Skip to content

[pull] dev from KelvinTegelaar:dev - #105

Open
pull[bot] wants to merge 1308 commits into
isgq-github01:devfrom
KelvinTegelaar:dev
Open

pull[bot] wants to merge 1308 commits into
isgq-github01:devfrom
KelvinTegelaar:dev

Conversation

@pull

@pull pull Bot commented Jun 16, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot locked and limited conversation to collaborators Jun 16, 2026
@pull pull Bot added the ⤵️ pull label Jun 16, 2026
MCP runs under the signed-in user's role, so a role IP allow-list that omits the AI
provider's egress range silently 403s every MCP call. Warn on the API client page (page
alert + live dialog warning when MCP is toggled on). ListCustomRole now attaches IPRange
to custom roles too, so the read-only list carries the data the warning needs.

Synced from CyberDrain/CIPP@095ddbc
Two workflows both named CodeQL ran on every PR, one with the frontend as
source root, so every alert appeared twice. Keep CodeQL_Analyser.yml
(security-extended), drop codeql.yml, and add a config that scans only the
frontend and skips the generated msw worker and test fixtures.

Synced from CyberDrain/CIPP@4933849
Derive StandardsList and StandardsApply orchestrator names from tenant/template scope instead of using fixed names. This prevents concurrent manual runs from being treated as already active and silently skipped, while keeping the unsuffixed names for full all-tenant/all-template sweeps.

Synced from CyberDrain/CIPP@e73753f
Offboarding steps must run in payload order — a later step can undo an earlier one when they
race (convert-to-shared reverting mailbox grants added a step earlier). The batch already
carried the legacy DurableMode='Sequence' flag, which Craft ignores; add the Sequential flag
Craft actually honours, so the run is pinned to one worker and its steps run one at a time in
order.

Guarded for older Craft: Start-CIPPOrchestrator probes the bridge arity, so a runtime that
predates Sequential logs a warning and falls back to fan-out instead of failing — safe here
because the grant steps are already idempotent (they read the ACE back), making the ordering
belt-and-suspenders rather than the sole protection.

Synced from CyberDrain/CIPP@2e66ea4
Remove legacy Azure Functions output-binding comments from MEM assignment filter endpoints, and update ExecGenerateReportBuilderReport to return HttpResponseContext directly instead of Push-OutputBinding. This aligns endpoint response handling with the current runtime pattern.

Synced from CyberDrain/CIPP@dcab357
Enhance the New-CIPPOneDriveShortCut function to include a destination parameter, allowing users to specify whether to create shortcuts in the OneDrive root or a dedicated shortcuts folder. Update related API and frontend components to support this new functionality, ensuring a seamless user experience when selecting shortcut locations.

Synced from CyberDrain/CIPP@a230744
The SharePoint capability preset in Test-CIPPStandardLicense listed only
SHAREPOINTWAC and SHAREPOINTSTANDARD (plus the ENTERPRISE_EDU plan), so
EDU tenants whose SharePoint is provisioned as SHAREPOINTWAC_EDU and
SHAREPOINTSTANDARD_EDU were treated as unlicensed. Every SharePoint
standard then reported 'License Missing' even though the feature works
identically to the standard SKU. Add the two EDU service plans to the
preset so all SharePoint standards run on EDU tenants.

Synced from CyberDrain/CIPP@a1be5e9
…OneDrive shortcuts

Introduced new API endpoints for migrating OneDrive shortcuts into a dedicated Shortcuts folder and removing existing shortcuts. Updated the frontend to include user actions for executing these migrations, enhancing user experience in managing OneDrive shortcuts. Additionally, added a new standard for migrating shortcuts to the SharePoint standards configuration.

Synced from CyberDrain/CIPP@33dc163
Refined the documentation descriptions in standards.json and related scripts to clarify the migration process of OneDrive shortcuts into the Shortcuts folder. Removed redundant details regarding folder creation and ensured consistency across all relevant files.

Synced from CyberDrain/CIPP@2a88ace
… access

AddStandardsTemplate accepts a list of assigned tenants (which may include
AllTenants or tenant groups), but the generic single-tenant scope check in
Test-CIPPAccess cannot represent a list, so it denied the endpoint outright
for any custom role that blocks a tenant appearing in the request.

Mark the endpoint AnyTenant and validate the assignment list explicitly, the
same pattern already used by AddWin32ScriptApp and AddIntuneTemplate: each
tenant, expanded group member, and the AllTenants selection must fall within
the caller's allowed-tenant list, otherwise the save is rejected per tenant.
This is the boundary that matters because standards runs execute app-level
and never re-check custom-role access.

Synced from CyberDrain/CIPP@81083ee
Get-CippKeyVaultSecret throws on a missing secret instead of returning nothing, causing failures on first provisioning for a tenant. Treat 404 errors as a cache miss and allow provisioning to proceed, while still propagating other retrieval errors. Adds tests covering the production Key Vault storage path for cache hit, miss, and non-404 failure scenarios.

Synced from CyberDrain/CIPP@9ad4b05
All Invoke-RestMethod calls to the HaloPSA API now include a UserAgent header via Get-CippUserAgent for consistent request identification.

Synced from CyberDrain/CIPP@d678e19
Adds a stub for Get-CippUserAgent in the HaloPSA ticket Pester tests to prevent failures caused by the new dependency in New-HaloPSATicket.

Synced from CyberDrain/CIPP@8be1d34
…-tenant scans

The SharePointPermissions cache is manual-only, so nothing refreshes it on a
schedule. Push-StoreSharePointPermissions discarded an entire run whenever the
fan-in was short (a single failed or reclaimed batch drops ~20 sites), so a large
tenant could go run after run without a successful write. Its cached rows then
aged past the 30-day reporting retention and the report reverted to "No cached
permission data found" - while the silent failure left the prior data on screen,
so the run looked like it had worked.

- Tolerate a missing batch: write the sites that were collected and carry every
  expected site that did not come back over from the prior cache, flagged Skipped,
  instead of throwing the whole run away. ExpectedSiteIds (now passed by the
  collector) is what distinguishes a failed batch from a deleted site. A run that
  collected nothing still writes nothing, so genuinely stale data is not re-stamped
  fresh and still expires on schedule.
- Bound store-step memory (this path threw OutOfMemoryException on a
  112k-assignment tenant): stream rows into one Add-CIPPDbItem invocation and
  release each site's rows as they are written, and read the prior cache only for
  the sites being restored, one at a time by RowKey prefix, instead of
  materialising the whole tenant.

Adds Push-StoreSharePointPermissions.Tests.ps1 covering complete runs, carry-over
of a missing batch, returned-Skipped restore, the no-collection guard and the
no-expected-ids back-compat path.

Synced from CyberDrain/CIPP@27fc17f
Update Domain Analyser orchestration so scheduled fan-out only targets tenants with required Exchange capabilities, while on-demand API-triggered runs explicitly bypass that filter and run for the selected tenant(s). The orchestrator now builds tenant batches directly for all-tenant runs and keeps targeted single-tenant queueing behavior.

Synced from CyberDrain/CIPP@f5d4c20
Push-ExecScheduledCommand wrote the whole task result array to the
Information stream as JSON (twice per run), which the task host captures
verbatim into its log. A vulnerabilities alert on a large estate returns
thousands of per-CVE objects, so one run could emit several MB per tenant
and evict all other operational history from the durable log ring within
about an hour.

Route the result dumps through a small helper that serialises only the
first N array elements and hard-caps the string length, so a large result
costs a few KB instead of megabytes and the full array is never serialised
for the log. The result used for delivery and storage is untouched.

Synced from CyberDrain/CIPP@72af320
Updated the Disable Guests standard to include a configurable grace period for soft-deleting already-disabled guest accounts. The help text and executive summary were revised to clarify the new functionality, emphasizing the reduction of security risks from dormant accounts while maintaining a clean user directory. The impact level was increased to high, reflecting the significance of these changes. Additionally, tests were updated to ensure compliance with the new deleteGraceDays feature.

Synced from CyberDrain/CIPP@3b8b228
Invoke-RestMethod returns a top-level JSON array as a single Object[], so returning it directly made @(Get-HaloTicketType) a nested array. Assign to a variable and write it out to properly enumerate rows. Adds a Pester test covering this behavior.

Synced from CyberDrain/CIPP@a99c681
Introduced a new action to view identity coverage for policies, allowing users to see which identities are included or excluded by a policy. Updated the policy actions table in the documentation to reflect this change. Additionally, added new translation keys for coverage reasons in the CIPP translations and improved formatting for displaying coverage information in the UI.

Synced from CyberDrain/CIPP@d94a489
Fixes several backend regressions and data-shape issues across alerts and reporting endpoints. Access checks now read Type/SkipCache/TenantId from both query and body so MCP-dispatched requests no longer return empty results; Azure AD Connect status now reports real elapsed sync hours (and exposes the raw timestamp separately); and SharePoint quota totals now cast string fields to numeric values before aggregation.

The phishing alert handler now downgrades known regional Exchange API route-miss errors to a stable “API unavailable” message while preserving normal failure alerts for real errors, and new Pester coverage verifies user-only filtering plus this error behavior. openapi.json was regenerated to reflect the updated request/response contracts and parameter descriptions.

Synced from CyberDrain/CIPP@0f01241
Introduces a 5-minute InstanceHealth timer that reduces container log lines into sample and client rows, a boot marker recorded on warmup, and a stalled-run predicate. Adds the ListInstanceDiagnostics endpoint (Checks/Timeline actions) and a new frontend Diagnostics tab with charts, checks, events, and API client tables. Includes table cleanup rules, log presets, translations, and unit tests for the new PowerShell and JS helpers.

Synced from CyberDrain/CIPP@89a556f
…ate can't deploy

Apple enrollment (ADE) policies are Settings Catalog policies whose template
marks every Setup Assistant option required. Microsoft keeps adding new
required options (recently accessibility appearance and Liquid Glass), so a
template captured before an option existed can no longer be deployed - Graph
rejects the create with an opaque "A required Setting in the template is not
present in the policy" error that names only an internal GUID.

Add a deploy-only ThrowOnMissingRequired guard to Select-CIPPIntuneAvailableSetting
that, for the enrollment family only, diffs the policy's settings against the
tenant's required setting templates (already fetched to filter unavailable
settings) and throws an actionable error naming the missing settings and how to
fix them. Scoped strictly to templateFamily enrollment* / technologies
enrollment so Endpoint Security and generic Catalog policies - which deploy fine
as a subset - are never validated. The comparison and drift paths never set the
switch, so their behaviour is unchanged.

Synced from CyberDrain/CIPP@80b5e53
- Look up services by name from one catalogue read instead of fetching it for every licence of every tenant
- Look up SKU display names from a hashtable instead of scanning the conversion table per licence
- Skip the sync when the catalogue cannot be read rather than creating duplicate services

Synced from CyberDrain/CIPP@5b968d1
- NinjaOne: check the token once before queuing the daily, catch-up or on-demand per-tenant sync, and queue nothing if it fails
- Hudu: check api_info at the start of each tenant sync and stop with the Hudu error instead of failing every call
- Hudu integration test: treat the 0.0.0.0 fallback version as a failed connection and show the error

Synced from CyberDrain/CIPP@24d0837
- One sequential orchestration per investigation: a Push-BECRun job per phase, run in order on one worker, each within its own timeout
- Phases hand data forward through the BecRunState table; a failed phase is flagged on the case and the later phases still run
- Containment can run while an investigation is in progress and is recorded on that case
- Users list keeps one bulk-capable BEC Remediation action

Synced from CyberDrain/CIPP@9932a74
Get-CIPPBaseline built a stage's standards via member access on the delta rows, which
yields a lone null when the stage is empty. The editor then crashed on reopening the
baseline. The list is now enumerated explicitly so an empty stage is an empty array.

Synced from CyberDrain/CIPP@b501d55
… scanning the reporting cache

- Add Get-CIPPLicenseSkuName: LicenseSkuNames table lookups, falling back to the tenant's LicenseOverview row and backfilling the table
- ExecLicenseSearch uses it and accepts tenantFilter
- License backfill sends the current tenant and requests each SKU once per tenant
- Seed the licence SKU name table from the licence overview cache

Synced from CyberDrain/CIPP@345c50b
…t-CopilotReportPeriod function

- Introduced Get-CopilotReportPeriod to handle period validation and fallback for Copilot report requests.
- Updated report fetching logic for UserDetail, Trend, and Adoption types to use the new function, improving error handling and code clarity.

Synced from CyberDrain/CIPP@5e0f313
…verride caches

- collect ActivityBasedTimeoutPolicy in the Graph group
- write ExoCASMailboxSmtpAuth from the existing CAS mailbox stream
- register both cache types

Synced from CyberDrain/CIPP@60e5ea0
…r text

Intune accepts 30 to 270 days for the device cleanup rule; the classic standard's helper
text said 31 to 365.

fixes #811

Synced from CyberDrain/CIPP@d31bdc4
The Check extension executor compares a config fingerprint and skips the redeploy when
nothing changed, but the engine still logged "Successfully changed" and recorded the run
as Remediated. The executor now returns an explicit unchanged marker and the engine
records that run as Compliant with no remediation log line or alert.

Synced from CyberDrain/CIPP@9a9bb2d
…ences

A task asking for Push from a user with no registered devices would notify
nobody. Add-CIPPScheduledTask now refuses it with a pointer to Preferences;
every form funnels through there, so offboarding, JIT admin, vacation mode
and add/edit user are covered. System-created tasks carry no principal and
never select Push, so they are unaffected.

Frontend
- usePushDevices reads the same paginated query the Preferences table runs
  under ListPushSubscriptions and exposes a flattened device list and the
  VAPID public key. Sharing that key with a plain ApiGetCall made the two
  fight over one cache entry.
- Scheduler and alert forms only offer "Push (notify me)" once a device is
  registered, with helper text that says where to enrol or how many devices
  will be notified.
- Preferences card: stable dataMap for the device table (an inline function
  re-mapped the rows on every render and made the table flicker) and the
  public key from the shared hook.

Backend
- Log the push service's status when an expired subscription is pruned.

Tests: enrolment guard (refused with no devices, accepted once enrolled,
device table untouched otherwise); hook reads the paginated cache and words
the hint by count. Verified in Chrome via Playwright: enrol, FCM accepts,
service worker displays the notification, impersonation blocks enrolment,
remove clears the row.

Synced from CyberDrain/CIPP@075753d
- New-ExoBulkRequest: .Where() for the tenant lookup and 429 scan, skip the per-response PSObject.Copy() for object bodies, serialise batch payloads with CippJson.ToJson
- Push-GetMailboxPermissionsBatch: .Where() for the mailbox lookups, drop the per-batch ConvertTo-Json sample logging

Synced from CyberDrain/CIPP@ae3310d
Bumps next to 16.3.8 for the next/og advisory and brace-expansion and dompurify to their
patched releases; suppresses the plain-text SecureString rule where the VAPID private key
is handed to Key Vault; gives Service Health a docs link target; and updates two tests
that lagged behind the BEC drawer hint text and the non-dismissible legacy notice.

Synced from CyberDrain/CIPP@9d43b99
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant