From 08f851841e2deef189140f398f9d296c6f1fc875 Mon Sep 17 00:00:00 2001 From: Marco Wende Date: Wed, 10 Jun 2026 21:57:54 +0200 Subject: [PATCH] Add PolicyService.ps1 --- MVVM/Services/PolicyService.ps1 | 109 ++++++++++++++++++++++++++++++++ 1 file changed, 109 insertions(+) create mode 100644 MVVM/Services/PolicyService.ps1 diff --git a/MVVM/Services/PolicyService.ps1 b/MVVM/Services/PolicyService.ps1 new file mode 100644 index 0000000..46fd5f0 --- /dev/null +++ b/MVVM/Services/PolicyService.ps1 @@ -0,0 +1,109 @@ +class PolicyService { + + static [System.Collections.Generic.List[PolicyCheckModel]] RunChecks() { + $results = [System.Collections.Generic.List[PolicyCheckModel]]::new() + $base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox" + $extBase = "$base\ExtensionSettings" + + # BlockAboutAddons + $val = [RegistryService]::GetValue($base, "BlockAboutAddons") + if ($val -eq 1) { + $results.Add([PolicyCheckModel]::new("FEHLER", "BlockAboutAddons", "1 (aktiv)", + "Sperrt Add-on-Manager. Auf 0 setzen.", $base)) + } else { + $results.Add([PolicyCheckModel]::new("OK", "BlockAboutAddons", "(nicht gesetzt)", "Kein Problem.", $base)) + } + + # JSON-String Konflikt + $jsonVal = [RegistryService]::GetValue($base, "ExtensionSettings") + if ($jsonVal) { + $results.Add([PolicyCheckModel]::new("FEHLER", "ExtensionSettings (JSON-String)", "vorhanden", + "JSON-String ueberschreibt Unterkeys. Loeschen!", $base)) + } + + # InstallAddonsPermission + $blockKey = "$base\InstallAddonsPermission\Block" + if (Test-Path $blockKey) { + $blockVals = (Get-ItemProperty $blockKey -ErrorAction SilentlyContinue).PSObject.Properties | + Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object { $_.Value } + if ($blockVals -contains "" -or $blockVals -contains "*") { + $results.Add([PolicyCheckModel]::new("FEHLER", "InstallAddonsPermission\Block", "", + "Alle Installationen geblockt.", $blockKey)) + } else { + $results.Add([PolicyCheckModel]::new("WARN", "InstallAddonsPermission\Block", + ($blockVals -join ", "), "Bestimmte Quellen geblockt.", $blockKey)) + } + } else { + $results.Add([PolicyCheckModel]::new("OK", "InstallAddonsPermission", "(keine Block-Regel)", "Kein Problem.", $base)) + } + + # ExtensionSettings Unterkeys + if (Test-Path $extBase) { + $subkeys = Get-ChildItem $extBase -ErrorAction SilentlyContinue + if ($subkeys) { + foreach ($sk in $subkeys) { + $mode = [RegistryService]::GetValue($sk.PSPath, "installation_mode") + $url = [RegistryService]::GetValue($sk.PSPath, "install_url") + $name = "ExtensionSettings\" + $sk.PSChildName + + if ($sk.PSChildName -eq "*") { + if ($mode -eq "blocked") { + $results.Add([PolicyCheckModel]::new("WARN", "$name (Wildcard)", "blocked", + "Alle nicht gelisteten Add-ons geblockt.", $sk.PSPath)) + } + continue + } + if ($mode -eq "force_installed") { + $info = if ($url) { "install_url: $url" } else { "Keine install_url - AMO muss erreichbar sein." } + $status = if ($url) { "OK" } else { "WARN" } + $results.Add([PolicyCheckModel]::new($status, $name, "force_installed", $info, $sk.PSPath)) + } elseif ($mode -eq "blocked") { + $results.Add([PolicyCheckModel]::new("FEHLER", $name, "blocked", + "Explizit geblockt!", $sk.PSPath)) + } elseif ($mode) { + $results.Add([PolicyCheckModel]::new("WARN", $name, $mode, + "Modus ist nicht force_installed.", $sk.PSPath)) + } + } + } else { + $results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(leer)", + "Kein Add-on als force_installed eingetragen.", $extBase)) + } + } else { + $results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(nicht vorhanden)", + "Noch keine Extension-Policy gesetzt.", $base)) + } + + # Proxy + $proxyMode = [RegistryService]::GetValue("$base\Proxy", "Mode") + if ($proxyMode) { + $results.Add([PolicyCheckModel]::new("INFO", "Proxy-Policy aktiv", "Mode: $proxyMode", + "Proxy kann AMO-Download blockieren - interne URL empfohlen.", "$base\Proxy")) + } + + return $results + } + + static [void] FixError([PolicyCheckModel]$check) { + $base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox" + $extBase = "$base\ExtensionSettings" + + switch ($check.Status) { + "FEHLER" { + if ($check.Policy -eq "BlockAboutAddons") { + [RegistryService]::SetDWord($base, "BlockAboutAddons", 0) + } + elseif ($check.Policy -match "JSON-String") { + [RegistryService]::RemoveJsonString() + } + elseif ($check.Policy -match "ExtensionSettings\\(.+)" -and $Matches[1] -ne "*") { + $key = Join-Path $extBase $Matches[1] + [RegistryService]::SetString($key, "installation_mode", "force_installed") + } + elseif ($check.Policy -match "Wildcard") { + [RegistryService]::RemoveKey((Join-Path $extBase "*")) + } + } + } + } +}