Add PolicyService.ps1
This commit is contained in:
@@ -0,0 +1,109 @@
|
||||
class PolicyService {
|
||||
|
||||
static [System.Collections.Generic.List[PolicyCheckModel]] RunChecks() {
|
||||
$results = [System.Collections.Generic.List[PolicyCheckModel]]::new()
|
||||
$base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox"
|
||||
$extBase = "$base\ExtensionSettings"
|
||||
|
||||
# BlockAboutAddons
|
||||
$val = [RegistryService]::GetValue($base, "BlockAboutAddons")
|
||||
if ($val -eq 1) {
|
||||
$results.Add([PolicyCheckModel]::new("FEHLER", "BlockAboutAddons", "1 (aktiv)",
|
||||
"Sperrt Add-on-Manager. Auf 0 setzen.", $base))
|
||||
} else {
|
||||
$results.Add([PolicyCheckModel]::new("OK", "BlockAboutAddons", "(nicht gesetzt)", "Kein Problem.", $base))
|
||||
}
|
||||
|
||||
# JSON-String Konflikt
|
||||
$jsonVal = [RegistryService]::GetValue($base, "ExtensionSettings")
|
||||
if ($jsonVal) {
|
||||
$results.Add([PolicyCheckModel]::new("FEHLER", "ExtensionSettings (JSON-String)", "vorhanden",
|
||||
"JSON-String ueberschreibt Unterkeys. Loeschen!", $base))
|
||||
}
|
||||
|
||||
# InstallAddonsPermission
|
||||
$blockKey = "$base\InstallAddonsPermission\Block"
|
||||
if (Test-Path $blockKey) {
|
||||
$blockVals = (Get-ItemProperty $blockKey -ErrorAction SilentlyContinue).PSObject.Properties |
|
||||
Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object { $_.Value }
|
||||
if ($blockVals -contains "<all_urls>" -or $blockVals -contains "*") {
|
||||
$results.Add([PolicyCheckModel]::new("FEHLER", "InstallAddonsPermission\Block", "<all_urls>",
|
||||
"Alle Installationen geblockt.", $blockKey))
|
||||
} else {
|
||||
$results.Add([PolicyCheckModel]::new("WARN", "InstallAddonsPermission\Block",
|
||||
($blockVals -join ", "), "Bestimmte Quellen geblockt.", $blockKey))
|
||||
}
|
||||
} else {
|
||||
$results.Add([PolicyCheckModel]::new("OK", "InstallAddonsPermission", "(keine Block-Regel)", "Kein Problem.", $base))
|
||||
}
|
||||
|
||||
# ExtensionSettings Unterkeys
|
||||
if (Test-Path $extBase) {
|
||||
$subkeys = Get-ChildItem $extBase -ErrorAction SilentlyContinue
|
||||
if ($subkeys) {
|
||||
foreach ($sk in $subkeys) {
|
||||
$mode = [RegistryService]::GetValue($sk.PSPath, "installation_mode")
|
||||
$url = [RegistryService]::GetValue($sk.PSPath, "install_url")
|
||||
$name = "ExtensionSettings\" + $sk.PSChildName
|
||||
|
||||
if ($sk.PSChildName -eq "*") {
|
||||
if ($mode -eq "blocked") {
|
||||
$results.Add([PolicyCheckModel]::new("WARN", "$name (Wildcard)", "blocked",
|
||||
"Alle nicht gelisteten Add-ons geblockt.", $sk.PSPath))
|
||||
}
|
||||
continue
|
||||
}
|
||||
if ($mode -eq "force_installed") {
|
||||
$info = if ($url) { "install_url: $url" } else { "Keine install_url - AMO muss erreichbar sein." }
|
||||
$status = if ($url) { "OK" } else { "WARN" }
|
||||
$results.Add([PolicyCheckModel]::new($status, $name, "force_installed", $info, $sk.PSPath))
|
||||
} elseif ($mode -eq "blocked") {
|
||||
$results.Add([PolicyCheckModel]::new("FEHLER", $name, "blocked",
|
||||
"Explizit geblockt!", $sk.PSPath))
|
||||
} elseif ($mode) {
|
||||
$results.Add([PolicyCheckModel]::new("WARN", $name, $mode,
|
||||
"Modus ist nicht force_installed.", $sk.PSPath))
|
||||
}
|
||||
}
|
||||
} else {
|
||||
$results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(leer)",
|
||||
"Kein Add-on als force_installed eingetragen.", $extBase))
|
||||
}
|
||||
} else {
|
||||
$results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(nicht vorhanden)",
|
||||
"Noch keine Extension-Policy gesetzt.", $base))
|
||||
}
|
||||
|
||||
# Proxy
|
||||
$proxyMode = [RegistryService]::GetValue("$base\Proxy", "Mode")
|
||||
if ($proxyMode) {
|
||||
$results.Add([PolicyCheckModel]::new("INFO", "Proxy-Policy aktiv", "Mode: $proxyMode",
|
||||
"Proxy kann AMO-Download blockieren - interne URL empfohlen.", "$base\Proxy"))
|
||||
}
|
||||
|
||||
return $results
|
||||
}
|
||||
|
||||
static [void] FixError([PolicyCheckModel]$check) {
|
||||
$base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox"
|
||||
$extBase = "$base\ExtensionSettings"
|
||||
|
||||
switch ($check.Status) {
|
||||
"FEHLER" {
|
||||
if ($check.Policy -eq "BlockAboutAddons") {
|
||||
[RegistryService]::SetDWord($base, "BlockAboutAddons", 0)
|
||||
}
|
||||
elseif ($check.Policy -match "JSON-String") {
|
||||
[RegistryService]::RemoveJsonString()
|
||||
}
|
||||
elseif ($check.Policy -match "ExtensionSettings\\(.+)" -and $Matches[1] -ne "*") {
|
||||
$key = Join-Path $extBase $Matches[1]
|
||||
[RegistryService]::SetString($key, "installation_mode", "force_installed")
|
||||
}
|
||||
elseif ($check.Policy -match "Wildcard") {
|
||||
[RegistryService]::RemoveKey((Join-Path $extBase "*"))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user