v0.1.31 — Policy-Konsolidierung, Geraete-Export nach Gruppe, Gruppen-in-Gruppen
Build & Release MSI / build-msi (push) Canceled after 0s
Build & Release MSI / build-msi (push) Canceled after 0s
- Policies zusammenfuehren (Settings Catalog -> eine neue Policy, Konfliktaufloesung) - Geraete-Tab: Gruppen-Filter (Live-Suche) + CSV-Export der angezeigten Liste - Group Management: bestehende Gruppen als Mitglied hinzufuegen (verschachtelt) - Fix: Geraete "Invalid Date" (ISO-Normalisierung) + Datums-/Spalten-Sortierung - Doku (README/CHANGELOG) + Version-Bump 0.1.31 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -738,6 +738,161 @@ function Invoke-PolicyAssignEndpoint {
|
||||
return @{ ok = $true; assignedCount = $ok; results = @($results) }
|
||||
}
|
||||
|
||||
# ============================================================
|
||||
# Settings-Catalog-Policies zu EINER neuen Policy zusammenfuehren
|
||||
# ============================================================
|
||||
|
||||
# settingDefinitionId eines Settings-Elements (Wrapper { settingInstance, id }).
|
||||
function Get-SettingDefinitionId {
|
||||
param($SettingElement)
|
||||
$si = Get-PolicyProp $SettingElement 'settingInstance'
|
||||
if (-not $si) { $si = $SettingElement }
|
||||
return [string](Get-PolicyProp $si 'settingDefinitionId')
|
||||
}
|
||||
|
||||
# Kanonische, stabil sortierte JSON-Darstellung der settingInstance -> Wert-Vergleich
|
||||
# fuer die Konflikt-Erkennung (gleiche Definition, unterschiedlicher Wert = Konflikt).
|
||||
function Get-SettingCanonicalJson {
|
||||
param($SettingElement)
|
||||
$si = Get-PolicyProp $SettingElement 'settingInstance'
|
||||
if (-not $si) { $si = $SettingElement }
|
||||
return ((ConvertTo-StableObject $si) | ConvertTo-Json -Depth 50 -Compress)
|
||||
}
|
||||
|
||||
# Body: { ids:[...], mode:"preview"|"create", name?, description?, resolutions?:{ <defId>:<sourceId> } }
|
||||
# Nur Settings Catalog. Fuehrt die 'settings' mehrerer Policies zu einer neuen zusammen.
|
||||
# Gleiche settingDefinitionId + gleicher Wert -> einmal uebernommen. Gleiche Definition,
|
||||
# anderer Wert -> Konflikt: Default gewinnt die zuerst gewaehlte Policy, per 'resolutions'
|
||||
# ueberschreibbar. Import erfolgt als Neuanlage (nie Ueberschreiben).
|
||||
function Invoke-PolicyConsolidateEndpoint {
|
||||
param($Body)
|
||||
try { Assert-GraphConnected } catch { return @{ __status = 401; error = 'Nicht mit Microsoft Graph verbunden' } }
|
||||
|
||||
$ids = @(Get-PolicyProp $Body 'ids') | Where-Object { $_ }
|
||||
if (@($ids).Count -lt 2) { return @{ __status = 400; error = 'Bitte mindestens zwei Settings-Catalog-Policies auswaehlen.' } }
|
||||
|
||||
$mode = [string](Get-PolicyProp $Body 'mode'); if (-not $mode) { $mode = 'preview' }
|
||||
$resolutions = Get-PolicyProp $Body 'resolutions'
|
||||
|
||||
# Details laden (Reihenfolge = Auswahlreihenfolge = Default-Konfliktgewinner)
|
||||
$sources = @()
|
||||
foreach ($id in $ids) {
|
||||
$detail = $null
|
||||
try { $detail = Get-GraphPolicyDetail -Type 'settingscatalog' -Id ([string]$id) } catch {}
|
||||
if (-not $detail) { return @{ __status = 400; error = "Policy $id konnte nicht geladen werden." } }
|
||||
$sources += @{
|
||||
id = [string]$id
|
||||
name = [string](Get-PolicyProp $detail 'name')
|
||||
platforms = [string](Get-PolicyProp $detail 'platforms')
|
||||
technologies = [string](Get-PolicyProp $detail 'technologies')
|
||||
settings = @(Get-PolicyProp $detail 'settings')
|
||||
}
|
||||
}
|
||||
|
||||
# Plattform muss uebereinstimmen - sonst kein sinnvoller Merge.
|
||||
$platforms = @($sources | ForEach-Object { $_.platforms } | Where-Object { $_ } | Sort-Object -Unique)
|
||||
if ($platforms.Count -gt 1) {
|
||||
return @{ __status = 400; error = "Unterschiedliche Plattformen ($($platforms -join ', ')) - Zusammenfuehren nicht moeglich." }
|
||||
}
|
||||
$mergedPlatform = if ($platforms.Count -ge 1) { $platforms[0] } else { 'windows10' }
|
||||
# Technologies vereinen (Union).
|
||||
$techSet = [ordered]@{}
|
||||
foreach ($s in $sources) { foreach ($t in ($s.technologies -split ',')) { $tt = $t.Trim(); if ($tt) { $techSet[$tt] = $true } } }
|
||||
$mergedTech = (@($techSet.Keys) -join ','); if (-not $mergedTech) { $mergedTech = 'mdm' }
|
||||
|
||||
# Nach settingDefinitionId gruppieren (Reihenfolge der Definitionen beibehalten).
|
||||
$groups = [ordered]@{}
|
||||
foreach ($s in $sources) {
|
||||
foreach ($el in @($s.settings)) {
|
||||
if (-not $el) { continue }
|
||||
$defId = Get-SettingDefinitionId $el
|
||||
if (-not $defId) { continue }
|
||||
if (-not $groups.Contains($defId)) { $groups[$defId] = @() }
|
||||
$groups[$defId] += @{ sourceId = $s.id; sourceName = $s.name; element = $el; canon = (Get-SettingCanonicalJson $el) }
|
||||
}
|
||||
}
|
||||
|
||||
$mergedSettings = @()
|
||||
$conflicts = @()
|
||||
foreach ($defId in @($groups.Keys)) {
|
||||
$entries = @($groups[$defId])
|
||||
$distinct = @($entries | Group-Object -Property { $_.canon })
|
||||
if ($distinct.Count -eq 1) {
|
||||
$mergedSettings += $entries[0].element
|
||||
continue
|
||||
}
|
||||
# Konflikt: Gewinner bestimmen (resolutions[defId] = sourceId, sonst erste Quelle).
|
||||
$resSource = if ($resolutions) { [string](Get-PolicyProp $resolutions $defId) } else { '' }
|
||||
$chosen = $null
|
||||
if ($resSource) { $chosen = @($entries | Where-Object { $_.sourceId -eq $resSource })[0] }
|
||||
if (-not $chosen) { $chosen = $entries[0] }
|
||||
$mergedSettings += $chosen.element
|
||||
$conflicts += @{
|
||||
settingDefinitionId = $defId
|
||||
chosenSourceId = $chosen.sourceId
|
||||
variants = @($distinct | ForEach-Object {
|
||||
@{
|
||||
sourceIds = @($_.Group | ForEach-Object { $_.sourceId })
|
||||
sourceNames = @($_.Group | ForEach-Object { $_.sourceName } | Select-Object -Unique)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
if ($mode -ne 'create') {
|
||||
return @{
|
||||
ok = $true
|
||||
mode = 'preview'
|
||||
platform = $mergedPlatform
|
||||
technologies = $mergedTech
|
||||
totalSettings = @($mergedSettings).Count
|
||||
conflictCount = @($conflicts).Count
|
||||
conflicts = @($conflicts)
|
||||
sources = @($sources | ForEach-Object { @{ id = $_.id; name = $_.name; settingCount = @($_.settings).Count } })
|
||||
}
|
||||
}
|
||||
|
||||
# --- create ---
|
||||
if ($script:State.ReadOnly) { return @{ __status = 403; error = 'Read-Only-Modus: Zusammenfuehren ist deaktiviert.' } }
|
||||
$name = [string](Get-PolicyProp $Body 'name')
|
||||
if ([string]::IsNullOrWhiteSpace($name)) { return @{ __status = 400; error = 'Name fuer die neue Policy fehlt.' } }
|
||||
$desc = [string](Get-PolicyProp $Body 'description')
|
||||
|
||||
# settings fuer den POST vorbereiten: Wrapper mit @odata.type, read-only 'id' weg,
|
||||
# Arrays reparieren (gleiche Behandlung wie beim Import).
|
||||
$outSettings = @()
|
||||
foreach ($el in $mergedSettings) {
|
||||
$si = Get-PolicyProp $el 'settingInstance'
|
||||
if (-not $si) { $si = $el }
|
||||
$outSettings += [ordered]@{
|
||||
'@odata.type' = '#microsoft.graph.deviceManagementConfigurationSetting'
|
||||
settingInstance = $si
|
||||
}
|
||||
}
|
||||
$outSettings = @(Repair-SettingsCatalogArrays $outSettings)
|
||||
|
||||
$newBody = [ordered]@{
|
||||
name = $name
|
||||
description = $desc
|
||||
platforms = $mergedPlatform
|
||||
technologies = $mergedTech
|
||||
templateReference = @{ templateFamily = 'none'; templateId = '' }
|
||||
settings = $outSettings
|
||||
}
|
||||
$json = $newBody | ConvertTo-Json -Depth 50
|
||||
if ($json -match 'System\.Collections\.Hashtable|System\.Object\[\]') {
|
||||
return @{ __status = 500; error = 'Interner Serialisierungsfehler beim Zusammenfuehren (stringifizierte Objekte).' }
|
||||
}
|
||||
try {
|
||||
$created = Invoke-MgGraphRequestRetry -Uri 'https://graph.microsoft.com/beta/deviceManagement/configurationPolicies' -Method POST -Body $json -ContentType 'application/json'
|
||||
return @{ ok = $true; mode = 'create'; newId = [string](Get-PolicyProp $created 'id'); name = $name; settingsCount = @($outSettings).Count; conflictCount = @($conflicts).Count }
|
||||
} catch {
|
||||
$msg = $_.Exception.Message
|
||||
try { if ($_.ErrorDetails.Message) { $msg = $_.ErrorDetails.Message } } catch {}
|
||||
return @{ __status = 500; error = $msg }
|
||||
}
|
||||
}
|
||||
|
||||
# ============================================================
|
||||
# Policy-Snapshot nach Git (voller Export, stabile Dateinamen)
|
||||
# ============================================================
|
||||
|
||||
Reference in New Issue
Block a user