Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1149 commits
Select commit Hold shift + click to select a range
4244d03
fix(standards): guard group template against duplicate creation
github-actions[bot] Aug 19, 2026
022e92f
fix(standards): improve spam filter policy resolution
github-actions[bot] Aug 19, 2026
55f970d
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 19, 2026
0f0d388
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 19, 2026
c9002cf
Merge pull request #341 from CyberDrain/chore/license-sku-update-2026…
github-actions[bot] Aug 20, 2026
890b79d
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 20, 2026
18b9b9e
Merge pull request #345 from jonwbstr/HuduIntegration-magicdash-add-l…
github-actions[bot] Aug 20, 2026
11d8024
Merge pull request #344 from jonwbstr/HuduIntegration-switching-magic…
github-actions[bot] Aug 20, 2026
bab87a4
feat(cipp): enhance group management and UI components
github-actions[bot] Aug 20, 2026
7e0cb78
Merge pull request #348 from MWG-Logan/feat/investigate-drift-standard
github-actions[bot] Aug 20, 2026
047c9f0
Merge pull request #318 from kris6673/quarantine-overhaul
github-actions[bot] Aug 20, 2026
24c5321
remove workflow, fix tests
github-actions[bot] Aug 21, 2026
98cd83b
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 21, 2026
2508748
OneDrive sizes
github-actions[bot] Aug 21, 2026
feef535
fiuxes https://github.com/CyberDrain/CIPP/issues/356
github-actions[bot] Aug 21, 2026
cfe70e5
retry logic for webhooks
github-actions[bot] Aug 21, 2026
750e52d
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 22, 2026
52a675f
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 22, 2026
8ad7218
FE fixes baselines
github-actions[bot] Aug 22, 2026
61d4a6b
drift to baselines
github-actions[bot] Aug 22, 2026
682e9ee
secure score updates
github-actions[bot] Aug 23, 2026
597abd4
add group graduational
github-actions[bot] Aug 23, 2026
f49b488
purview fixes
github-actions[bot] Aug 24, 2026
d038b36
fixes teams standard.
github-actions[bot] Aug 24, 2026
47d6ec1
chore: bump version to 10.9.1
github-actions[bot] Aug 24, 2026
c3acc52
fix(auth): self-heal orphaned auto-roles in user sync
github-actions[bot] Aug 24, 2026
a75385d
chore: update DNS health module
github-actions[bot] Aug 24, 2026
826bd08
fix(standards): prevent false compliance failures
github-actions[bot] Aug 24, 2026
b1c2d17
fix(standards): resolve variables in group template names before comp…
github-actions[bot] Aug 24, 2026
ae7a1e3
fix: ignore tenant for user bookmark operations
github-actions[bot] Aug 25, 2026
ccab7b2
Update openapi.json
github-actions[bot] Aug 25, 2026
c356c08
feat(standards): manage BccSuspiciousOutboundMail in outbound spam alert
github-actions[bot] Aug 25, 2026
f6cac93
fix(standards): make mailbox-audit test reflect real config and repai…
github-actions[bot] Aug 25, 2026
a559fd9
feat(standards): add external meeting chat and cloud recording to Tea…
github-actions[bot] Aug 25, 2026
79f6923
fix(tenant): show loading title for ca template
github-actions[bot] Aug 25, 2026
f85fe82
feat(ninjaone): add per-tenant on-demand sync from the mapping table
github-actions[bot] Aug 25, 2026
8df1bb5
fix(graph): disable pagination when $top=1 is requested
github-actions[bot] Aug 25, 2026
11281ea
feat(frontend): link assessment categories to tabs
github-actions[bot] Aug 25, 2026
ffbdb94
feat(auth): log the 429 returned when access-refresh hits its cooldown
github-actions[bot] Aug 25, 2026
eda79f9
feat(api): honour Retry-After on 503 retry delay
github-actions[bot] Aug 26, 2026
de295c5
Update openapi.json
github-actions[bot] Aug 26, 2026
3abae0b
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 26, 2026
e968f32
fixes issue with groups not adding from manage tenant screen
github-actions[bot] Aug 26, 2026
cd0b77e
Merge pull request #394 from Renada-Solutions/fix/scheduled-task-resu…
github-actions[bot] Aug 26, 2026
ab530f7
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 26, 2026
effa1d7
Merge pull request #383 from MWG-Logan/feat/external-compliance-trusted
github-actions[bot] Aug 26, 2026
1f54694
Merge pull request #393 from Renada-Solutions/fix/psa-ticket-referenc…
github-actions[bot] Aug 26, 2026
ade5bcb
fix(scheduler): prevent cross-tenant task execution
github-actions[bot] Aug 27, 2026
9fe4146
fix(auth): authorize group tenantFilter by identity, not membership
github-actions[bot] Aug 27, 2026
23307eb
fix(cippdb): remove $expand from permission grant policies request
github-actions[bot] Aug 27, 2026
79a28a0
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 27, 2026
7ddb7c6
Merge pull request #410 from CyberDrain/fix/issue-396-signinfrequency
github-actions[bot] Aug 28, 2026
e5762f7
fix(mdm): include id in includedGroups $select
github-actions[bot] Aug 28, 2026
65b98cb
fix(settings): advertise mcp oidc scopes
github-actions[bot] Aug 28, 2026
f113961
feat(permissions): auto-refresh PermissionsTranslator from AzAdvertizer
github-actions[bot] Aug 28, 2026
108e9e2
fix(groups): only emit membersCsv/ownersCsv when expanded
github-actions[bot] Aug 28, 2026
fa532b2
feat(onedrive): add reactivate action for archived accounts
github-actions[bot] Aug 28, 2026
ebb1c95
Update openapi.json
github-actions[bot] Aug 28, 2026
ec6de5a
perf(cippdb): select exo fields for mail contacts
github-actions[bot] Aug 28, 2026
8d49454
feat(security): expand defender alerts coverage
github-actions[bot] Aug 28, 2026
11a9911
fix(sharepoint): use app-only auth for ListSharepointSettings
github-actions[bot] Aug 28, 2026
0c426e1
fix(offboarding): skip conflicting tasks when DeleteUser is set
github-actions[bot] Aug 29, 2026
95ffab0
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 29, 2026
618d572
Merge pull request #428 from CyberDrain/feat/mail-flow
github-actions[bot] Aug 30, 2026
96c76ca
feat(sharepoint): deepen site browser recycle/storage UX and add View…
github-actions[bot] Aug 30, 2026
fea5267
Merge pull request #425 from kris6673/feat/enforce-per-user-mfa
github-actions[bot] Aug 30, 2026
add947b
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 30, 2026
64d4910
baseline improvements
github-actions[bot] Aug 30, 2026
e543d3f
standard updates and baseline for mailbox Set the state of the built-…
github-actions[bot] Aug 30, 2026
b69a5e1
fix(dlp): exclude Microsoft built-in SIT rule packages from cache
github-actions[bot] Aug 30, 2026
7ec1afe
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 30, 2026
b977ca7
Adds ability to wipe device
github-actions[bot] Aug 30, 2026
d4cf549
"not configured" as option in standards for auth.
github-actions[bot] Aug 30, 2026
77bfeda
datetime casting.
github-actions[bot] Aug 30, 2026
2b992a4
add minimum days too
github-actions[bot] Aug 30, 2026
78e886b
add automapping
github-actions[bot] Aug 30, 2026
6b45038
device link in ninjaone
github-actions[bot] Aug 30, 2026
00c64d5
fix(cippdb): gate MDO cache collectors by license and soften expected…
github-actions[bot] Aug 31, 2026
8b3fcdc
fix: quarantine release request alert firing and standard compliance
github-actions[bot] Aug 31, 2026
d64551a
fix(defender): shrink DefenderCVEs cache rows to stop nightly OOM/tim…
github-actions[bot] Aug 31, 2026
34e6332
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 31, 2026
d5c1e4c
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 31, 2026
60fa55c
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 31, 2026
47c8d0f
Merge pull request #429 from CyberDrain/feat/certificate-auth-exclusive
github-actions[bot] Aug 31, 2026
2cec75f
feat(intune): add min/max OS version to classic device enrollment res…
github-actions[bot] Aug 31, 2026
e945974
fix(purview): show correct retention policy scope, rule count, and Te…
github-actions[bot] Aug 31, 2026
d72b0d2
Merge pull request #434 from CyberDrain/preview/PIM-management
github-actions[bot] Aug 31, 2026
679233d
Merge pull request #437 from sfaxluke/feature/configurable-apn-dep-vp…
github-actions[bot] Aug 31, 2026
65a923b
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Aug 31, 2026
3155715
disabled flag
github-actions[bot] Aug 31, 2026
bc0db5d
Merge pull request #448 from CyberDrain/feat/mfa-push-and-otp-verify
github-actions[bot] Aug 31, 2026
90d732b
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 1, 2026
2404933
feat(sharepoint): use SPO admin RLD for site usage and site browser s…
github-actions[bot] Sep 1, 2026
75418ea
fix(identity): handle duplicate group templates in CA policy deploy
github-actions[bot] Sep 1, 2026
a6c871e
Update openapi.json
github-actions[bot] Sep 1, 2026
62b81b3
fix(auth): surface signed-in identity on denial page across auth hosts
github-actions[bot] Sep 1, 2026
4b9fda0
Merge pull request #456 from kris6673/fix/Country-in-bad-rep-alert
github-actions[bot] Sep 1, 2026
3aed4be
Merge pull request #101 from TecharyJames/jit-role-permissions
github-actions[bot] Sep 1, 2026
f47e080
Update openapi.json
github-actions[bot] Sep 1, 2026
b302abe
Merge pull request #461 from joaadvi/feat/edge-app-deployment
github-actions[bot] Sep 1, 2026
aa77876
fix(reporting): project split markers so orphan cleanup reassembles s…
github-actions[bot] Sep 1, 2026
36d2cb0
refactor(sharepoint): centralize SharePoint REST context resolution
github-actions[bot] Sep 1, 2026
3db02db
Merge pull request #193 from Renada-Solutions/feat/psa-ticket-priority
github-actions[bot] Sep 1, 2026
da35ebf
feat: add minimal mode to listmailboxes for improved perf
github-actions[bot] Sep 1, 2026
577feea
feat: add OneDriveLongPaths functionality and alerting
github-actions[bot] Sep 2, 2026
4d19b2d
Merge pull request #472 from k-grube/fix/api-client-empty-ip-range
github-actions[bot] Sep 2, 2026
83685d9
Merge pull request #467 from kris6673/fix/calendar-permission-folder-…
github-actions[bot] Sep 2, 2026
3b57ca1
test(standards): expect the missing-template wording for CA report rows
github-actions[bot] Sep 2, 2026
3d9bf1c
Merge pull request #464 from CyberDrain/preview/server-side-paging
github-actions[bot] Sep 2, 2026
381f3cf
fix(drift): stop pruning accepted policy rows when a Graph continuati…
github-actions[bot] Sep 2, 2026
3d48715
fix(standards): judge guest inactivity on newest sign-in attempt
github-actions[bot] Sep 2, 2026
7d03255
feat(frontend): dismiss all bulk action results from the summary alert
github-actions[bot] Sep 2, 2026
c90cf4e
Merge pull request #476 from CyberDrain/feat/gdap-role-templates
github-actions[bot] Sep 3, 2026
43c739c
chore(openapi): regenerate ExecBackendURLs description for the App Se…
github-actions[bot] Sep 3, 2026
13070a9
fix(ui): improve mobile responsiveness and Intune policy naming
github-actions[bot] Sep 3, 2026
d2d3e32
Update yarn.lock
github-actions[bot] Sep 3, 2026
425e938
Update openapi.json
github-actions[bot] Sep 3, 2026
7590f8c
perf(build): make the dev watcher's openapi.json regeneration fast
github-actions[bot] Sep 3, 2026
917ab0a
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 3, 2026
00855a6
feat(identity): move user templates under users
github-actions[bot] Sep 3, 2026
a7f7650
Replace Update-AzDataTableEntity with Add-AzDataTableEntity
Zacgoose Sep 3, 2026
9add86b
Update openapi.json
github-actions[bot] Sep 3, 2026
d8e1fda
refactor(standards): make SPOSites a generic per-site cache
github-actions[bot] Sep 3, 2026
f93806a
fix(cippdb-cache): run the producing collector for derived cache types
github-actions[bot] Sep 3, 2026
caa1615
Enhance logging and error handling across multiple scripts
github-actions[bot] Sep 3, 2026
3c66a96
perf(standards): apply the People Picker site sweep concurrently
github-actions[bot] Sep 3, 2026
2dd1e93
fix(http): escape $Var: interpolation that broke module parse
github-actions[bot] Sep 3, 2026
f538df8
Update openapi.json
github-actions[bot] Sep 3, 2026
b3ff8a0
fix(sharepoint): use certificate auth for version-control and quota s…
github-actions[bot] Sep 3, 2026
53d9c94
refactor(standards): read live and verify-after for the People Picker…
github-actions[bot] Sep 3, 2026
d794928
fix(email): correct message trace window and error display
github-actions[bot] Sep 3, 2026
71f6287
feat(cippdb-cache): enrich SPOSites with authoritative per-site field…
github-actions[bot] Sep 3, 2026
715c163
fix(exchange): find older messages in message trace
github-actions[bot] Sep 3, 2026
1c6c761
fix(gdap): recreate missing groups during role repair
github-actions[bot] Sep 3, 2026
f5925e2
fix(backend): create DevSecrets row when missing in SAM cert setup
github-actions[bot] Sep 3, 2026
51bd139
feat(patch-wizard): enhance user addition functionality in UsersDispl…
github-actions[bot] Sep 3, 2026
87c6b26
fix(mfa): correct perUserMfaState property casing
github-actions[bot] Sep 3, 2026
e7dbe2f
test: remove Set-CIPPPerUserMFA pester tests
github-actions[bot] Sep 3, 2026
79f2a16
Update openapi.json
github-actions[bot] Sep 4, 2026
4c0dccd
chore: test fixes
github-actions[bot] Sep 4, 2026
8b406cc
fix(docs): reconcile published-pages snapshot with live docs URLs
github-actions[bot] Sep 4, 2026
734a31f
fix(docs): align GDAP group-mapping page path with its published URL
github-actions[bot] Sep 4, 2026
701893c
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 4, 2026
fcb2d67
feat(api): add Storage Cleanup Scan endpoint and update related confi…
github-actions[bot] Sep 4, 2026
4af1742
test(tenants): pin the Get-Tenants refresh-loop rules
github-actions[bot] Sep 4, 2026
d1110ee
Update openapi.json
github-actions[bot] Sep 4, 2026
3867bb8
fix(scheduler): match scheduled tasks on any tenant identifier
github-actions[bot] Sep 4, 2026
e27e231
Update FeatureFlags.json
github-actions[bot] Sep 4, 2026
6ed38d2
feat(groups): add 'Set Group Visibility' functionality to group manag…
github-actions[bot] Sep 4, 2026
d5c0d8a
feat(reports): render the Mail Flow report server-side
github-actions[bot] Sep 6, 2026
bd82536
Merge pull request #496 from ZenTopBrandon/fix/mx-record-alert-baseline
github-actions[bot] Sep 6, 2026
9b75b41
Merge pull request #495 from sfaxluke/feature/groups-missing-owner-co…
github-actions[bot] Sep 6, 2026
d84b13a
Merge pull request #493 from John-2811/fix/mailbox-cache-null-externa…
github-actions[bot] Sep 6, 2026
afe2970
Merge pull request #475 from kris6673/fix/scripted-alert-tenant-group…
github-actions[bot] Sep 6, 2026
b6b33a1
fix(sharepoint): pre-provision OneDrive app-only with SAM certificate
github-actions[bot] Sep 7, 2026
ba68e80
fix(groups): derive hasowner from computed ownerscsv
github-actions[bot] Sep 7, 2026
46d8dd9
chore: update SKU profile memory mapping
github-actions[bot] Sep 7, 2026
a6bd11f
Update openapi.json
github-actions[bot] Sep 7, 2026
2d06595
Update openapi.json
github-actions[bot] Sep 7, 2026
7dc7efb
feat(integrations): warn when an MCP client's role restricts IPs
github-actions[bot] Sep 7, 2026
4fad6be
feat: expose exsting tenant library syncing jobs in the config page
github-actions[bot] Sep 7, 2026
d95ddba
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 7, 2026
ee066f7
version up
github-actions[bot] Sep 7, 2026
46d39ed
ci: consolidate CodeQL into one workflow with a scoped config
github-actions[bot] Sep 7, 2026
2670010
fix(standards): avoid run name collisions
github-actions[bot] Sep 7, 2026
11663a5
feat(offboarding): run offboarding steps sequentially on one worker
github-actions[bot] Sep 8, 2026
b7b016a
refactor(http): use return response in endpoints
github-actions[bot] Sep 8, 2026
b0fa998
feat(oneDrive): add destination parameter for shortcut creation
github-actions[bot] Sep 8, 2026
8caa635
fix(standards): recognise EDU SharePoint plans in license check
github-actions[bot] Sep 8, 2026
a0f8525
feat(oneDrive): add API endpoints and frontend actions for migrating …
github-actions[bot] Sep 8, 2026
bc7f02a
fix(standards): update documentation for OneDrive shortcut migration
github-actions[bot] Sep 8, 2026
c9a72d0
fix(standards): scope standards template tenant assignments to caller…
github-actions[bot] Sep 8, 2026
455b50b
fix(mfa-connector): handle 404 on missing key vault secret
github-actions[bot] Sep 8, 2026
53e3954
chore: bump version to 10.10.1
github-actions[bot] Sep 8, 2026
8c37f31
chore(halo): add custom user-agent to HaloPSA API calls
github-actions[bot] Sep 8, 2026
5eb8d91
test(halo): add Get-CippUserAgent mock in ticket tests
github-actions[bot] Sep 8, 2026
7f1594f
fix(sharepoint): keep the permissions report alive across flaky large…
github-actions[bot] Sep 9, 2026
98d7d99
fix(domain): skip exchange gate for manual runs
github-actions[bot] Sep 9, 2026
3de996d
fix(scheduler): size-cap scheduled task result logging
github-actions[bot] Sep 9, 2026
712974a
feat(guests): enhance guest account standard with soft-delete option
github-actions[bot] Sep 9, 2026
228d3f3
fix(halo): unwrap ticket type array before returning
github-actions[bot] Sep 9, 2026
edfff6a
feat(policies): add identity coverage view and enhance policy actions
github-actions[bot] Sep 10, 2026
2f6b51a
fix(backend): correct diagnostics and report values
github-actions[bot] Sep 10, 2026
3b0c808
Update openapi.json
github-actions[bot] Sep 10, 2026
d74997b
feat(diagnostics): add instance health sampling and self diagnostics
github-actions[bot] Sep 10, 2026
11e1c45
fix(intune): name the missing settings when an Apple enrollment templ…
github-actions[bot] Sep 10, 2026
4e2b28f
Update openapi.json
github-actions[bot] Sep 10, 2026
1c29092
refactor(auth): extract helpers from Test-CIPPAccess
github-actions[bot] Sep 10, 2026
6509966
feat(intune): bind Apple enrollment (ADE) templates to the tenant tok…
github-actions[bot] Sep 11, 2026
bd7e4f1
chore(intune): refresh settings catalog and definitions
github-actions[bot] Sep 11, 2026
2f72e43
fix(tests): read FileTypeAction in CISA MS.EXO.10.2 malware test
github-actions[bot] Sep 11, 2026
6772f87
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 11, 2026
0dad259
chore(config): update self-service license management and documentation
github-actions[bot] Sep 11, 2026
ec01e50
feat(auth): add offline_access to CIPP-SSO app permissions
github-actions[bot] Sep 11, 2026
65e513a
Merge pull request #575 from CyberDrain/chore/permissions-translator-…
github-actions[bot] Sep 11, 2026
2552d69
deprecate(reports): mark Invoke-ListSignIns as deprecated
github-actions[bot] Sep 11, 2026
52d4f75
Update openapi.json
github-actions[bot] Sep 11, 2026
7a4cd7e
feat(diagnostics): track and surface API egress usage
github-actions[bot] Sep 11, 2026
70f4fcf
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 11, 2026
2b0c5fe
chore(openapi): add egress tracking fields to schema
github-actions[bot] Sep 11, 2026
5e15049
fix(mcp): self-heal offline_access in the MCP OAuth scope advertiseme…
github-actions[bot] Sep 12, 2026
263615a
fix(cippdb): include deviceId in Azure AD Devices cache projection
github-actions[bot] Sep 14, 2026
2c0a5ba
fix(standards): skip unsupported dynamic distribution groups in group…
github-actions[bot] Sep 14, 2026
b742be8
Merge pull request #591 from CyberDrain/chore/permissions-translator-…
github-actions[bot] Sep 14, 2026
69d9a97
refactor(diagnostics): replace egress ledger with accounting table
github-actions[bot] Sep 14, 2026
2c7ef0f
chore: bump version to 10.10.3
github-actions[bot] Sep 14, 2026
d16ea38
chore: remove egress fields from openapi schema
github-actions[bot] Sep 14, 2026
27732f0
test(add-user): validate single-tenant filter resolution
github-actions[bot] Sep 14, 2026
0624292
refactor(graph): remove GraphErrorCount tenant tracking
github-actions[bot] Sep 14, 2026
8aa9d55
Merge pull request #617 from CyberDrain/chore/openapi-spec-update-202…
github-actions[bot] Sep 15, 2026
1f64951
fix(standards): ignore empty template standards in drift and on save
github-actions[bot] Sep 16, 2026
33bfc06
Merge pull request #628 from kris6673/feat/message-encryption-options
github-actions[bot] Sep 16, 2026
21a4375
Merge pull request #598 from generalct83/feat/sp-anonymous-link-expir…
github-actions[bot] Sep 16, 2026
a75b205
Merge pull request #609 from kris6673/feat/deploy-drawer-group-picker
github-actions[bot] Sep 16, 2026
5c6780b
Merge pull request #519 from malvinportner/fix/conditional-access-sta…
github-actions[bot] Sep 16, 2026
93d14f8
Merge pull request #561 from dlepi24/fix/expiring-licenses-snooze-id
github-actions[bot] Sep 16, 2026
3533954
Merge pull request #576 from Flagstream-Technologies-Inc/fix/registra…
github-actions[bot] Sep 16, 2026
370e7a2
Merge pull request #585 from kris6673/feat/sharepoint-group-connected…
github-actions[bot] Sep 16, 2026
847a40f
Merge pull request #587 from TuEye/fix/safelinks-atatchments-domain-d…
github-actions[bot] Sep 16, 2026
aac9ead
Merge pull request #579 from sfaxluke/claude/jit-vacation-mode-2f61a8
github-actions[bot] Sep 16, 2026
7c18918
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 16, 2026
1f316ad
Fix countrylist is couple of components.
github-actions[bot] Sep 16, 2026
20560c3
made buttons blue because dark/lightmode
github-actions[bot] Sep 16, 2026
9f002fc
add tap option as pwpush
github-actions[bot] Sep 16, 2026
6df723c
Add 90 days to manage alert options.
github-actions[bot] Sep 16, 2026
5932ff8
Update openapi.json
github-actions[bot] Sep 16, 2026
ffdb62f
feat(dbcache): cache tenant sharepoint usage
github-actions[bot] Sep 16, 2026
3c09b27
fix(sharepoint): add cached quota mode
github-actions[bot] Sep 16, 2026
b5ee41b
Merge pull request #637 from kris6673/feat/teams-voice-backup
github-actions[bot] Sep 16, 2026
953e05a
Merge pull request #634 from kris6673/feat/clear-onprem-attributes
github-actions[bot] Sep 16, 2026
9642b80
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 16, 2026
d040783
refactor(planner): update help and documentation text for task deleti…
github-actions[bot] Sep 16, 2026
89ba1cd
chore: add licence check to CIS_2_1_4
github-actions[bot] Sep 17, 2026
176b7a3
chore: add licence check to CIS_2_1_1
github-actions[bot] Sep 17, 2026
3e12b94
chore: add licence check to CIS_2_1_5
github-actions[bot] Sep 17, 2026
10403f6
chore: update list tests to contain 'Unlicensed' results
github-actions[bot] Sep 17, 2026
8e07588
fix(domainanalyser): overwrite DKIM Selectors instead of Add() to sto…
github-actions[bot] Sep 17, 2026
17b8995
fix(intune): give an actionable error when a template's stored null i…
github-actions[bot] Sep 17, 2026
80b6521
fix(standards): list shared mailboxes via Get-Mailbox cmdlet instead …
github-actions[bot] Sep 17, 2026
67c5957
fix(standards): resolve variables in Intune template names before com…
github-actions[bot] Sep 17, 2026
84dcb92
Merge pull request #639 from kris6673/fix/force-refresh-tenant-result
github-actions[bot] Sep 17, 2026
a0fd399
fixes hudu sync typo and tenant issue
github-actions[bot] Sep 17, 2026
f7c6c19
Merge branch 'dev' of https://github.com/CyberDrain/CIPP into dev
github-actions[bot] Sep 17, 2026
7561a35
hudu fix mailboxes
github-actions[bot] Sep 17, 2026
748515b
Update openapi.json
github-actions[bot] Sep 18, 2026
6004342
docs(api): regenerate openapi spec for Tier A MCP payload params
github-actions[bot] Sep 18, 2026
d130d6c
docs updates
github-actions[bot] Sep 18, 2026
31773ce
Merge pull request #653 from matstocks/fix/650-sam-permission-grants
github-actions[bot] Sep 18, 2026
98b00cf
Merge pull request #620 from John-2811/fix/gdap-cleanold-false-critical
github-actions[bot] Sep 18, 2026
039eeaa
Merge pull request #640 from Aaronkatz0/fix/edit-tenant-clear-static-…
github-actions[bot] Sep 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
349 changes: 349 additions & 0 deletions .build/Add-OpenApiResponseSchemas.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,349 @@
#Requires -Version 7.0
<#
.SYNOPSIS
Enriches a CIPP openapi.json with typed 200 response schemas derived by static
analysis of the API and frontend repositories.

.DESCRIPTION
The generated CIPP spec types every request body but leaves every 200 response
as the generic StandardResults envelope. This stage fills typed per-endpoint
response schemas for the read surface, using two deterministic sources that are
already checked into the repositories (no live API calls):

1. Captured response shape baselines (CIPP/Tests/Shapes/*.json) - carry real
field types and nesting. Preferred when present.
2. Frontend table column declarations (simpleColumns in CIPP/src pages) -
carry field names only. Used when no baseline exists; fields are typed as
string and marked x-cipp-field-source: frontend so consumers know the type
is a name-only inference, not a verified type.

Endpoints with neither source keep the StandardResults envelope, which is the
correct shape for write/exec operations. Output is deterministic: the same input
repositories always produce a byte-identical spec.

.PARAMETER InputSpec
Path to the source openapi.json. Defaults to the repo-root spec relative to this
script (.build/.. ).

.PARAMETER OutputSpec
Path to write the enriched spec. Defaults to InputSpec (in-place rewrite).

.PARAMETER FrontendRepoPath
Path to a checkout of the CIPP frontend repository. Provides both the shape
baselines (Tests/Shapes) and the page column declarations (src).

.PARAMETER PassThru
Return the enriched spec object instead of only writing it. Used by tests.

.EXAMPLE
./Add-OpenApiResponseSchemas.ps1 -FrontendRepoPath ../CIPP

Rewrites the repo-root openapi.json in place with typed response schemas.
#>
[CmdletBinding()]
param(
[string]$InputSpec = (Join-Path $PSScriptRoot '..' 'openapi.json'),
[string]$OutputSpec,
[string]$FrontendRepoPath,
[switch]$PassThru
)

$ErrorActionPreference = 'Stop'

$script:CippHttpMethods = @('get', 'post', 'put', 'patch', 'delete')

function ConvertFrom-ShapeNode {
<#
.SYNOPSIS
Converts one node of a captured shape tree into an OpenAPI schema fragment.
#>
param($Node)

if ($Node -is [string]) {
switch ($Node) {
'string' { return @{ type = 'string' } }
'number' { return @{ type = 'number' } }
'bool' { return @{ type = 'boolean' } }
'datetime' { return [ordered]@{ type = 'string'; format = 'date-time' } }
# 'null' (captured as null at sample time) and 'truncated' (below the
# capture depth limit) carry no reliable type, so stay permissive.
default { return @{} }
}
}

if ($Node -is [System.Collections.IDictionary]) {
if ($Node['_type'] -eq 'array') {
return [ordered]@{ type = 'array'; items = (ConvertFrom-ShapeNode -Node $Node['_element']) }
}
$properties = [ordered]@{}
foreach ($key in ($Node.Keys | Sort-Object)) {
$properties[[string]$key] = ConvertFrom-ShapeNode -Node $Node[$key]
}
return [ordered]@{ type = 'object'; properties = $properties }
}

return @{}
}

function Get-ShapeBaselineMap {
<#
.SYNOPSIS
Maps endpoint name -> per-record OpenAPI schema, from captured shape baselines.
.DESCRIPTION
Reads only files carrying both _metadata and shape; the sibling
test-results.json and any non-baseline file is skipped. The per-record schema
is the baseline shape itself (the CIPP envelope's Results[] element).
#>
param([string]$ShapesDir)

$map = @{}
if (-not (Test-Path $ShapesDir)) {
Write-Warning "Shapes directory not found: $ShapesDir"
return $map
}

foreach ($file in (Get-ChildItem -Path $ShapesDir -Filter '*.json' | Sort-Object -Property FullName)) {
$doc = Get-Content -LiteralPath $file.FullName -Raw | ConvertFrom-Json -AsHashtable -Depth 100
if (-not ($doc -is [System.Collections.IDictionary] -and $doc.ContainsKey('_metadata') -and $doc.ContainsKey('shape'))) {
continue
}
$endpoint = $doc['_metadata']['endpoint']
if (-not $endpoint) { continue }
$map[$endpoint] = ConvertFrom-ShapeNode -Node $doc['shape']
}
return $map
}

function Get-FrontendColumnMap {
<#
.SYNOPSIS
Maps endpoint name -> sorted unique field names, from page simpleColumns.
.DESCRIPTION
Intent: skips conditional simpleColumns arrays to avoid non-column branch strings; false negatives beat junk fields.
Scans frontend page sources for files that pair an /api/<Endpoint> reference
with a simpleColumns array, and unions the declared column names per endpoint.
Field names are deterministic; their types are not, so callers type them as
string with a provenance marker.
#>
param([string]$SrcDir)

$map = @{}
if (-not (Test-Path $SrcDir)) {
Write-Warning "Frontend src directory not found: $SrcDir"
return $map
}

$endpointPattern = [regex]'/api/([A-Za-z0-9_]+)'
$columnsPattern = [regex]'(?s)\bsimpleColumns\s*(?:=|:)\s*(?:\{\s*)?\[(?<columns>[^\]]*)\]'
$stringPattern = [regex]'"([^"]+)"|''([^'']+)'''

$files = Get-ChildItem -Path $SrcDir -Recurse -File -Include '*.js', '*.jsx'
foreach ($file in $files) {
$text = Get-Content -LiteralPath $file.FullName -Raw
if ([string]::IsNullOrEmpty($text) -or $text -notmatch 'simpleColumns') { continue }

$endpoints = $endpointPattern.Matches($text) | ForEach-Object { $_.Groups[1].Value } | Sort-Object -Unique
if (-not $endpoints) { continue }

$columns = foreach ($colMatch in $columnsPattern.Matches($text)) {
foreach ($strMatch in $stringPattern.Matches($colMatch.Groups['columns'].Value)) {
$value = if ($strMatch.Groups[1].Success) { $strMatch.Groups[1].Value } else { $strMatch.Groups[2].Value }
if ($value) { $value }
}
}
if (-not $columns) { continue }

foreach ($endpoint in $endpoints) {
if (-not $map.ContainsKey($endpoint)) { $map[$endpoint] = [System.Collections.Generic.HashSet[string]]::new() }
foreach ($column in $columns) { [void]$map[$endpoint].Add($column) }
}
}
return $map
}

function ConvertTo-ColumnRecordSchema {
<#
.SYNOPSIS
Builds a per-record object schema from a set of frontend column names.
#>
param([System.Collections.Generic.HashSet[string]]$Columns)

$properties = [ordered]@{}
foreach ($column in ($Columns | Sort-Object)) {
$properties[$column] = [ordered]@{ type = 'string'; 'x-cipp-field-source' = 'frontend' }
}
return [ordered]@{ type = 'object'; properties = $properties }
}

function ConvertTo-ResponseEnvelopeSchema {
<#
.SYNOPSIS
Wraps a per-record schema in the CIPP { Results: [...], Metadata: {...} } envelope.
#>
param($RecordSchema)

return [ordered]@{
type = 'object'
properties = [ordered]@{
Results = [ordered]@{ type = 'array'; items = $RecordSchema }
Metadata = [ordered]@{ type = 'object' }
}
}
}


function Get-CippOperationId {
<#
.SYNOPSIS
Builds the deterministic operationId for one CIPP path and method.
.DESCRIPTION
Riftwing imports OpenAPI operations by operationId. CIPP upstream does not
currently emit operationIds, so this keeps importer keys stable without
depending on display labels or external data.
#>
param(
[Parameter(Mandatory)][string]$Path,
[Parameter(Mandatory)][string]$Method,
[Parameter(Mandatory)][string[]]$PathMethods
)

$endpointName = $Path -replace '^/api/', ''
if ($PathMethods.Count -eq 1) {
return $endpointName
}

$methodName = [System.Globalization.CultureInfo]::InvariantCulture.TextInfo.ToTitleCase($Method.ToLowerInvariant())
return "$methodName$endpointName"
}

function Add-CippOperationId {
<#
.SYNOPSIS
Injects missing operationIds and fails on duplicate operationIds.
.DESCRIPTION
Existing non-empty operationIds are preserved so this pass can retire itself
when upstream starts emitting operationIds. Duplicate operationIds are fatal
because importers commonly key operations by operationId.
#>
param([Parameter(Mandatory)][System.Collections.IDictionary]$Spec)

if (-not $Spec['paths']) { throw 'Spec has no paths.' }

$operationCount = 0
$injectedCount = 0
$operationIds = @{}

foreach ($pathEntry in $Spec['paths'].GetEnumerator()) {
$pathMethods = @($pathEntry.Value.Keys | Where-Object { $_ -in $script:CippHttpMethods })
foreach ($methodEntry in $pathEntry.Value.GetEnumerator()) {
if ($methodEntry.Key -notin $script:CippHttpMethods) { continue }

$operationCount++
$operation = $methodEntry.Value
$operationId = $operation['operationId']
if ([string]::IsNullOrWhiteSpace([string]$operationId)) {
$operationId = Get-CippOperationId -Path $pathEntry.Key -Method $methodEntry.Key -PathMethods $pathMethods
$operation['operationId'] = $operationId
$injectedCount++
}

if ($operationIds.ContainsKey($operationId)) {
throw "Duplicate operationId found: $operationId"
}
$operationIds[$operationId] = $true
}
}

return [pscustomobject]@{ Operations = $operationCount; Injected = $injectedCount; Unique = $operationIds.Count }
}

function Resolve-SpecResponse {
<#
.SYNOPSIS
Adds typed 200 response schemas to a parsed spec, in place, and returns counts.
.DESCRIPTION
The pure core of this stage: operates on an already-parsed spec hashtable and
the two endpoint maps, with no file or repository access, so it is unit
testable. Only existing 200 responses on get/post/put/patch/delete operations
are touched; everything else (including operations with no matching source) is
left exactly as found.
#>
param(
[Parameter(Mandatory)][System.Collections.IDictionary]$Spec,
[Parameter(Mandatory)][hashtable]$BaselineMap,
[Parameter(Mandatory)][hashtable]$ColumnMap
)

if (-not $Spec['paths']) { throw 'Spec has no paths.' }

$operationCount = 0
$typedCount = 0

foreach ($pathEntry in $Spec['paths'].GetEnumerator()) {
$endpoint = $pathEntry.Key -replace '^/api/', ''

$recordSchema = $null
if ($BaselineMap.ContainsKey($endpoint)) {
$recordSchema = $BaselineMap[$endpoint]
} elseif ($ColumnMap.ContainsKey($endpoint)) {
$recordSchema = ConvertTo-ColumnRecordSchema -Columns $ColumnMap[$endpoint]
}

foreach ($methodEntry in $pathEntry.Value.GetEnumerator()) {
if ($methodEntry.Key -notin $script:CippHttpMethods) { continue }
$operationCount++
if ($null -eq $recordSchema) { continue }

$responses = $methodEntry.Value['responses']
if ($null -eq $responses) { continue }

$okResponse = $responses['200']
if (-not $okResponse) { continue }

$okResponse['content'] = [ordered]@{
'application/json' = [ordered]@{ schema = (ConvertTo-ResponseEnvelopeSchema -RecordSchema $recordSchema) }
}
$typedCount++
}
}

return [pscustomobject]@{
Operations = $operationCount
Typed = $typedCount
}
}

function Add-CippResponseSchema {
<#
.SYNOPSIS
File-level orchestration: read spec + repo sources, enrich, write output.
#>
param(
[Parameter(Mandatory)][string]$InputSpec,
[Parameter(Mandatory)][string]$OutputSpec,
[Parameter(Mandatory)][string]$FrontendRepoPath,
[switch]$PassThru
)

if (-not (Test-Path $InputSpec)) { throw "Input spec not found: $InputSpec" }

$spec = Get-Content -LiteralPath $InputSpec -Raw | ConvertFrom-Json -AsHashtable -Depth 100
$baselineMap = Get-ShapeBaselineMap -ShapesDir (Join-Path $FrontendRepoPath 'Tests' 'Shapes')
$columnMap = Get-FrontendColumnMap -SrcDir (Join-Path $FrontendRepoPath 'src')

$operationIdResult = Add-CippOperationId -Spec $spec
$result = Resolve-SpecResponse -Spec $spec -BaselineMap $baselineMap -ColumnMap $columnMap
Write-Information "Operations: $($result.Operations) | typed responses added: $($result.Typed) | operationIds injected: $($operationIdResult.Injected) | unique operationIds: $($operationIdResult.Unique)" -InformationAction Continue

# Serialization is deterministic for the object this stage builds, but it does not globally canonicalize pre-existing spec keys.
[System.IO.File]::WriteAllText($OutputSpec, ($spec | ConvertTo-Json -Depth 100))

if ($PassThru) { return $spec }
}

# Run orchestration only when invoked as a script, not when dot-sourced for testing.
if ($MyInvocation.InvocationName -ne '.') {
if (-not $FrontendRepoPath) { throw 'FrontendRepoPath is required when running the script.' }
if (-not $OutputSpec) { $OutputSpec = $InputSpec }
Add-CippResponseSchema -InputSpec $InputSpec -OutputSpec $OutputSpec -FrontendRepoPath $FrontendRepoPath -PassThru:$PassThru
}
38 changes: 38 additions & 0 deletions .build/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# OpenAPI enrichment

`Add-OpenApiResponseSchemas.ps1` post-processes the generated CIPP `openapi.json`. It adds deterministic operationIds and typed `200` response schemas where response shape data can be derived from the CIPP frontend repository. It does not replace the upstream OpenAPI generator.

The enriched spec is published on each GitHub Release as the `openapi.enriched.json` release asset.

The PR check and release workflow strictly lint the CI-generated `openapi.enriched.json` with Redocly. The committed `.redocly.lint-ignore.yaml` baseline pins findings that already exist in the generated enriched spec because of upstream `openapi.json` issues. Any new Redocly error or warning that is not in the baseline fails CI.

To regenerate locally, check out the CIPP frontend repository and run:

```powershell
pwsh -NoProfile -File .build/Add-OpenApiResponseSchemas.ps1 `
-FrontendRepoPath <path-to-CIPP-frontend-checkout> `
-InputSpec ./openapi.json -OutputSpec ./openapi.enriched.json
```

If upstream `openapi.json` legitimately changes and the pinned Redocly findings must be refreshed, regenerate the enriched spec first, then regenerate the ignore baseline from that enriched output:

```powershell
pwsh -NoProfile -File .build/Add-OpenApiResponseSchemas.ps1 `
-FrontendRepoPath <path-to-CIPP-frontend-checkout> `
-InputSpec ./openapi.json -OutputSpec ./openapi.enriched.json
npx --yes @redocly/cli@2.35.1 lint ./openapi.enriched.json --generate-ignore-file
```

Do not generate the baseline from the base `openapi.json`. The lint subject is always the generated `openapi.enriched.json`.

## Known limitations

- Only `get`, `post`, `put`, `patch`, and `delete` operations are processed. `head`, `options`, and `trace` are not present in the current spec.
- Paths are assumed to start with `/api/`. All 580 current paths do.
- When a typed `200` response is added, it replaces the existing `200.content`. Today that content is only the generic `StandardResults` envelope.
- Conditional/ternary `simpleColumns` expressions are intentionally not parsed.

## Release workflow notes

- `openapi-enriched-release.yml` builds and uploads from the same tag. On `workflow_dispatch`, the `tag` input is checked out and used as the upload target. On `release: published`, the release tag is checked out and used as the upload target.
- `.github/workflows/` is gitignored in this repository, so the OpenAPI workflow files require `git add -f` when they are intentionally added or updated.
Loading
Loading