StackJack 0.1.0.4371+5ff6f75
StackJack 0.1.0.4371+5ff6f75
This release is centred on Microsoft connections: you can now connect Azure and Microsoft Graph using your own app registration, choose how much permission you consent to, and send per-customer-tenant consent links from the Portal. It also fixes widespread request failures on Addigy, hardens Halo quotation writes against silent data loss, and rebuilds several CIPP tools that previously ignored their parameters.
New features
- Bring your own Microsoft app registration. Both Microsoft connector cards now have an "Advanced — use your own app registration" section where you can supply your organization's own client ID and secret. Shared, per-member, and agent connections all use the same application, so an organization can never end up split across two consent boundaries. Token refresh uses your own application's credentials.
- A provisioning script you can run yourself. A PowerShell script builds a multi-tenant app registration in your tenant with the correct StackJack redirect URLs and the permission set matching your chosen tier, and prints the secret once. Re-running it against an existing app updates it in place.
- Microsoft permission tiers. When connecting, you can choose Full, Standard, or Read. The choice applies to your own application and to StackJack's application, and it is remembered so re-authorizing repeats the same choice rather than widening it.
- Switch back to StackJack's application. An explicit control returns the shared connection to the StackJack app if you no longer want to use your own.
- Authorize a customer tenant. Both Microsoft cards can now generate an admin-consent link for a specific customer tenant, ready to copy and send. The consenting admin lands on a new page that shows the outcome of the consent — no StackJack sign-in required on their side.
- Addigy: a new tool reports the organization your API token belongs to, so an agent can discover the token's own organization ID without being told it.
- CIPP: new tools to list excluded licenses and to manage the license exclusion list.
Improvements
- Microsoft connection failures now explain what to do instead of returning a generic error. Missing per-customer-tenant admin consent, tenants not covered by a delegated admin relationship (now on both Microsoft connectors), and expired authorization each get their own guidance, including which roles can grant consent and a note that reconnecting will not resolve a consent gap. A consent gap no longer triggers a re-authorization email to a user who could not have fixed it.
- Microsoft consent now asks for Graph and Azure management only, so a customer admin is no longer blocked by resources their tenant cannot see. The two remaining resources are consented separately via scoped links.
- Diagnostic files StackJack generates while working a support ticket are now deleted when the ticket closes, across every path that can close a ticket. Files you attached yourself are untouched.
- Several CIPP tool descriptions were corrected where they described behavior that could silently lose your changes — for example, user edits requiring both the username and the domain on every call, license and mailbox permission entries needing object form rather than plain strings, and the date format log filtering actually accepts.
- Ingram: the order tool now warns against the duplicate-purchase-order override that appears in the vendor's own sample requests, and notes that the async lane does not return an order number at submit time. D&H: the purchase-order uniqueness guidance is now scoped to the lane the vendor actually documents it for.
- Connector documentation updated: a walkthrough for consenting once per customer tenant, a guide to bringing your own Microsoft app registration and choosing a permission tier, UniFi Site Manager per-key site scopes, correct Addigy permission naming, and new Copilot Studio connection and troubleshooting guidance.
Bug fixes
- Addigy: JSON requests no longer send a character-set parameter that Addigy rejected outright, which was causing failures across most operations that send a body. Requests that Addigy redirects to the trailing-slash form of the same path are now retried once automatically.
- Addigy: the "needs a parent-organization token" hint no longer attaches to every Addigy rejection. It now appears only for the endpoints where it applies, and token or rate-limit signals keep their own guidance.
- Halo: creating a quotation with an ID in the payload is now refused. Previously this behaved as an update and could silently rewrite an existing quote's header fields.
- Halo: quotation line updates are now verified by reading the quote back. Line IDs that do not exist are refused before anything is sent, duplicate line IDs and lines without an ID are refused so a retry cannot double a billing line, and a write that did not land is reported as a failure instead of returning success.
- Halo: fixed false "your values did not persist" reports when a number came back stored in a different string format, and when clearing a field or writing a composite value that the vendor re-serializes.
- Microsoft: re-authorizing no longer silently widens a Read or Standard connection back to the full permission set — the stored tier is loaded when you open the card.
- Microsoft: the Read tier was missing the core user, group, directory, mail, and Intune read permissions, and the Standard tier had dropped the delegated-admin, domain, organization, and role reads used for troubleshooting. Both now include them.
- Microsoft: narrow tiers on StackJack's application no longer trigger a per-customer-tenant consent prompt for permissions that were already consented.
- Consent links: the generated link is cleared when you change the tenant, cancel, close, or reopen the dialog, so a previous customer's link can no longer be copied under a new customer's name. Printed links now use the production return address rather than a development one.
- Microsoft credentials: a half-entered pair (an ID without a secret, or a secret without an ID) is refused rather than quietly falling back to StackJack's application, and if stored credentials cannot be read the authorization is refused instead of proceeding under a different application. A disabled stored credential no longer causes a silent switch back to StackJack's app.
- CIPP: tools that previously ignored the parameters you passed now send them — service principal operations, and log filtering by tenant, date range, severity, and API. Bulk license changes now work over a list of operations, and invalid operation names or mismatched "all licenses" flags are refused up front instead of silently applying the previous entry's licenses.
UI & UX changes
- The customer-tenant field now commits shortly after you stop typing rather than on every keystroke, so characters are no longer dropped and the stale link clears predictably.
- The permission tier dropdown distinguishes "still reading" from "could not be read" instead of showing Full while the stored value is still loading, and a tier you pick while the read is in flight is kept.
- Disconnecting a Microsoft connection now closes the configuration form.
- The Ingram contact email field is now labelled as required for quote search and freight estimates, with clearer helper text, and the error for a missing value names the Portal field rather than only the underlying header.
- The permission tier selector and the provisioning script's help text no longer use internal vocabulary, and the script's progress output no longer implies a narrow tier is a subset of the full set.
Breaking changes
- The CIPP app approval tool has been rebuilt to reflect what it actually does: it returns one admin-consent link per managed tenant. It does not approve or deny pending requests — no API can — and it is now classified as a read-only tool.
- The CIPP bulk license tool now takes a list of license operations in the request body instead of its previous parameterless form.
Known issues
- The CIPP organization message tool still ships without a usable input schema and is queued for a rebuild.