Notifications still receive matching events, and per-job NTFY continues. Those per-job settings stay stored and resume when the mode is turned off.
- Recipient and dashboard link: An optional override recipient sends the summary somewhere other than the Email settings address. An optional public dashboard URL (or the
DUPLISTATUS_PUBLIC_URLenvironment variable) fills{duplistatus_link}in the email.
External API protection
- Scoped API keys (issue #79): Administrators can create
uploadandreadkeys. They are optional and off by default, so existing Duplicati jobs keep working. The secret is shown once and later identified by a fingerprint. When keys are not required, a valid matching key is accepted and tracked; an invalid, disabled, expired, or wrong-scope key is ignored and the request still proceeds. - IP allowlists: Separate CIDR lists can restrict the admin interface and the external APIs (
/api/upload,/api/summary,/api/lastbackup*). Both lists are off by default and always include127.0.0.1and::1. Forwarded client addresses are trusted only when the TCP peer is a configured trusted proxy. - Upload limits:
/api/uploadhas a configurable body-size cap (default 5 MB) and per-IP rate limits.
Access and versions
- Per-user server access: Settings → Users can limit a non-admin account to selected servers. The default remains every current and future server. A custom list hides other servers on the dashboard, detail pages, charts, and settings lists. Administrators always see every server.
- Duplicati version badges: Dashboard cards and the table show each server’s Duplicati version against the latest release for that channel (
stable,beta,experimental,canary). Current versions use muted text; outdated versions use warning yellow. Settings → Duplicati Versions shows the cached channel releases and lets administrators set a daily, 12-hour, or 6-hour check. - Delivery failures: Administrators see a toolbar button while email or NTFY delivery is failing. It shows the error and links to the matching settings page.
- Weekly database compact: Every Sunday at 04:00 UTC the cron service removes backup rows whose server is gone, servers with no backups, leftover notification settings, and old Daily Summary delivery rows, then vacuums SQLite.
- Relative time in the UI language (issue #74): Display Settings → Format Locale has an opt-in checkbox so relative-time phrases stay in the interface language when Format Locale is overridden.
Improvements
Notifications
- Markdown email templates: Success, Warning/Error, Overdue, and Daily Summary bodies are Markdown, rendered to sanitised HTML and plain text. Unmodified stored defaults are upgraded to the new layout; customised templates are kept. NTFY messages send Markdown and omit GFM table header rows.
- Language follows the signed-in user: Interface language is stored per account in the browser, in the same way as theme and display settings. The
NEXT_LOCALEcookie still drives the login page and server rendering. The Hindi locale code is nowhi; existinghi-Latncookies and bookmarks still resolve.
Operations
- Cron control plane: The cron service binds to
127.0.0.1by default (CRON_BIND_HOST). Binding elsewhere requiresCRON_SERVICE_SECRET. Administrator session routes are required to change cron tasks through the app. - Database restore size: Settings → Database Maintenance accepts restore uploads up to 200 MB. If you put Nginx in front, set
client_max_body_sizeto at least 256 MB so the proxy does not cut the file first. - Development server:
pnpm devstarts Next.js (port 8666) and the cron service (port 8667) together. CTRL-C stops both.
Bug fixes
- Overdue alerts no longer repeat on every check: A failed notification channel no longer sends another overdue alert on the next monitoring pass when another channel was already delivered. The one-time, daily, weekly, or monthly window is recorded after any successful channel.
- Collect logs on Duplicati 2.4: Collecting backup logs and syncing schedules no longer fail with
Could not find machine-id in system optionsagainst Duplicati 2.4.0 and later. The configured machine ID is read from server settings. - Docker startup: The production cron process no longer exits immediately on container start, and image builds no longer fail while installing dependencies on overlay filesystems.
- First login: After the required password change on a fresh instance, the app opens the dashboard.
- Daily Summary schedule: Changing the send time creates a new occurrence. That clock time still sends after Send summary now or another email the same day. The job list matches the dashboard (latest report per server and backup name).
Security
Probes, templates, and dependencies
- Health and ping:
GET /api/healthno longer lists SQLite tables or runs dashboard queries./api/healthand/api/pingare rate-limited per IP for clients that are not on loopback. When either IP allowlist is enabled, those probes accept loopback plus addresses from the admin list or the external list. - Email HTML: Notification bodies are parsed as Markdown with raw HTML disabled, then sanitised before sending.
- Dependency fixes:
nodemaileris now 10.0.9. The documentation workspace audit findings were cleared with updatedundici,svgo, andimage-size-next.
Migration notes
From version 1.4.2
When upgrading to version 1.5.0:
- Database migrations run on startup: Schema 4.2 adds the Daily Summary delivery ledger. Schema 4.3 adds per-user server access. Existing users keep access to every server.
- New controls stay off: Daily Summary, required API keys, and both IP allowlists default to off. Existing Duplicati upload URLs keep working until you turn protection on.
- Allowlists always include loopback:
127.0.0.1and::1are merged into both lists and cannot be removed in Settings. - Cron binds to localhost: The cron port is not reachable from other hosts unless you set
CRON_BIND_HOSTandCRON_SERVICE_SECRET. - Default notification templates: Unmodified Success, Warning, Overdue, and Daily Summary templates are replaced with the Markdown defaults. Customised templates are left as they are.
- Dependencies: Run
pnpm installto apply the updated lockfile and overrides. Node.js 24 or newer is still required.
Support
Getting help
- Documentation: User Guide
- Email settings: Email configuration guide
- API reference: API documentation
- Migration guide: Version upgrade migration
- Community: GitHub Discussions
- Issues: GitHub Issues
Reporting bugs
When reporting bugs, please include:
- Version: 1.5.0
- Operating system and version
- Docker/podman version
- Container type (Docker or podman)
- Error messages and logs
- Steps to reproduce
Detailed changelog
The sections above are the highlights of this release. The complete list of changes is in dev/CHANGELOG.md under [1.5.0].
License
This project is licensed under the Apache License 2.0.
Copyright © 2026 Waldemar Scudeller Jr.