Conversation
MCP runs under the signed-in user's role, so a role IP allow-list that omits the AI provider's egress range silently 403s every MCP call. Warn on the API client page (page alert + live dialog warning when MCP is toggled on). ListCustomRole now attaches IPRange to custom roles too, so the read-only list carries the data the warning needs. Synced from CyberDrain/CIPP@095ddbc
Synced from CyberDrain/CIPP@5d12ed2
Two workflows both named CodeQL ran on every PR, one with the frontend as source root, so every alert appeared twice. Keep CodeQL_Analyser.yml (security-extended), drop codeql.yml, and add a config that scans only the frontend and skips the generated msw worker and test fixtures. Synced from CyberDrain/CIPP@4933849
Derive StandardsList and StandardsApply orchestrator names from tenant/template scope instead of using fixed names. This prevents concurrent manual runs from being treated as already active and silently skipped, while keeping the unsuffixed names for full all-tenant/all-template sweeps. Synced from CyberDrain/CIPP@e73753f
Offboarding steps must run in payload order — a later step can undo an earlier one when they race (convert-to-shared reverting mailbox grants added a step earlier). The batch already carried the legacy DurableMode='Sequence' flag, which Craft ignores; add the Sequential flag Craft actually honours, so the run is pinned to one worker and its steps run one at a time in order. Guarded for older Craft: Start-CIPPOrchestrator probes the bridge arity, so a runtime that predates Sequential logs a warning and falls back to fan-out instead of failing — safe here because the grant steps are already idempotent (they read the ACE back), making the ordering belt-and-suspenders rather than the sole protection. Synced from CyberDrain/CIPP@2e66ea4
Remove legacy Azure Functions output-binding comments from MEM assignment filter endpoints, and update ExecGenerateReportBuilderReport to return HttpResponseContext directly instead of Push-OutputBinding. This aligns endpoint response handling with the current runtime pattern. Synced from CyberDrain/CIPP@dcab357
Enhance the New-CIPPOneDriveShortCut function to include a destination parameter, allowing users to specify whether to create shortcuts in the OneDrive root or a dedicated shortcuts folder. Update related API and frontend components to support this new functionality, ensuring a seamless user experience when selecting shortcut locations. Synced from CyberDrain/CIPP@a230744
The SharePoint capability preset in Test-CIPPStandardLicense listed only SHAREPOINTWAC and SHAREPOINTSTANDARD (plus the ENTERPRISE_EDU plan), so EDU tenants whose SharePoint is provisioned as SHAREPOINTWAC_EDU and SHAREPOINTSTANDARD_EDU were treated as unlicensed. Every SharePoint standard then reported 'License Missing' even though the feature works identically to the standard SKU. Add the two EDU service plans to the preset so all SharePoint standards run on EDU tenants. Synced from CyberDrain/CIPP@a1be5e9
…OneDrive shortcuts Introduced new API endpoints for migrating OneDrive shortcuts into a dedicated Shortcuts folder and removing existing shortcuts. Updated the frontend to include user actions for executing these migrations, enhancing user experience in managing OneDrive shortcuts. Additionally, added a new standard for migrating shortcuts to the SharePoint standards configuration. Synced from CyberDrain/CIPP@33dc163
Refined the documentation descriptions in standards.json and related scripts to clarify the migration process of OneDrive shortcuts into the Shortcuts folder. Removed redundant details regarding folder creation and ensured consistency across all relevant files. Synced from CyberDrain/CIPP@2a88ace
… access AddStandardsTemplate accepts a list of assigned tenants (which may include AllTenants or tenant groups), but the generic single-tenant scope check in Test-CIPPAccess cannot represent a list, so it denied the endpoint outright for any custom role that blocks a tenant appearing in the request. Mark the endpoint AnyTenant and validate the assignment list explicitly, the same pattern already used by AddWin32ScriptApp and AddIntuneTemplate: each tenant, expanded group member, and the AllTenants selection must fall within the caller's allowed-tenant list, otherwise the save is rejected per tenant. This is the boundary that matters because standards runs execute app-level and never re-check custom-role access. Synced from CyberDrain/CIPP@81083ee
Get-CippKeyVaultSecret throws on a missing secret instead of returning nothing, causing failures on first provisioning for a tenant. Treat 404 errors as a cache miss and allow provisioning to proceed, while still propagating other retrieval errors. Adds tests covering the production Key Vault storage path for cache hit, miss, and non-404 failure scenarios. Synced from CyberDrain/CIPP@9ad4b05
All Invoke-RestMethod calls to the HaloPSA API now include a UserAgent header via Get-CippUserAgent for consistent request identification. Synced from CyberDrain/CIPP@d678e19
Adds a stub for Get-CippUserAgent in the HaloPSA ticket Pester tests to prevent failures caused by the new dependency in New-HaloPSATicket. Synced from CyberDrain/CIPP@8be1d34
