Skip to content

Add Backup & Restore page with Google Drive integration - #3

Merged
Undermozes merged 4 commits into
masterfrom
copilot/add-backup-feature
Mar 11, 2026
Merged

Undermozes merged 4 commits into
masterfrom
copilot/add-backup-feature

Conversation

Copilot AI commented Mar 11, 2026 •

Copy link
Copy Markdown

Users had no way to back up their account data (devices, device groups). This adds a /backup page enabling local JSON backup/restore and cloud storage via Google Drive OAuth.

Backup page

Core changes

  • Shared/Dtos/BackupData.cs — DTO models (BackupData, DeviceBackupDto, DeviceGroupBackupDto) for serializing user account data
  • Server/Services/BackupService.cs — IBackupService for creating, serializing, deserializing, and restoring backups. Restore only updates device metadata (alias, tags, notes, group) for devices that still exist in the org
  • Server/Services/GoogleDriveService.cs — IGoogleDriveService wrapping Google Drive v3 API: OAuth flow, upload/list/download to a Remotely Backups folder
  • Server/API/GoogleDriveCallbackController.cs — OAuth callback endpoint with cryptographic state token validation
  • Server/Components/Pages/Backup.razor — Full page UI: download backup, upload restore file, connect Google Drive, list/restore cloud backups
  • Server/Components/Layout/NavMenu.razor — Added "Backup" nav link for authenticated users

Security

  • CSRF: one-time cryptographic state tokens for OAuth callback validation
  • Open redirect: LocalRedirect("/backup") instead of Redirect
  • Ownership: backup userName verified against current user before restore
  • Size limits: 10MB cap on both local file upload and Google Drive downloads
  • Async: RestoreBackupAsync avoids .Wait() deadlocks

Configuration

Google Drive is optional. Server admins add credentials to appsettings.json:

"GoogleDrive": {
  "ClientId": "",
  "ClientSecret": ""
}

When unconfigured, the UI shows an informational message instead of the connect button.

Tests

9 new tests in BackupServiceTests.cs covering creation, round-trip serialization, restore behavior, and edge cases. All 27 tests (18 existing + 9 new) pass.


Please read the following. Do not delete below this line.

Thank you for your contribution to the Remotely project. It is required that contributors assign copyright to Immense Networks so we retain full ownership of the project.

This makes it easier for other entities to use the software because they only have to deal with one copyright holder. It also gives me assurance that we'll be able to make decisions in the future without gathering and consulting all contributors.

While this may seem odd, many open source maintainers practice this. Here are a couple well-known examples:

A nice article on the topic can be found here: https://haacked.com/archive/2006/01/26/WhoOwnstheCopyrightforAnOpenSourceProject.aspx/

By submitting this PR, you agree to the following:

You hereby assign copyright in this PR's code to the Remotely project and its copyright holder, Immense Networks, to be licensed under the same terms as the rest of the code. You agree to relinquish any and all copyright interest in the software, to the detriment of your heirs and successors.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • api.cdnjs.com
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj ely uppo�� (dns block)
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj /p:ResolveLibManAssets=false ptsP�� (dns block)
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj /p:LibManRestore=false /p:DisableLibManRestore=true --no-restore (dns block)
  • unpkg.com
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj ely uppo�� (dns block)
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj /p:ResolveLibManAssets=false ptsP�� (dns block)
    • Triggering command: /usr/bin/dotnet dotnet build Server/Server.csproj /p:LibManRestore=false /p:DisableLibManRestore=true --no-restore (dns block)
  • www.myget.org
    • Triggering command: /opt/hostedtoolcache/CodeQL/2.24.2/x64/codeql/csharp/tools/linux64/Semmle.Autobuild.CSharp /opt/hostedtoolcache/CodeQL/2.24.2/x64/codeql/csharp/tools/linux64/Semmle.Autobuild.CSharp (dns block)
    • Triggering command: /usr/bin/dotnet dotnet restore --no-dependencies /home/REDACTED/work/Remotely/Remotely/Remotely.sln --packages /tmp/codeql-scratch-308cdbf2ab4d8643/dbs/csharp/working/packages /p:DisableImplicitNuGetFallbackFolder=true --verbosity normal /p:TargetFrameworkRootPath=/tmp/codeql-scratch-308cdbf2ab4d8643/dbs/csharp/working/emptyFakeDotnetRoot /p:NetCoreTargetingPackRoot=/tmp/codeql-scratch-308cdbf2ab4d8643/dbs/csharp/working/emptyFakeDotnetRoot /p:AllowMissingPrunePackageData=true /hom�� (dns block)

If you need me to access, download, or install something from one of these locations, you can either:


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Copilot AI and others added 3 commits March 11, 2026 19:38
- Add BackupData DTO model for serializing user account data
- Add GoogleDriveOptions configuration model
- Add IBackupService/BackupService for creating and restoring backups
- Add IGoogleDriveService/GoogleDriveService for Google Drive OAuth
- Add GoogleDriveCallbackController for OAuth callback
- Add Backup.razor page at /backup with full UI
- Add backup link to NavMenu
- Register services in Program.cs
- Add Google Drive config to appsettings.json
- Add Google.Apis.Drive.v3 NuGet package
- Add DownloadFile JS interop method

Co-authored-by: Undermozes <58026189+Undermozes@users.noreply.github.com>
…ests

- Make RestoreBackup async (RestoreBackupAsync) to prevent deadlocks
- Use DateTimeOffset.Now instead of DateTime.Now for consistency
- Add TODO comment about in-memory token storage
- Add 9 unit tests for BackupService
- Register logging in test IoCActivator

Co-authored-by: Undermozes <58026189+Undermozes@users.noreply.github.com>
… limits

- Add cryptographic state token validation for OAuth callback (CSRF protection)
- Use LocalRedirect instead of Redirect to prevent open redirect
- Add backup ownership verification before restore
- Add 10MB download size limit for Google Drive files
- ValidateOAuthState method for one-time use state tokens

Co-authored-by: Undermozes <58026189+Undermozes@users.noreply.github.com>
Copilot AI changed the title [WIP] Add backup functionality for user accounts to Google Drive Add Backup & Restore page with Google Drive integration Mar 11, 2026
@Undermozes
Undermozes marked this pull request as ready for review March 11, 2026 20:03
@Undermozes
Undermozes merged commit 01f1fcd into master Mar 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants