Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1308 commits
Select commit Hold shift + click to select a range
7dc7efb
feat(integrations): warn when an MCP client's role restricts IPs
github-actions[bot] Sep 7, 2026
4fad6be
feat: expose exsting tenant library syncing jobs in the config page
github-actions[bot] Sep 7, 2026
d95ddba
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 7, 2026
ee066f7
version up
github-actions[bot] Sep 7, 2026
46d39ed
ci: consolidate CodeQL into one workflow with a scoped config
github-actions[bot] Sep 7, 2026
2670010
fix(standards): avoid run name collisions
github-actions[bot] Sep 7, 2026
11663a5
feat(offboarding): run offboarding steps sequentially on one worker
github-actions[bot] Sep 8, 2026
b7b016a
refactor(http): use return response in endpoints
github-actions[bot] Sep 8, 2026
b0fa998
feat(oneDrive): add destination parameter for shortcut creation
github-actions[bot] Sep 8, 2026
8caa635
fix(standards): recognise EDU SharePoint plans in license check
github-actions[bot] Sep 8, 2026
a0f8525
feat(oneDrive): add API endpoints and frontend actions for migrating …
github-actions[bot] Sep 8, 2026
bc7f02a
fix(standards): update documentation for OneDrive shortcut migration
github-actions[bot] Sep 8, 2026
c9a72d0
fix(standards): scope standards template tenant assignments to caller…
github-actions[bot] Sep 8, 2026
455b50b
fix(mfa-connector): handle 404 on missing key vault secret
github-actions[bot] Sep 8, 2026
53e3954
chore: bump version to 10.10.1
github-actions[bot] Sep 8, 2026
8c37f31
chore(halo): add custom user-agent to HaloPSA API calls
github-actions[bot] Sep 8, 2026
5eb8d91
test(halo): add Get-CippUserAgent mock in ticket tests
github-actions[bot] Sep 8, 2026
7f1594f
fix(sharepoint): keep the permissions report alive across flaky large…
github-actions[bot] Sep 9, 2026
98d7d99
fix(domain): skip exchange gate for manual runs
github-actions[bot] Sep 9, 2026
3de996d
fix(scheduler): size-cap scheduled task result logging
github-actions[bot] Sep 9, 2026
712974a
feat(guests): enhance guest account standard with soft-delete option
github-actions[bot] Sep 9, 2026
228d3f3
fix(halo): unwrap ticket type array before returning
github-actions[bot] Sep 9, 2026
edfff6a
feat(policies): add identity coverage view and enhance policy actions
github-actions[bot] Sep 10, 2026
2f6b51a
fix(backend): correct diagnostics and report values
github-actions[bot] Sep 10, 2026
3b0c808
Update openapi.json
github-actions[bot] Sep 10, 2026
d74997b
feat(diagnostics): add instance health sampling and self diagnostics
github-actions[bot] Sep 10, 2026
11e1c45
fix(intune): name the missing settings when an Apple enrollment templ…
github-actions[bot] Sep 10, 2026
4e2b28f
Update openapi.json
github-actions[bot] Sep 10, 2026
1c29092
refactor(auth): extract helpers from Test-CIPPAccess
github-actions[bot] Sep 10, 2026
6509966
feat(intune): bind Apple enrollment (ADE) templates to the tenant tok…
github-actions[bot] Sep 11, 2026
bd7e4f1
chore(intune): refresh settings catalog and definitions
github-actions[bot] Sep 11, 2026
2f72e43
fix(tests): read FileTypeAction in CISA MS.EXO.10.2 malware test
github-actions[bot] Sep 11, 2026
6772f87
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 11, 2026
0dad259
chore(config): update self-service license management and documentation
github-actions[bot] Sep 11, 2026
ec01e50
feat(auth): add offline_access to CIPP-SSO app permissions
github-actions[bot] Sep 11, 2026
65e513a
Merge pull request #575 from CyberDrain/chore/permissions-translator-…
github-actions[bot] Sep 11, 2026
2552d69
deprecate(reports): mark Invoke-ListSignIns as deprecated
github-actions[bot] Sep 11, 2026
52d4f75
Update openapi.json
github-actions[bot] Sep 11, 2026
7a4cd7e
feat(diagnostics): track and surface API egress usage
github-actions[bot] Sep 11, 2026
70f4fcf
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 11, 2026
2b0c5fe
chore(openapi): add egress tracking fields to schema
github-actions[bot] Sep 11, 2026
5e15049
fix(mcp): self-heal offline_access in the MCP OAuth scope advertiseme…
github-actions[bot] Sep 12, 2026
263615a
fix(cippdb): include deviceId in Azure AD Devices cache projection
github-actions[bot] Sep 14, 2026
2c0a5ba
fix(standards): skip unsupported dynamic distribution groups in group…
github-actions[bot] Sep 14, 2026
b742be8
Merge pull request #591 from CyberDrain/chore/permissions-translator-…
github-actions[bot] Sep 14, 2026
69d9a97
refactor(diagnostics): replace egress ledger with accounting table
github-actions[bot] Sep 14, 2026
2c7ef0f
chore: bump version to 10.10.3
github-actions[bot] Sep 14, 2026
d16ea38
chore: remove egress fields from openapi schema
github-actions[bot] Sep 14, 2026
27732f0
test(add-user): validate single-tenant filter resolution
github-actions[bot] Sep 14, 2026
0624292
refactor(graph): remove GraphErrorCount tenant tracking
github-actions[bot] Sep 14, 2026
8aa9d55
Merge pull request #617 from CyberDrain/chore/openapi-spec-update-202…
github-actions[bot] Sep 15, 2026
1f64951
fix(standards): ignore empty template standards in drift and on save
github-actions[bot] Sep 16, 2026
33bfc06
Merge pull request #628 from kris6673/feat/message-encryption-options
github-actions[bot] Sep 16, 2026
21a4375
Merge pull request #598 from generalct83/feat/sp-anonymous-link-expir…
github-actions[bot] Sep 16, 2026
a75b205
Merge pull request #609 from kris6673/feat/deploy-drawer-group-picker
github-actions[bot] Sep 16, 2026
5c6780b
Merge pull request #519 from malvinportner/fix/conditional-access-sta…
github-actions[bot] Sep 16, 2026
93d14f8
Merge pull request #561 from dlepi24/fix/expiring-licenses-snooze-id
github-actions[bot] Sep 16, 2026
3533954
Merge pull request #576 from Flagstream-Technologies-Inc/fix/registra…
github-actions[bot] Sep 16, 2026
370e7a2
Merge pull request #585 from kris6673/feat/sharepoint-group-connected…
github-actions[bot] Sep 16, 2026
847a40f
Merge pull request #587 from TuEye/fix/safelinks-atatchments-domain-d…
github-actions[bot] Sep 16, 2026
aac9ead
Merge pull request #579 from sfaxluke/claude/jit-vacation-mode-2f61a8
github-actions[bot] Sep 16, 2026
7c18918
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 16, 2026
1f316ad
Fix countrylist is couple of components.
github-actions[bot] Sep 16, 2026
20560c3
made buttons blue because dark/lightmode
github-actions[bot] Sep 16, 2026
9f002fc
add tap option as pwpush
github-actions[bot] Sep 16, 2026
6df723c
Add 90 days to manage alert options.
github-actions[bot] Sep 16, 2026
5932ff8
Update openapi.json
github-actions[bot] Sep 16, 2026
ffdb62f
feat(dbcache): cache tenant sharepoint usage
github-actions[bot] Sep 16, 2026
3c09b27
fix(sharepoint): add cached quota mode
github-actions[bot] Sep 16, 2026
b5ee41b
Merge pull request #637 from kris6673/feat/teams-voice-backup
github-actions[bot] Sep 16, 2026
953e05a
Merge pull request #634 from kris6673/feat/clear-onprem-attributes
github-actions[bot] Sep 16, 2026
9642b80
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 16, 2026
d040783
refactor(planner): update help and documentation text for task deleti…
github-actions[bot] Sep 16, 2026
89ba1cd
chore: add licence check to CIS_2_1_4
github-actions[bot] Sep 17, 2026
176b7a3
chore: add licence check to CIS_2_1_1
github-actions[bot] Sep 17, 2026
3e12b94
chore: add licence check to CIS_2_1_5
github-actions[bot] Sep 17, 2026
10403f6
chore: update list tests to contain 'Unlicensed' results
github-actions[bot] Sep 17, 2026
8e07588
fix(domainanalyser): overwrite DKIM Selectors instead of Add() to sto…
github-actions[bot] Sep 17, 2026
17b8995
fix(intune): give an actionable error when a template's stored null i…
github-actions[bot] Sep 17, 2026
80b6521
fix(standards): list shared mailboxes via Get-Mailbox cmdlet instead …
github-actions[bot] Sep 17, 2026
67c5957
fix(standards): resolve variables in Intune template names before com…
github-actions[bot] Sep 17, 2026
84dcb92
Merge pull request #639 from kris6673/fix/force-refresh-tenant-result
github-actions[bot] Sep 17, 2026
a0fd399
fixes hudu sync typo and tenant issue
github-actions[bot] Sep 17, 2026
f7c6c19
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 17, 2026
7561a35
hudu fix mailboxes
github-actions[bot] Sep 17, 2026
748515b
Update openapi.json
github-actions[bot] Sep 18, 2026
6004342
docs(api): regenerate openapi spec for Tier A MCP payload params
github-actions[bot] Sep 18, 2026
d130d6c
docs updates
github-actions[bot] Sep 18, 2026
31773ce
Merge pull request #653 from matstocks/fix/650-sam-permission-grants
github-actions[bot] Sep 18, 2026
98b00cf
Merge pull request #620 from John-2811/fix/gdap-cleanold-false-critical
github-actions[bot] Sep 18, 2026
039eeaa
Merge pull request #640 from Aaronkatz0/fix/edit-tenant-clear-static-…
github-actions[bot] Sep 18, 2026
38e1750
improvements to infra notice
github-actions[bot] Sep 19, 2026
970872e
Merge pull request #658 from kris6673/fix/autopilot-add-device-batch-…
github-actions[bot] Sep 19, 2026
0b15905
new license report
github-actions[bot] Sep 19, 2026
44164f3
Merge pull request #661 from luimen6/feat/mfa-alert-new-user-grace
github-actions[bot] Sep 19, 2026
a27e7ef
Merge pull request #662 from luimen6/feat/sharepoint-bulk-add-members
github-actions[bot] Sep 19, 2026
ad3cf63
Merge pull request #659 from luimen6/feat/onboarding-tenant-groups
github-actions[bot] Sep 19, 2026
735d428
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 19, 2026
ca5f2f1
fixes preprovision onedrive
github-actions[bot] Sep 19, 2026
1e751d1
Merge pull request #664 from luimen6/feat/user-template-sharepoint-sites
github-actions[bot] Sep 19, 2026
b99fb36
fixes permissions
github-actions[bot] Sep 19, 2026
8412808
update alert emails for baselines
github-actions[bot] Sep 19, 2026
09af032
Merge pull request #665 from luimen6/feat/teams-channel-sites
github-actions[bot] Sep 20, 2026
8e84f8a
Merge pull request #656 from CyberDrain/preview/mcptokenfixes
github-actions[bot] Sep 20, 2026
7059540
Merge pull request #604 from Aaronkatz0/feat/hudu-laps-bitlocker
github-actions[bot] Sep 20, 2026
9023a0e
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 20, 2026
d1a8658
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 20, 2026
ac80d73
add reasoning for ninjaone non compliant device.
github-actions[bot] Sep 20, 2026
37410ee
disable alerts
github-actions[bot] Sep 20, 2026
f0c15fb
remove alpha marker
github-actions[bot] Sep 20, 2026
11cfe85
Merge pull request #667 from CyberDrain/chore/openapi-spec-update-202…
github-actions[bot] Sep 21, 2026
880a5a4
Merge pull request #669 from CyberDrain/chore/permissions-translator-…
github-actions[bot] Sep 21, 2026
0cabc13
Merge pull request #672 from CyberDrain/feature/security-simulations
github-actions[bot] Sep 21, 2026
a44e4f7
fixes scenarios
github-actions[bot] Sep 21, 2026
b5579d6
feat(logs): add server-side API filter to logbook
github-actions[bot] Sep 21, 2026
0e833ec
fix(devicePrep): apply enrollment-time group via Graph action
github-actions[bot] Sep 21, 2026
a1e8c66
add amdx resolver
github-actions[bot] Sep 21, 2026
bd1ed60
Fix duplicate template JSON keys
github-actions[bot] Sep 22, 2026
c7ad84e
fix(api): validate report query parameters
github-actions[bot] Sep 22, 2026
8a4a950
chore: api spec description updates
github-actions[bot] Sep 22, 2026
d7c24f7
Merge pull request #684 from kris6673/feat/autopilot-profile-assignme…
github-actions[bot] Sep 22, 2026
dd74130
fix(settings): clarify access check refresh
github-actions[bot] Sep 22, 2026
fc5d670
Merge pull request #686 from kris6673/feat/hudu-pim-eligible-roles
github-actions[bot] Sep 22, 2026
bec371e
Merge pull request #674 from kris6673/fix/user-template-default-attri…
github-actions[bot] Sep 22, 2026
178334a
universal search improvements.
github-actions[bot] Sep 22, 2026
474b0a5
update alert management
github-actions[bot] Sep 22, 2026
e168c5d
fix(webhooks): dedupe audit log claims by event time
github-actions[bot] Sep 22, 2026
0243f8d
feat(defender): cache TVM export URLs
github-actions[bot] Sep 22, 2026
618e855
fix(mcp): pre-authorize clients and split URIs
github-actions[bot] Sep 22, 2026
a52deb6
Merge pull request #695 from CyberDrain/fix/baseline-migration-value-…
github-actions[bot] Sep 22, 2026
5f90449
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 22, 2026
fe2ebd1
Add or update the Azure App Service build and deployment workflow config
KelvinTegelaar Sep 22, 2026
511a60a
Security Simulations: never carry a null entry in the situation, find…
github-actions[bot] Sep 22, 2026
a10b518
fix(settings): remove invalid Timestamp filter clause
github-actions[bot] Sep 23, 2026
046aeff
fix(tests): use ExoExternalInOutlook cache for external tag tests
github-actions[bot] Sep 23, 2026
7272945
fix(setup): clear cached tokens after refresh token update
github-actions[bot] Sep 23, 2026
57474cd
bump default logs returned to 2k from 400
github-actions[bot] Sep 23, 2026
41d2f38
perf(mem): stream export-backed mem reports
github-actions[bot] Sep 23, 2026
7ad2eaa
Merge pull request #708 from kris6673/fix/setauthmethod-select-unwrap
github-actions[bot] Sep 23, 2026
aa0cecd
feat(conditional): clone CA templates to detach them from template li…
github-actions[bot] Sep 23, 2026
00b5da0
Merge pull request #710 from CyberDrain/feat/template-sync-ux
github-actions[bot] Sep 23, 2026
e30828d
Merge pull request #490 from CyberDrain/preview/bec-case-workflow
github-actions[bot] Sep 23, 2026
04fe31b
Merge pull request #497 from CyberDrain/preview/server-side-pdf-reports
github-actions[bot] Sep 23, 2026
2e40192
s
github-actions[bot] Sep 23, 2026
a8288aa
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 23, 2026
002be1d
refactor(identity): move Business Email Compromise under Identity > A…
github-actions[bot] Sep 23, 2026
90cfde1
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 23, 2026
6a21cf1
Merge pull request #694 from MartinRain/fix/halopsa-alert-consolidation
github-actions[bot] Sep 23, 2026
d34447a
refactor(scheduler): extract orchestrator priority resolution
github-actions[bot] Sep 24, 2026
fbf4791
enhance(graph-requests): add endpoint blocking checks for Graph requests
github-actions[bot] Sep 24, 2026
8982938
fix(graph-requests): harden Graph endpoint blocklist against encoding…
github-actions[bot] Sep 24, 2026
259af44
Update openapi.json
github-actions[bot] Sep 24, 2026
96b86a7
fix(ninjaone): stop queuing no-op CVE sync orchestration
github-actions[bot] Sep 24, 2026
1a5748e
fix(standards): grade app consent reviewers by presence, not count
github-actions[bot] Sep 24, 2026
5f6dc33
fix(graph): stop endpoint blocklist guard leaking $false into results
github-actions[bot] Sep 24, 2026
7eac3bc
feat(sharepoint): enhance site template deployment with channels and …
github-actions[bot] Sep 24, 2026
2f05f45
Update Get-NormalizedError.ps1
github-actions[bot] Sep 24, 2026
4cadcdc
fix(alerts): scan 30 days of quarantine for pending release requests
github-actions[bot] Sep 24, 2026
484ac8b
Update openapi.json
github-actions[bot] Sep 24, 2026
c3a26cc
fix(gradient): sync licence counts from the reporting DB cache
github-actions[bot] Sep 24, 2026
7e68135
fix(msp-apps): repackage Huntress with the vendor's current v2 instal…
github-actions[bot] Sep 24, 2026
aef3778
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 24, 2026
18f5184
Delete cachebpav2 since BPA is now removed
github-actions[bot] Sep 24, 2026
10120bb
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 24, 2026
b6f87d8
fix(baselines): expand excluded group ids to member tenants
github-actions[bot] Sep 24, 2026
3219e5a
fix(baselines): clean EXO edits and clear stale flag
github-actions[bot] Sep 25, 2026
94cb146
fix(Get-CIPPAlertMFAAlertUsers): improve handling of new user grace p…
github-actions[bot] Sep 25, 2026
2565062
fix(alerts): omit email attachments that push sendMail over 4MB
github-actions[bot] Sep 25, 2026
53a5bd4
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 25, 2026
ebf2f2e
version up
github-actions[bot] Sep 25, 2026
1677122
fix(scheduler): convert hashtable input in Add-CIPPScheduledTask
github-actions[bot] Sep 25, 2026
da9f580
Update openapi.json
github-actions[bot] Sep 25, 2026
6826fba
test(graph): stub endpoint blocklist guard in Get-GraphRequestList pa…
github-actions[bot] Sep 25, 2026
0e01d18
chore(docs): refresh published docs page snapshot from llms.txt
github-actions[bot] Sep 25, 2026
fd1bc00
fix(logs): make log retention cleanup keep up on large log tables
github-actions[bot] Sep 25, 2026
4ff149c
fix(scheduler): store ScheduledTime as string on RunNow
github-actions[bot] Sep 25, 2026
4e11b3a
fix(bec): stop Microsoft and IPv6 addresses cascading into false atta…
github-actions[bot] Sep 26, 2026
a3852e6
feat(api): document dual GET/POST for read endpoints with body fields
github-actions[bot] Sep 26, 2026
da8ca03
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 27, 2026
edd4ed6
feat(alerts): enhance task alert display title handling
github-actions[bot] Sep 28, 2026
93125b1
feat(reporting): enhance callout rendering with height fitting logic
github-actions[bot] Sep 28, 2026
5d290c5
Revert "fix(auth): check granted SAM permissions instead of CIPP's sa…
github-actions[bot] Sep 28, 2026
139faba
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 28, 2026
91a2fcf
fixes baselines max stages and app consents
github-actions[bot] Sep 28, 2026
dfc8835
fixes migration of groups, as this is now also a multi-prop.
github-actions[bot] Sep 28, 2026
4e84a91
fixes scenarios
github-actions[bot] Sep 28, 2026
587b80e
fixes name translations
github-actions[bot] Sep 28, 2026
a96e6d8
fix(ninjaone): drop rejected user batches and apply CA role exclusions
github-actions[bot] Sep 28, 2026
bf5c80e
fix(sam-cert): only prune this instance's own KV certs
github-actions[bot] Sep 28, 2026
bb72f78
fix(license-recommendation): exclude opaque add-ons from consolidation
github-actions[bot] Sep 28, 2026
8d87304
feat(standards): add EWS allowed applications standard
github-actions[bot] Sep 28, 2026
3478e9e
feat(stats): add baseline usage counts to stats payload
github-actions[bot] Sep 28, 2026
1e51056
build: add version bump script, bump to 11.0.1
github-actions[bot] Sep 28, 2026
2126c4b
chore(openapi): simplify template check response schema
github-actions[bot] Sep 28, 2026
d1a9756
fix(openapi): ensure unique operationIds for dual-method endpoints
github-actions[bot] Sep 28, 2026
23e1c29
perf(dbcache): cap the collection shape sample at 10 rows
github-actions[bot] Sep 29, 2026
35a697d
perf(dbcache): stop waiting on Intune exports and rebalance queue bands
github-actions[bot] Sep 29, 2026
d6e86ac
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into feat/sp…
github-actions[bot] Sep 29, 2026
c21edb7
perf(dbcache): stream the mailbox cache and cut its allocation
github-actions[bot] Sep 29, 2026
c107954
Update openapi.json
github-actions[bot] Sep 29, 2026
41a6f64
fix(dbcache): store the collection shape as a plain string
github-actions[bot] Sep 29, 2026
ca2be6c
Update openapi.json
github-actions[bot] Sep 29, 2026
9157130
feat(updates): show the scheduled restart time in the out-of-date alert
github-actions[bot] Sep 29, 2026
22b9a54
fix(groups): retry license assignment while a new group replicates
github-actions[bot] Sep 29, 2026
f41c960
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 29, 2026
abe6073
fix(bec): judge password resets and MFA-stopped sign-ins on evidence
github-actions[bot] Sep 29, 2026
d790123
Update openapi.json
github-actions[bot] Sep 29, 2026
9892780
feat(bec): take approved vacation-mode travel into the location verdicts
github-actions[bot] Sep 29, 2026
b82717d
Merge pull request #767 from CyberDrain/chore/docs-published-pages-up…
github-actions[bot] Sep 29, 2026
8b98607
fix: quarantine alert release request error
github-actions[bot] Sep 29, 2026
73f0878
fix(baselines): edge-trigger remediation alerts and report failed wri…
github-actions[bot] Sep 29, 2026
6506a28
perf(reports): read AllTenants report data once, scoped to the caller…
github-actions[bot] Sep 29, 2026
389cb19
fix(license-recommendation): removal candidates crashed the report
github-actions[bot] Sep 29, 2026
cc4e76d
feat: MS365 Service Health Page
github-actions[bot] Sep 30, 2026
be72298
chore(timers): Start caching and lighter tasks earlier
github-actions[bot] Sep 30, 2026
b5daad6
perf(ninjaone): cut tenant sync memory and runtime
github-actions[bot] Sep 30, 2026
1d19c98
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 30, 2026
e50bcdf
CASMailboxSMTPAuth
github-actions[bot] Sep 30, 2026
28b56ca
Update openapi.json
github-actions[bot] Sep 30, 2026
906d4ba
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 30, 2026
e968a11
fix(gradient): reuse one HTTP connection per licence sync run
github-actions[bot] Sep 30, 2026
e117abc
perf(gradient): read the service catalogue once per licence sync run
github-actions[bot] Sep 30, 2026
666dea3
fix(extensions): check the Hudu and NinjaOne APIs before syncing
github-actions[bot] Sep 30, 2026
3bcaa36
feat(bec): run each investigation phase as its own sequential job
github-actions[bot] Sep 30, 2026
1e9ec09
fix(baselines): a stage with no standards no longer returns a null entry
github-actions[bot] Sep 30, 2026
466cf97
fix: switch to api calls on table
github-actions[bot] Oct 1, 2026
be1b13e
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Oct 1, 2026
246c075
macosx support
github-actions[bot] Oct 1, 2026
d18be76
fixes issue with tests and baseline exlcusion reporting
github-actions[bot] Oct 1, 2026
09f7224
fixes join of strings
github-actions[bot] Oct 1, 2026
bc73f01
fixes shortcut looping and makes it multipost
github-actions[bot] Oct 1, 2026
40ee81f
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Oct 1, 2026
6f00f7e
add conditional feature flag enablement
github-actions[bot] Oct 1, 2026
ee83086
feat(manifest): add new scope entry to SAMManifest.json
github-actions[bot] Oct 1, 2026
220dfe4
fix(licenses): resolve SKU names from a point-lookup table instead of…
github-actions[bot] Oct 2, 2026
f0ed0fb
Update openapi.json
github-actions[bot] Oct 2, 2026
9c75e17
refactor(Invoke-ListCopilotUsage): streamline report fetching with Ge…
github-actions[bot] Oct 2, 2026
54cf04e
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Oct 2, 2026
5962d47
Update openapi.json
github-actions[bot] Oct 2, 2026
a3ee269
Update Set-CIPPDBCachePIMSettings.ps1
github-actions[bot] Oct 2, 2026
a983fdc
chore: add lastPasswordChangeDateTime to the user cache
github-actions[bot] Oct 2, 2026
9d48196
fix(dbcache): schedule baseline-read activity timeout and SMTP AUTH o…
github-actions[bot] Oct 2, 2026
670c7df
chore: remove deprecated endpoint from caching
github-actions[bot] Oct 2, 2026
43380dd
fix(standards): correct the device retirement days range in the helpe…
github-actions[bot] Oct 2, 2026
9e6e499
fix(baselines): record a skipped self-gating remediation as Compliant
github-actions[bot] Oct 2, 2026
5b317ae
perf(sharepoint): request only the cached fields in the per-site SPOS…
github-actions[bot] Oct 2, 2026
ffcc289
feat(notifications): gate Push on enrolment and point forms at Prefer…
github-actions[bot] Oct 2, 2026
3374abc
chore: bump version to 11.0.2
github-actions[bot] Oct 2, 2026
fad8e49
perf(exchange): reduce PowerShell churn in EXO bulk requests
github-actions[bot] Oct 2, 2026
28750b7
fix(ci): clear the audit, analyzer and test failures on the hotfix PR
github-actions[bot] Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
349 changes: 349 additions & 0 deletions .build/Add-OpenApiResponseSchemas.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,349 @@
#Requires -Version 7.0
<#
.SYNOPSIS
Enriches a CIPP openapi.json with typed 200 response schemas derived by static
analysis of the API and frontend repositories.

.DESCRIPTION
The generated CIPP spec types every request body but leaves every 200 response
as the generic StandardResults envelope. This stage fills typed per-endpoint
response schemas for the read surface, using two deterministic sources that are
already checked into the repositories (no live API calls):

1. Captured response shape baselines (CIPP/Tests/Shapes/*.json) - carry real
field types and nesting. Preferred when present.
2. Frontend table column declarations (simpleColumns in CIPP/src pages) -
carry field names only. Used when no baseline exists; fields are typed as
string and marked x-cipp-field-source: frontend so consumers know the type
is a name-only inference, not a verified type.

Endpoints with neither source keep the StandardResults envelope, which is the
correct shape for write/exec operations. Output is deterministic: the same input
repositories always produce a byte-identical spec.

.PARAMETER InputSpec
Path to the source openapi.json. Defaults to the repo-root spec relative to this
script (.build/.. ).

.PARAMETER OutputSpec
Path to write the enriched spec. Defaults to InputSpec (in-place rewrite).

.PARAMETER FrontendRepoPath
Path to a checkout of the CIPP frontend repository. Provides both the shape
baselines (Tests/Shapes) and the page column declarations (src).

.PARAMETER PassThru
Return the enriched spec object instead of only writing it. Used by tests.

.EXAMPLE
./Add-OpenApiResponseSchemas.ps1 -FrontendRepoPath ../CIPP

Rewrites the repo-root openapi.json in place with typed response schemas.
#>
[CmdletBinding()]
param(
[string]$InputSpec = (Join-Path $PSScriptRoot '..' 'openapi.json'),
[string]$OutputSpec,
[string]$FrontendRepoPath,
[switch]$PassThru
)

$ErrorActionPreference = 'Stop'

$script:CippHttpMethods = @('get', 'post', 'put', 'patch', 'delete')

function ConvertFrom-ShapeNode {
<#
.SYNOPSIS
Converts one node of a captured shape tree into an OpenAPI schema fragment.
#>
param($Node)

if ($Node -is [string]) {
switch ($Node) {
'string' { return @{ type = 'string' } }
'number' { return @{ type = 'number' } }
'bool' { return @{ type = 'boolean' } }
'datetime' { return [ordered]@{ type = 'string'; format = 'date-time' } }
# 'null' (captured as null at sample time) and 'truncated' (below the
# capture depth limit) carry no reliable type, so stay permissive.
default { return @{} }
}
}

if ($Node -is [System.Collections.IDictionary]) {
if ($Node['_type'] -eq 'array') {
return [ordered]@{ type = 'array'; items = (ConvertFrom-ShapeNode -Node $Node['_element']) }
}
$properties = [ordered]@{}
foreach ($key in ($Node.Keys | Sort-Object)) {
$properties[[string]$key] = ConvertFrom-ShapeNode -Node $Node[$key]
}
return [ordered]@{ type = 'object'; properties = $properties }
}

return @{}
}

function Get-ShapeBaselineMap {
<#
.SYNOPSIS
Maps endpoint name -> per-record OpenAPI schema, from captured shape baselines.
.DESCRIPTION
Reads only files carrying both _metadata and shape; the sibling
test-results.json and any non-baseline file is skipped. The per-record schema
is the baseline shape itself (the CIPP envelope's Results[] element).
#>
param([string]$ShapesDir)

$map = @{}
if (-not (Test-Path $ShapesDir)) {
Write-Warning "Shapes directory not found: $ShapesDir"
return $map
}

foreach ($file in (Get-ChildItem -Path $ShapesDir -Filter '*.json' | Sort-Object -Property FullName)) {
$doc = Get-Content -LiteralPath $file.FullName -Raw | ConvertFrom-Json -AsHashtable -Depth 100
if (-not ($doc -is [System.Collections.IDictionary] -and $doc.ContainsKey('_metadata') -and $doc.ContainsKey('shape'))) {
continue
}
$endpoint = $doc['_metadata']['endpoint']
if (-not $endpoint) { continue }
$map[$endpoint] = ConvertFrom-ShapeNode -Node $doc['shape']
}
return $map
}

function Get-FrontendColumnMap {
<#
.SYNOPSIS
Maps endpoint name -> sorted unique field names, from page simpleColumns.
.DESCRIPTION
Intent: skips conditional simpleColumns arrays to avoid non-column branch strings; false negatives beat junk fields.
Scans frontend page sources for files that pair an /api/<Endpoint> reference
with a simpleColumns array, and unions the declared column names per endpoint.
Field names are deterministic; their types are not, so callers type them as
string with a provenance marker.
#>
param([string]$SrcDir)

$map = @{}
if (-not (Test-Path $SrcDir)) {
Write-Warning "Frontend src directory not found: $SrcDir"
return $map
}

$endpointPattern = [regex]'/api/([A-Za-z0-9_]+)'
$columnsPattern = [regex]'(?s)\bsimpleColumns\s*(?:=|:)\s*(?:\{\s*)?\[(?<columns>[^\]]*)\]'
$stringPattern = [regex]'"([^"]+)"|''([^'']+)'''

$files = Get-ChildItem -Path $SrcDir -Recurse -File -Include '*.js', '*.jsx'
foreach ($file in $files) {
$text = Get-Content -LiteralPath $file.FullName -Raw
if ([string]::IsNullOrEmpty($text) -or $text -notmatch 'simpleColumns') { continue }

$endpoints = $endpointPattern.Matches($text) | ForEach-Object { $_.Groups[1].Value } | Sort-Object -Unique
if (-not $endpoints) { continue }

$columns = foreach ($colMatch in $columnsPattern.Matches($text)) {
foreach ($strMatch in $stringPattern.Matches($colMatch.Groups['columns'].Value)) {
$value = if ($strMatch.Groups[1].Success) { $strMatch.Groups[1].Value } else { $strMatch.Groups[2].Value }
if ($value) { $value }
}
}
if (-not $columns) { continue }

foreach ($endpoint in $endpoints) {
if (-not $map.ContainsKey($endpoint)) { $map[$endpoint] = [System.Collections.Generic.HashSet[string]]::new() }
foreach ($column in $columns) { [void]$map[$endpoint].Add($column) }
}
}
return $map
}

function ConvertTo-ColumnRecordSchema {
<#
.SYNOPSIS
Builds a per-record object schema from a set of frontend column names.
#>
param([System.Collections.Generic.HashSet[string]]$Columns)

$properties = [ordered]@{}
foreach ($column in ($Columns | Sort-Object)) {
$properties[$column] = [ordered]@{ type = 'string'; 'x-cipp-field-source' = 'frontend' }
}
return [ordered]@{ type = 'object'; properties = $properties }
}

function ConvertTo-ResponseEnvelopeSchema {
<#
.SYNOPSIS
Wraps a per-record schema in the CIPP { Results: [...], Metadata: {...} } envelope.
#>
param($RecordSchema)

return [ordered]@{
type = 'object'
properties = [ordered]@{
Results = [ordered]@{ type = 'array'; items = $RecordSchema }
Metadata = [ordered]@{ type = 'object' }
}
}
}


function Get-CippOperationId {
<#
.SYNOPSIS
Builds the deterministic operationId for one CIPP path and method.
.DESCRIPTION
Riftwing imports OpenAPI operations by operationId. CIPP upstream does not
currently emit operationIds, so this keeps importer keys stable without
depending on display labels or external data.
#>
param(
[Parameter(Mandatory)][string]$Path,
[Parameter(Mandatory)][string]$Method,
[Parameter(Mandatory)][string[]]$PathMethods
)

$endpointName = $Path -replace '^/api/', ''
if ($PathMethods.Count -eq 1) {
return $endpointName
}

$methodName = [System.Globalization.CultureInfo]::InvariantCulture.TextInfo.ToTitleCase($Method.ToLowerInvariant())
return "$methodName$endpointName"
}

function Add-CippOperationId {
<#
.SYNOPSIS
Injects missing operationIds and fails on duplicate operationIds.
.DESCRIPTION
Existing non-empty operationIds are preserved so this pass can retire itself
when upstream starts emitting operationIds. Duplicate operationIds are fatal
because importers commonly key operations by operationId.
#>
param([Parameter(Mandatory)][System.Collections.IDictionary]$Spec)

if (-not $Spec['paths']) { throw 'Spec has no paths.' }

$operationCount = 0
$injectedCount = 0
$operationIds = @{}

foreach ($pathEntry in $Spec['paths'].GetEnumerator()) {
$pathMethods = @($pathEntry.Value.Keys | Where-Object { $_ -in $script:CippHttpMethods })
foreach ($methodEntry in $pathEntry.Value.GetEnumerator()) {
if ($methodEntry.Key -notin $script:CippHttpMethods) { continue }

$operationCount++
$operation = $methodEntry.Value
$operationId = $operation['operationId']
if ([string]::IsNullOrWhiteSpace([string]$operationId)) {
$operationId = Get-CippOperationId -Path $pathEntry.Key -Method $methodEntry.Key -PathMethods $pathMethods
$operation['operationId'] = $operationId
$injectedCount++
}

if ($operationIds.ContainsKey($operationId)) {
throw "Duplicate operationId found: $operationId"
}
$operationIds[$operationId] = $true
}
}

return [pscustomobject]@{ Operations = $operationCount; Injected = $injectedCount; Unique = $operationIds.Count }
}

function Resolve-SpecResponse {
<#
.SYNOPSIS
Adds typed 200 response schemas to a parsed spec, in place, and returns counts.
.DESCRIPTION
The pure core of this stage: operates on an already-parsed spec hashtable and
the two endpoint maps, with no file or repository access, so it is unit
testable. Only existing 200 responses on get/post/put/patch/delete operations
are touched; everything else (including operations with no matching source) is
left exactly as found.
#>
param(
[Parameter(Mandatory)][System.Collections.IDictionary]$Spec,
[Parameter(Mandatory)][hashtable]$BaselineMap,
[Parameter(Mandatory)][hashtable]$ColumnMap
)

if (-not $Spec['paths']) { throw 'Spec has no paths.' }

$operationCount = 0
$typedCount = 0

foreach ($pathEntry in $Spec['paths'].GetEnumerator()) {
$endpoint = $pathEntry.Key -replace '^/api/', ''