…-tenant scans The SharePointPermissions cache is manual-only, so nothing refreshes it on a schedule. Push-StoreSharePointPermissions discarded an entire run whenever the fan-in was short (a single failed or reclaimed batch drops ~20 sites), so a large tenant could go run after run without a successful write. Its cached rows then aged past the 30-day reporting retention and the report reverted to "No cached permission data found" - while the silent failure left the prior data on screen, so the run looked like it had worked. - Tolerate a missing batch: write the sites that were collected and carry every expected site that did not come back over from the prior cache, flagged Skipped, instead of throwing the whole run away. ExpectedSiteIds (now passed by the collector) is what distinguishes a failed batch from a deleted site. A run that collected nothing still writes nothing, so genuinely stale data is not re-stamped fresh and still expires on schedule. - Bound store-step memory (this path threw OutOfMemoryException on a 112k-assignment tenant): stream rows into one Add-CIPPDbItem invocation and release each site's rows as they are written, and read the prior cache only for the sites being restored, one at a time by RowKey prefix, instead of materialising the whole tenant. Adds Push-StoreSharePointPermissions.Tests.ps1 covering complete runs, carry-over of a missing batch, returned-Skipped restore, the no-collection guard and the no-expected-ids back-compat path. Synced from CyberDrain/CIPP@27fc17f
Update Domain Analyser orchestration so scheduled fan-out only targets tenants with required Exchange capabilities, while on-demand API-triggered runs explicitly bypass that filter and run for the selected tenant(s). The orchestrator now builds tenant batches directly for all-tenant runs and keeps targeted single-tenant queueing behavior. Synced from CyberDrain/CIPP@f5d4c20
Push-ExecScheduledCommand wrote the whole task result array to the Information stream as JSON (twice per run), which the task host captures verbatim into its log. A vulnerabilities alert on a large estate returns thousands of per-CVE objects, so one run could emit several MB per tenant and evict all other operational history from the durable log ring within about an hour. Route the result dumps through a small helper that serialises only the first N array elements and hard-caps the string length, so a large result costs a few KB instead of megabytes and the full array is never serialised for the log. The result used for delivery and storage is untouched. Synced from CyberDrain/CIPP@72af320
Updated the Disable Guests standard to include a configurable grace period for soft-deleting already-disabled guest accounts. The help text and executive summary were revised to clarify the new functionality, emphasizing the reduction of security risks from dormant accounts while maintaining a clean user directory. The impact level was increased to high, reflecting the significance of these changes. Additionally, tests were updated to ensure compliance with the new deleteGraceDays feature. Synced from CyberDrain/CIPP@3b8b228
Invoke-RestMethod returns a top-level JSON array as a single Object[], so returning it directly made @(Get-HaloTicketType) a nested array. Assign to a variable and write it out to properly enumerate rows. Adds a Pester test covering this behavior. Synced from CyberDrain/CIPP@a99c681
Introduced a new action to view identity coverage for policies, allowing users to see which identities are included or excluded by a policy. Updated the policy actions table in the documentation to reflect this change. Additionally, added new translation keys for coverage reasons in the CIPP translations and improved formatting for displaying coverage information in the UI. Synced from CyberDrain/CIPP@d94a489
Fixes several backend regressions and data-shape issues across alerts and reporting endpoints. Access checks now read Type/SkipCache/TenantId from both query and body so MCP-dispatched requests no longer return empty results; Azure AD Connect status now reports real elapsed sync hours (and exposes the raw timestamp separately); and SharePoint quota totals now cast string fields to numeric values before aggregation. The phishing alert handler now downgrades known regional Exchange API route-miss errors to a stable “API unavailable” message while preserving normal failure alerts for real errors, and new Pester coverage verifies user-only filtering plus this error behavior. openapi.json was regenerated to reflect the updated request/response contracts and parameter descriptions. Synced from CyberDrain/CIPP@0f01241
Synced from CyberDrain/CIPP@8a7d336
Introduces a 5-minute InstanceHealth timer that reduces container log lines into sample and client rows, a boot marker recorded on warmup, and a stalled-run predicate. Adds the ListInstanceDiagnostics endpoint (Checks/Timeline actions) and a new frontend Diagnostics tab with charts, checks, events, and API client tables. Includes table cleanup rules, log presets, translations, and unit tests for the new PowerShell and JS helpers. Synced from CyberDrain/CIPP@89a556f
…ate can't deploy Apple enrollment (ADE) policies are Settings Catalog policies whose template marks every Setup Assistant option required. Microsoft keeps adding new required options (recently accessibility appearance and Liquid Glass), so a template captured before an option existed can no longer be deployed - Graph rejects the create with an opaque "A required Setting in the template is not present in the policy" error that names only an internal GUID. Add a deploy-only ThrowOnMissingRequired guard to Select-CIPPIntuneAvailableSetting that, for the enrollment family only, diffs the policy's settings against the tenant's required setting templates (already fetched to filter unavailable settings) and throws an actionable error naming the missing settings and how to fix them. Scoped strictly to templateFamily enrollment* / technologies enrollment so Endpoint Security and generic Catalog policies - which deploy fine as a subset - are never validated. The comparison and drift paths never set the switch, so their behaviour is unchanged. Synced from CyberDrain/CIPP@80b5e53
Synced from CyberDrain/CIPP@63fe1f8
- Look up services by name from one catalogue read instead of fetching it for every licence of every tenant - Look up SKU display names from a hashtable instead of scanning the conversion table per licence - Skip the sync when the catalogue cannot be read rather than creating duplicate services Synced from CyberDrain/CIPP@5b968d1
- NinjaOne: check the token once before queuing the daily, catch-up or on-demand per-tenant sync, and queue nothing if it fails - Hudu: check api_info at the start of each tenant sync and stop with the Hudu error instead of failing every call - Hudu integration test: treat the 0.0.0.0 fallback version as a failed connection and show the error Synced from CyberDrain/CIPP@24d0837
- One sequential orchestration per investigation: a Push-BECRun job per phase, run in order on one worker, each within its own timeout - Phases hand data forward through the BecRunState table; a failed phase is flagged on the case and the later phases still run - Containment can run while an investigation is in progress and is recorded on that case - Users list keeps one bulk-capable BEC Remediation action Synced from CyberDrain/CIPP@9932a74
Get-CIPPBaseline built a stage's standards via member access on the delta rows, which yields a lone null when the stage is empty. The editor then crashed on reopening the baseline. The list is now enumerated explicitly so an empty stage is an empty array. Synced from CyberDrain/CIPP@b501d55
Synced from CyberDrain/CIPP@05fbe2b
Synced from CyberDrain/CIPP@8e403e2
… scanning the reporting cache - Add Get-CIPPLicenseSkuName: LicenseSkuNames table lookups, falling back to the tenant's LicenseOverview row and backfilling the table - ExecLicenseSearch uses it and accepts tenantFilter - License backfill sends the current tenant and requests each SKU once per tenant - Seed the licence SKU name table from the licence overview cache Synced from CyberDrain/CIPP@345c50b
Synced from CyberDrain/CIPP@4c977a7
…t-CopilotReportPeriod function - Introduced Get-CopilotReportPeriod to handle period validation and fallback for Copilot report requests. - Updated report fetching logic for UserDetail, Trend, and Adoption types to use the new function, improving error handling and code clarity. Synced from CyberDrain/CIPP@5e0f313
Synced from CyberDrain/CIPP@270a5c5
…verride caches - collect ActivityBasedTimeoutPolicy in the Graph group - write ExoCASMailboxSmtpAuth from the existing CAS mailbox stream - register both cache types Synced from CyberDrain/CIPP@60e5ea0
…r text Intune accepts 30 to 270 days for the device cleanup rule; the classic standard's helper text said 31 to 365. fixes #811 Synced from CyberDrain/CIPP@d31bdc4
The Check extension executor compares a config fingerprint and skips the redeploy when nothing changed, but the engine still logged "Successfully changed" and recorded the run as Remediated. The executor now returns an explicit unchanged marker and the engine records that run as Compliant with no remediation log line or alert. Synced from CyberDrain/CIPP@9a9bb2d
…ites read Synced from CyberDrain/CIPP@8b65f67
…ences A task asking for Push from a user with no registered devices would notify nobody. Add-CIPPScheduledTask now refuses it with a pointer to Preferences; every form funnels through there, so offboarding, JIT admin, vacation mode and add/edit user are covered. System-created tasks carry no principal and never select Push, so they are unaffected. Frontend - usePushDevices reads the same paginated query the Preferences table runs under ListPushSubscriptions and exposes a flattened device list and the VAPID public key. Sharing that key with a plain ApiGetCall made the two fight over one cache entry. - Scheduler and alert forms only offer "Push (notify me)" once a device is registered, with helper text that says where to enrol or how many devices will be notified. - Preferences card: stable dataMap for the device table (an inline function re-mapped the rows on every render and made the table flicker) and the public key from the shared hook. Backend - Log the push service's status when an expired subscription is pruned. Tests: enrolment guard (refused with no devices, accepted once enrolled, device table untouched otherwise); hook reads the paginated cache and words the hint by count. Verified in Chrome via Playwright: enrol, FCM accepts, service worker displays the notification, impersonation blocks enrolment, remove clears the row. Synced from CyberDrain/CIPP@075753d
- New-ExoBulkRequest: .Where() for the tenant lookup and 429 scan, skip the per-response PSObject.Copy() for object bodies, serialise batch payloads with CippJson.ToJson - Push-GetMailboxPermissionsBatch: .Where() for the mailbox lookups, drop the per-batch ConvertTo-Json sample logging Synced from CyberDrain/CIPP@ae3310d
Bumps next to 16.3.8 for the next/og advisory and brace-expansion and dompurify to their patched releases; suppresses the plain-text SecureString rule where the VAPID private key is handed to Key Vault; gives Service Health a docs link target; and updates two tests that lagged behind the BEC drawer hint text and the non-dismissible legacy notice. Synced from CyberDrain/CIPP@9d43b99
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )