- borg-apiscp-repo: status/init/check-access/gen-passphrase/key-status/
backup-key/key-bundle/config-get/set/sites/run/running/prune/maintenance
(borg compact)/verify (borg check [--data])/set-schedule/notify-test/
list-databases. Config whitelist + single-quote escaping + newline guard,
mirroring apiscp-kopia's security boundary.
- borg-apiscp-restore: list/list-json/site (+ --subpath)/account/system/
restore-db/import-db and site-owner variants (owner-files/-account/
-restore-db/-import-db) that land under /.borg-restore chowned to the owner.
All restores are `borg extract` with computed --strip-components to rebase
archived paths under a staging target; ACLs/xattrs come back natively.