$recordSchema = $null
if ($BaselineMap.ContainsKey($endpoint)) {
$recordSchema = $BaselineMap[$endpoint]
} elseif ($ColumnMap.ContainsKey($endpoint)) {
$recordSchema = ConvertTo-ColumnRecordSchema -Columns $ColumnMap[$endpoint]
}

foreach ($methodEntry in $pathEntry.Value.GetEnumerator()) {
if ($methodEntry.Key -notin $script:CippHttpMethods) { continue }
$operationCount++
if ($null -eq $recordSchema) { continue }

$responses = $methodEntry.Value['responses']
if ($null -eq $responses) { continue }

$okResponse = $responses['200']
if (-not $okResponse) { continue }

$okResponse['content'] = [ordered]@{
'application/json' = [ordered]@{ schema = (ConvertTo-ResponseEnvelopeSchema -RecordSchema $recordSchema) }
}
$typedCount++
}
}

return [pscustomobject]@{
Operations = $operationCount
Typed = $typedCount
}
}

function Add-CippResponseSchema {
<#
.SYNOPSIS
File-level orchestration: read spec + repo sources, enrich, write output.
#>
param(
[Parameter(Mandatory)][string]$InputSpec,
[Parameter(Mandatory)][string]$OutputSpec,
[Parameter(Mandatory)][string]$FrontendRepoPath,
[switch]$PassThru
)

if (-not (Test-Path $InputSpec)) { throw "Input spec not found: $InputSpec" }

$spec = Get-Content -LiteralPath $InputSpec -Raw | ConvertFrom-Json -AsHashtable -Depth 100
$baselineMap = Get-ShapeBaselineMap -ShapesDir (Join-Path $FrontendRepoPath 'Tests' 'Shapes')
$columnMap = Get-FrontendColumnMap -SrcDir (Join-Path $FrontendRepoPath 'src')

$operationIdResult = Add-CippOperationId -Spec $spec
$result = Resolve-SpecResponse -Spec $spec -BaselineMap $baselineMap -ColumnMap $columnMap
Write-Information "Operations: $($result.Operations) | typed responses added: $($result.Typed) | operationIds injected: $($operationIdResult.Injected) | unique operationIds: $($operationIdResult.Unique)" -InformationAction Continue

# Serialization is deterministic for the object this stage builds, but it does not globally canonicalize pre-existing spec keys.
[System.IO.File]::WriteAllText($OutputSpec, ($spec | ConvertTo-Json -Depth 100))

if ($PassThru) { return $spec }
}

# Run orchestration only when invoked as a script, not when dot-sourced for testing.
if ($MyInvocation.InvocationName -ne '.') {
if (-not $FrontendRepoPath) { throw 'FrontendRepoPath is required when running the script.' }
if (-not $OutputSpec) { $OutputSpec = $InputSpec }
Add-CippResponseSchema -InputSpec $InputSpec -OutputSpec $OutputSpec -FrontendRepoPath $FrontendRepoPath -PassThru:$PassThru
}
38 changes: 38 additions & 0 deletions .build/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# OpenAPI enrichment

`Add-OpenApiResponseSchemas.ps1` post-processes the generated CIPP `openapi.json`. It adds deterministic operationIds and typed `200` response schemas where response shape data can be derived from the CIPP frontend repository. It does not replace the upstream OpenAPI generator.

The enriched spec is published on each GitHub Release as the `openapi.enriched.json` release asset.

The PR check and release workflow strictly lint the CI-generated `openapi.enriched.json` with Redocly. The committed `.redocly.lint-ignore.yaml` baseline pins findings that already exist in the generated enriched spec because of upstream `openapi.json` issues. Any new Redocly error or warning that is not in the baseline fails CI.

To regenerate locally, check out the CIPP frontend repository and run:

```powershell
pwsh -NoProfile -File .build/Add-OpenApiResponseSchemas.ps1 `
-FrontendRepoPath <path-to-CIPP-frontend-checkout> `
-InputSpec ./openapi.json -OutputSpec ./openapi.enriched.json
```

If upstream `openapi.json` legitimately changes and the pinned Redocly findings must be refreshed, regenerate the enriched spec first, then regenerate the ignore baseline from that enriched output:

```powershell
pwsh -NoProfile -File .build/Add-OpenApiResponseSchemas.ps1 `
-FrontendRepoPath <path-to-CIPP-frontend-checkout> `
-InputSpec ./openapi.json -OutputSpec ./openapi.enriched.json
npx --yes @redocly/cli@2.35.1 lint ./openapi.enriched.json --generate-ignore-file
```

Do not generate the baseline from the base `openapi.json`. The lint subject is always the generated `openapi.enriched.json`.

## Known limitations

- Only `get`, `post`, `put`, `patch`, and `delete` operations are processed. `head`, `options`, and `trace` are not present in the current spec.
- Paths are assumed to start with `/api/`. All 580 current paths do.
- When a typed `200` response is added, it replaces the existing `200.content`. Today that content is only the generic `StandardResults` envelope.
- Conditional/ternary `simpleColumns` expressions are intentionally not parsed.

## Release workflow notes

- `openapi-enriched-release.yml` builds and uploads from the same tag. On `workflow_dispatch`, the `tag` input is checked out and used as the upload target. On `release: published`, the release tag is checked out and used as the upload target.
- `.github/workflows/` is gitignored in this repository, so the OpenAPI workflow files require `git add -f` when they are intentionally added or updated.
Loading
Loading