v0.1.30 — Policy-Bulk-Import gehaertet, macOS-Apps, Gruppen-Suche & Direkt-Zuweisung
Build & Release MSI / build-msi (push) Canceled after 0s

- Bulk-Import von Policies (Batches + Fortschritt, Fehler-Isolierung)
- Export/Import-Treue via Raw-JSON (-OutputType Json), null-Collections-Strip,
  Settings-Catalog-Reparatur + Korruptions-Erkennung, Git-Resolver
- macOS-Apps in Liste/Suche + Plattform-Filter
- "Gruppe"-Tab durchsucht alle Gruppen (Live-Suche) statt nur Praefix-Gruppen
- Bestehende Gruppe(n) direkt an Apps zuweisen inkl. Mehrfachauswahl
- Fix: Add-GraphAppAssignment merged bestehende Zuweisungen (/assign ersetzt sonst
  die komplette Liste) -> kein Ueberschreiben mehr, ein Request fuer alle Ziele

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-09-03 09:03:22 +02:00
co-authored by Claude Opus 4.8
parent 5c60eacc12
commit 446c53f409
9 changed files with 642 additions and 100 deletions
+50 -36
View File
@@ -2805,23 +2805,29 @@ function Add-AppAssignmentEndpoint {
if ($intent -notin @("required","available")) {
return @{ __status = 400; error = "intent muss 'required' oder 'available' sein" }
}
$target = [string]$Body.target
if ([string]::IsNullOrWhiteSpace($target)) {
return @{ __status = 400; error = "target fehlt (ALL_USERS / ALL_DEVICES / <group-guid>)" }
# Ein ODER mehrere Ziele akzeptieren: 'targets' (Array) hat Vorrang, sonst 'target'.
$targets = @()
if ($Body.targets) { $targets = @($Body.targets | ForEach-Object { [string]$_ }) }
elseif ($Body.target) { $targets = @([string]$Body.target) }
$targets = @($targets | Where-Object { $_ -and $_.Trim() })
if ($targets.Count -eq 0) {
return @{ __status = 400; error = "target/targets fehlt (ALL_USERS / ALL_DEVICES / <group-guid>)" }
}
# Bei Group-Target: zumindest grobe Hex/GUID-Form pruefen damit wir keine
# Garbage an Graph schicken.
if ($target -notin @("ALL_USERS","ALL_DEVICES") -and $target -notmatch '^[0-9a-fA-F-]{8,}$') {
return @{ __status = 400; error = "Ungueltige target-GUID: $target" }
# Jedes Group-Target grob auf Hex/GUID-Form pruefen (keine Garbage an Graph).
foreach ($t in $targets) {
if ($t -notin @("ALL_USERS","ALL_DEVICES") -and $t -notmatch '^[0-9a-fA-F-]{8,}$') {
return @{ __status = 400; error = "Ungueltige target-GUID: $t" }
}
}
# App-Cache fuer logging
$cachedApp = $script:State.Apps | Where-Object { $_.AppId -eq $AppId } | Select-Object -First 1
$appName = if ($cachedApp) { $cachedApp.AppName } else { $AppId }
Write-Host "[ADD ASSIGN] $appName -> intent=$intent target=$target" -ForegroundColor Yellow
Write-Host "[ADD ASSIGN] $appName -> intent=$intent targets=$($targets -join ', ')" -ForegroundColor Yellow
try {
Add-GraphAppAssignment -AppId $AppId -Intent $intent -GroupId $target
# EIN Request fuer alle Ziele: bestehende Zuweisungen werden gemergt.
Add-GraphAppAssignment -AppId $AppId -Intent $intent -GroupId $targets
} catch {
$graphBody = $null
try { $graphBody = $_.ErrorDetails.Message } catch {}
@@ -2836,38 +2842,46 @@ function Add-AppAssignmentEndpoint {
return @{ __status = $status; error = $friendly; code = $details.Code; graph = $graphBody }
}
# Cache aktualisieren — neue Zuweisung im App-Eintrag ergaenzen
# Cache aktualisieren — neue Zuweisung(en) im App-Eintrag ergaenzen.
# (Das Frontend laedt danach ohnehin neu; das haelt die UI aber sofort konsistent.)
if ($cachedApp) {
$entry = if ($target -eq "ALL_USERS") {
@{ GroupId = "ALL_USERS"; GroupName = "All Users"; IsNative = $true }
} elseif ($target -eq "ALL_DEVICES") {
@{ GroupId = "ALL_DEVICES"; GroupName = "All Devices"; IsNative = $true }
} else {
# Group-Namen aus den geladenen Gruppen oder Graph nachschlagen
$groupName = $target
$lookup = @{}
foreach ($g in $script:State.Groups) { $lookup[$g.Id] = $g.DisplayName }
foreach ($g in $script:State.RpaGroups) { $lookup[$g.Id] = $g.DisplayName }
if ($lookup.ContainsKey($target)) { $groupName = $lookup[$target] }
else {
try {
$g = Get-GraphGroupById -Id $target -Property @("id","displayName")
if ($g.displayName) { $groupName = [string]$g.displayName }
} catch {}
$lookup = @{}
foreach ($g in $script:State.Groups) { $lookup[$g.Id] = $g.DisplayName }
foreach ($g in $script:State.RpaGroups) { $lookup[$g.Id] = $g.DisplayName }
foreach ($target in $targets) {
$entry = if ($target -eq "ALL_USERS") {
@{ GroupId = "ALL_USERS"; GroupName = "All Users"; IsNative = $true }
} elseif ($target -eq "ALL_DEVICES") {
@{ GroupId = "ALL_DEVICES"; GroupName = "All Devices"; IsNative = $true }
} else {
$groupName = $target
if ($lookup.ContainsKey($target)) { $groupName = $lookup[$target] }
else {
try {
$g = Get-GraphGroupById -Id $target -Property @("id","displayName")
if ($g.displayName) { $groupName = [string]$g.displayName }
} catch {}
}
@{ GroupId = $target; GroupName = $groupName; IsNative = $false }
}
$exists = if ($intent -eq "available") {
@($cachedApp.AvailableGroups | Where-Object { $_.GroupId -eq $entry.GroupId }).Count -gt 0
} else {
@($cachedApp.RequiredGroups | Where-Object { $_.GroupId -eq $entry.GroupId }).Count -gt 0
}
if ($exists) { continue }
if ($intent -eq "available") {
$cachedApp.AvailableGroups = @($cachedApp.AvailableGroups + $entry)
$cachedApp.AvailableCount = $cachedApp.AvailableGroups.Count
} else {
$cachedApp.RequiredGroups = @($cachedApp.RequiredGroups + $entry)
$cachedApp.RequiredCount = $cachedApp.RequiredGroups.Count
}
@{ GroupId = $target; GroupName = $groupName; IsNative = $false }
}
if ($intent -eq "available") {
$cachedApp.AvailableGroups = @($cachedApp.AvailableGroups + $entry)
$cachedApp.AvailableCount = $cachedApp.AvailableGroups.Count
} else {
$cachedApp.RequiredGroups = @($cachedApp.RequiredGroups + $entry)
$cachedApp.RequiredCount = $cachedApp.RequiredGroups.Count
}
}
Write-Host "[ADD ASSIGN] OK" -ForegroundColor Green
return @{ ok = $true; appId = $AppId; intent = $intent; target = $target }
Write-Host "[ADD ASSIGN] OK ($($targets.Count) Ziel(e))" -ForegroundColor Green
return @{ ok = $true; appId = $AppId; intent = $intent; targets = @($targets); count = $targets.Count }
}
function Remove-AppAssignmentEndpoint {