110 lines
5.2 KiB
PowerShell
110 lines
5.2 KiB
PowerShell
class PolicyService {
|
|
|
|
static [System.Collections.Generic.List[PolicyCheckModel]] RunChecks() {
|
|
$results = [System.Collections.Generic.List[PolicyCheckModel]]::new()
|
|
$base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox"
|
|
$extBase = "$base\ExtensionSettings"
|
|
|
|
# BlockAboutAddons
|
|
$val = [RegistryService]::GetValue($base, "BlockAboutAddons")
|
|
if ($val -eq 1) {
|
|
$results.Add([PolicyCheckModel]::new("FEHLER", "BlockAboutAddons", "1 (aktiv)",
|
|
"Sperrt Add-on-Manager. Auf 0 setzen.", $base))
|
|
} else {
|
|
$results.Add([PolicyCheckModel]::new("OK", "BlockAboutAddons", "(nicht gesetzt)", "Kein Problem.", $base))
|
|
}
|
|
|
|
# JSON-String Konflikt
|
|
$jsonVal = [RegistryService]::GetValue($base, "ExtensionSettings")
|
|
if ($jsonVal) {
|
|
$results.Add([PolicyCheckModel]::new("FEHLER", "ExtensionSettings (JSON-String)", "vorhanden",
|
|
"JSON-String ueberschreibt Unterkeys. Loeschen!", $base))
|
|
}
|
|
|
|
# InstallAddonsPermission
|
|
$blockKey = "$base\InstallAddonsPermission\Block"
|
|
if (Test-Path $blockKey) {
|
|
$blockVals = (Get-ItemProperty $blockKey -ErrorAction SilentlyContinue).PSObject.Properties |
|
|
Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object { $_.Value }
|
|
if ($blockVals -contains "<all_urls>" -or $blockVals -contains "*") {
|
|
$results.Add([PolicyCheckModel]::new("FEHLER", "InstallAddonsPermission\Block", "<all_urls>",
|
|
"Alle Installationen geblockt.", $blockKey))
|
|
} else {
|
|
$results.Add([PolicyCheckModel]::new("WARN", "InstallAddonsPermission\Block",
|
|
($blockVals -join ", "), "Bestimmte Quellen geblockt.", $blockKey))
|
|
}
|
|
} else {
|
|
$results.Add([PolicyCheckModel]::new("OK", "InstallAddonsPermission", "(keine Block-Regel)", "Kein Problem.", $base))
|
|
}
|
|
|
|
# ExtensionSettings Unterkeys
|
|
if (Test-Path $extBase) {
|
|
$subkeys = Get-ChildItem $extBase -ErrorAction SilentlyContinue
|
|
if ($subkeys) {
|
|
foreach ($sk in $subkeys) {
|
|
$mode = [RegistryService]::GetValue($sk.PSPath, "installation_mode")
|
|
$url = [RegistryService]::GetValue($sk.PSPath, "install_url")
|
|
$name = "ExtensionSettings\" + $sk.PSChildName
|
|
|
|
if ($sk.PSChildName -eq "*") {
|
|
if ($mode -eq "blocked") {
|
|
$results.Add([PolicyCheckModel]::new("WARN", "$name (Wildcard)", "blocked",
|
|
"Alle nicht gelisteten Add-ons geblockt.", $sk.PSPath))
|
|
}
|
|
continue
|
|
}
|
|
if ($mode -eq "force_installed") {
|
|
$info = if ($url) { "install_url: $url" } else { "Keine install_url - AMO muss erreichbar sein." }
|
|
$status = if ($url) { "OK" } else { "WARN" }
|
|
$results.Add([PolicyCheckModel]::new($status, $name, "force_installed", $info, $sk.PSPath))
|
|
} elseif ($mode -eq "blocked") {
|
|
$results.Add([PolicyCheckModel]::new("FEHLER", $name, "blocked",
|
|
"Explizit geblockt!", $sk.PSPath))
|
|
} elseif ($mode) {
|
|
$results.Add([PolicyCheckModel]::new("WARN", $name, $mode,
|
|
"Modus ist nicht force_installed.", $sk.PSPath))
|
|
}
|
|
}
|
|
} else {
|
|
$results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(leer)",
|
|
"Kein Add-on als force_installed eingetragen.", $extBase))
|
|
}
|
|
} else {
|
|
$results.Add([PolicyCheckModel]::new("WARN", "ExtensionSettings", "(nicht vorhanden)",
|
|
"Noch keine Extension-Policy gesetzt.", $base))
|
|
}
|
|
|
|
# Proxy
|
|
$proxyMode = [RegistryService]::GetValue("$base\Proxy", "Mode")
|
|
if ($proxyMode) {
|
|
$results.Add([PolicyCheckModel]::new("INFO", "Proxy-Policy aktiv", "Mode: $proxyMode",
|
|
"Proxy kann AMO-Download blockieren - interne URL empfohlen.", "$base\Proxy"))
|
|
}
|
|
|
|
return $results
|
|
}
|
|
|
|
static [void] FixError([PolicyCheckModel]$check) {
|
|
$base = "HKLM:\SOFTWARE\Policies\Mozilla\Firefox"
|
|
$extBase = "$base\ExtensionSettings"
|
|
|
|
switch ($check.Status) {
|
|
"FEHLER" {
|
|
if ($check.Policy -eq "BlockAboutAddons") {
|
|
[RegistryService]::SetDWord($base, "BlockAboutAddons", 0)
|
|
}
|
|
elseif ($check.Policy -match "JSON-String") {
|
|
[RegistryService]::RemoveJsonString()
|
|
}
|
|
elseif ($check.Policy -match "ExtensionSettings\\(.+)" -and $Matches[1] -ne "*") {
|
|
$key = Join-Path $extBase $Matches[1]
|
|
[RegistryService]::SetString($key, "installation_mode", "force_installed")
|
|
}
|
|
elseif ($check.Policy -match "Wildcard") {
|
|
[RegistryService]::RemoveKey((Join-Path $extBase "*"))
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|