Skip to content

[pull] dev from KelvinTegelaar:dev - #108

Open
pull[bot] wants to merge 1019 commits into
isgq-github01:devfrom
KelvinTegelaar:dev
Open

pull[bot] wants to merge 1019 commits into
isgq-github01:devfrom
KelvinTegelaar:dev

Conversation

@pull

@pull pull Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot locked and limited conversation to collaborators Aug 13, 2026
@pull pull Bot added the ⤵️ pull label Aug 13, 2026
Adds docsPath entries to Endpoint MEM and email report navigation items to enable proper help link resolution. Also updates the help-links test to exclude two paths without documentation yet.

Synced from CyberDrain/CIPP@3486e07
…ams policies

Get-RetentionCompliancePolicy reports each rule's parent policy by GUID, but
Invoke-ListRetentionCompliancePolicy matched rules by policy Name, so every
policy showed RuleCount 0 and its retention period never surfaced. Match on the
policy GUID and expose the associated rule's action and duration.

The listing also relied on the flat Workload string, which is a fixed superset
(Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, DynamicScope)
that does not reflect a policy's real scope. Fetch policies with
-DistributionDetail and derive an accurate ScopedLocations summary from the
populated location fields; this also fills in the per-location off-canvas fields.

Teams-scoped retention policies are not returned by the default cmdlet call, so
they were absent from the list. Fetch them with -TeamsPolicyOnly and merge,
de-duped by GUID.

Synced from CyberDrain/CIPP@237edd5
feat(pim): PIM Configuration, Templates and Standards

Synced from CyberDrain/CIPP@c3bec92
…p-expiry-alerts

feat(alerts): make APN/DEP/VPP expiry alert window configurable

Synced from CyberDrain/CIPP@da4e8ff
…stem-template

feat(templates): add install-as-system option to store app templates

Synced from CyberDrain/CIPP@3a5aa0d
…filters

feat(domains-analyser): add mail provider and onmicrosoft.com column filters

Synced from CyberDrain/CIPP@a4aee7d
feat(mfa): add OTP verification and fix connector token caching

Synced from CyberDrain/CIPP@49ef0e9
Adds a MailFlowReportButton and MailFlowReportDocument that generate a client-ready PDF from Exchange mail flow statistics. Integrates the report into the mail flow statistics page, the branding preview, and the cover preset list. Includes sample data and vitest tests that render the document through react-pdf's layout pass.

Synced from CyberDrain/CIPP@ea1830d
CippChartCard assigns colors by slice index (green→low, orange→medium, red→high), but the API returns byRisk in alphabetical order. Add sortByRiskSeverity to reorder slices as Low, Medium, High so severity colors are correct. Unrecognized values sort last. Includes unit tests.

Synced from CyberDrain/CIPP@176ff9e
…witcher

Replace Graph D7 usage reports with SharePoint admin RenderAdminListData for
cached and live SharePoint site lists, with shared row builders and normalized
admin storage fields. Add recent-site tracking and a searchable site crumb
switcher in the browser, and update SharePoint Sites alerts for the new source.

Synced from CyberDrain/CIPP@62dd43b
The access-denied page read the signed-in account only from the Static Web Apps /.auth/me shape ({ clientPrincipal: { userDetails } }). On an App Service EasyAuth host /.auth/me returns an array ([{ user_id, user_claims }]), so "Signed in as" never rendered and "Return to Home" was suppressed.

Recognise both shapes, read the identity from user_claims by the same claim priority the backend uses, and fall back to CIPP's own /api/me userDetails.

Synced from CyberDrain/CIPP@1ace129
…end/dev/msw-2.15.0

chore(deps-dev): bump msw from 2.12.14 to 2.15.0 in /frontend

Synced from CyberDrain/CIPP@e32f23a
…end/dev/react-pdf/renderer-4.9.0

chore(deps): bump @react-pdf/renderer from 4.5.1 to 4.9.0 in /frontend

Synced from CyberDrain/CIPP@f29f946
feat(jit): Add JIT role templates and restricted role access

Synced from CyberDrain/CIPP@11a438d
…end/dev/tanstack/query-sync-storage-persister-5.102.8

chore(deps): bump @tanstack/query-sync-storage-persister from 5.101.4 to 5.102.8 in /frontend

Synced from CyberDrain/CIPP@6961657
feat(templates): add Template Package Manager under Tools

Synced from CyberDrain/CIPP@32f9532
chore(js): Migrate JSX to .jsx extensions and bump Vite to 8

Synced from CyberDrain/CIPP@17867b8
feat(intune): add native Microsoft Edge app deployment

Synced from CyberDrain/CIPP@330ba38
- Updated CippChartCard to accept custom colors for chart series.
- Introduced riskChartColor utility to map risk levels to semantic colors.
- Added sortByRiskSeverity function to ensure consistent ordering of risk categories.
- Integrated new color mapping in the Shadow AI page for improved visual representation of risk data.
- Added tests for riskChartColor and sortByRiskSeverity to ensure functionality.

Synced from CyberDrain/CIPP@1aa1dbe
feat(alerts): per-alert HaloPSA ticket priority

Synced from CyberDrain/CIPP@329e7b0
- Introduced new cache type for OneDrive long paths, allowing for per-user counts of paths exceeding Windows sync limits.
- Implemented Push-DBCacheOneDriveLongPaths function to handle path recounting for personal sites.
- Added Get-CIPPAlertOneDriveLongPaths for alerting on accounts with over-long paths.
- Created tests for the new functionality and alerts to ensure reliability.
- Updated frontend alert configurations to include OneDriveLongPaths alerting.

Synced from CyberDrain/CIPP@e9711cf
chore(frontend): regenerate msw worker script for msw 2.15.0

Synced from CyberDrain/CIPP@755b4ab
…tes as Error

Standards that write on every run (checkBeforeRun: false) raised a Remediated alert on
every scheduled cycle even when nothing changed. The alert now fires only on the
transition out of a non-compliant state, matching how Drift alerts already behave.

A remediation write that threw left the row at its graded Drift status, so the alignment
page showed Drift with an empty diff and expected equal to current. The row now persists
as Error, a pending Denied status survives the failure, and the failure log carries the
exception detail so a 403 response body is no longer lost. The alignment page gets an
error colour for that status and offers no Accept/Deny action on it.

Synced from CyberDrain/CIPP@f986260
Standard-backed controls sent the Remediate button to /tenant/standards, which has no
page, so the frontend fallback served the home page. The link now follows the Baselines
flag: the Baselines page when it is on, the classic standards list when it is off, with
the standard name carried in the query.

Synced from CyberDrain/CIPP@f1ef597
Stage panels were keyed on the template id, so a create's save response remounted them
and their forms re-seeded from the pre-save stage state, dropping the actions the
operator had set. The panels are now keyed on an editor generation that only changes
when a different template is loaded.

Synced from CyberDrain/CIPP@26628ef
Resolves seven Dependabot advisories against undici 8.10.0. It is a dev-only transitive
dependency of jsdom, the vitest environment, and never reaches the shipped static export.

Synced from CyberDrain/CIPP@cc758d5
- One sequential orchestration per investigation: a Push-BECRun job per phase, run in order on one worker, each within its own timeout
- Phases hand data forward through the BecRunState table; a failed phase is flagged on the case and the later phases still run
- Containment can run while an investigation is in progress and is recorded on that case
- Users list keeps one bulk-capable BEC Remediation action

Synced from CyberDrain/CIPP@9932a74
…end/dev/eslint-config-next-16.3.6

chore(deps-dev): bump eslint-config-next from 16.3.5 to 16.3.6 in /frontend

Synced from CyberDrain/CIPP@a505f4d
…end/dev/storybook/addon-a11y-10.6.0

chore(deps-dev): bump @storybook/addon-a11y from 10.3.5 to 10.6.0 in /frontend

Synced from CyberDrain/CIPP@929094f
…end/dev/export-to-csv-1.5.0

chore(deps): bump export-to-csv from 1.4.0 to 1.5.0 in /frontend

Synced from CyberDrain/CIPP@bbd215f
…end/dev/storybook/addon-vitest-10.6.0

chore(deps-dev): bump @storybook/addon-vitest from 10.3.5 to 10.6.0 in /frontend

Synced from CyberDrain/CIPP@c668ef2
…end/dev/tanstack/react-query-5.104.0

chore(deps): bump @tanstack/react-query from 5.101.2 to 5.104.0 in /frontend

Synced from CyberDrain/CIPP@a21ba4c
… scanning the reporting cache

- Add Get-CIPPLicenseSkuName: LicenseSkuNames table lookups, falling back to the tenant's LicenseOverview row and backfilling the table
- ExecLicenseSearch uses it and accepts tenantFilter
- License backfill sends the current tenant and requests each SKU once per tenant
- Seed the licence SKU name table from the licence overview cache

Synced from CyberDrain/CIPP@345c50b
…verride caches

- collect ActivityBasedTimeoutPolicy in the Graph group
- write ExoCASMailboxSmtpAuth from the existing CAS mailbox stream
- register both cache types

Synced from CyberDrain/CIPP@60e5ea0
…r text

Intune accepts 30 to 270 days for the device cleanup rule; the classic standard's helper
text said 31 to 365.

fixes #811

Synced from CyberDrain/CIPP@d31bdc4
…ences

A task asking for Push from a user with no registered devices would notify
nobody. Add-CIPPScheduledTask now refuses it with a pointer to Preferences;
every form funnels through there, so offboarding, JIT admin, vacation mode
and add/edit user are covered. System-created tasks carry no principal and
never select Push, so they are unaffected.

Frontend
- usePushDevices reads the same paginated query the Preferences table runs
  under ListPushSubscriptions and exposes a flattened device list and the
  VAPID public key. Sharing that key with a plain ApiGetCall made the two
  fight over one cache entry.
- Scheduler and alert forms only offer "Push (notify me)" once a device is
  registered, with helper text that says where to enrol or how many devices
  will be notified.
- Preferences card: stable dataMap for the device table (an inline function
  re-mapped the rows on every render and made the table flicker) and the
  public key from the shared hook.

Backend
- Log the push service's status when an expired subscription is pruned.

Tests: enrolment guard (refused with no devices, accepted once enrolled,
device table untouched otherwise); hook reads the paginated cache and words
the hint by count. Verified in Chrome via Playwright: enrol, FCM accepts,
service worker displays the notification, impersonation blocks enrolment,
remove clears the row.

Synced from CyberDrain/CIPP@075753d
Bumps next to 16.3.8 for the next/og advisory and brace-expansion and dompurify to their
patched releases; suppresses the plain-text SecureString rule where the VAPID private key
is handed to Key Vault; gives Service Health a docs link target; and updates two tests
that lagged behind the BEC drawer hint text and the non-dismissible legacy notice.

Synced from CyberDrain/CIPP@9d43b99
- File snoozes under the alert function's real name so casing differences in email links still match
- Give the SharePoint and OneDrive quota items a stable Message so usage changes keep the same content hash

Synced from CyberDrain/CIPP@bf62099
feat: add bulk license pricing import/export

Synced from CyberDrain/CIPP@76bddae
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants