Skip to main content

StackJack 0.1.0.4645+7127aa4

StackJack 0.1.0.4645+7127aa4

This release is mostly about accuracy: Microsoft 365 (CIPP) tools now verify that the operation you authorized is the one that actually runs, Halo ticket and quotation writes report honestly when StackJack could not confirm the result, and agents and templates that reference tools which no longer exist can finally be seen and repaired instead of silently misbehaving.

New features

  • The template editor now shows tool names it cannot resolve in your catalog instead of hiding them. Names are grouped by cause — tools removed from the platform, and tools your tenant is not subscribed or entitled to — because the fix differs: the first group can only be deleted, the second usually points at a subscription or plan change. Each name has a remove control, and removed-from-platform names can be cleared as a group. Previously these names were invisible and un-removable while still blocking publish, leaving the template unfixable.

Improvements

  • CIPP tools that take a specific operation (enable/disable, add/remove, delete, and similar) now re-check that operation against the final request body after any raw field overrides are merged. If an override would change the operation you were shown and approved, the call is refused before anything is sent, with an error naming the conflicting key. All other raw keys keep their existing last-wins behaviour. Tool descriptions were updated to match what is now enforced.
  • Halo ticket writes no longer report success when StackJack cannot prove the write is what landed. If another change overwrites the field between the write and the read-back, or the outcome cannot be determined, the result comes back as unconfirmed with guidance to re-read the ticket before re-sending, rather than as a plain success or a vendor-normalised value.
  • halo_bulk_ticket_update now reports an unconfirmed row type with the affected fields and an unconfirmedCount. Rows in that state are excluded from successCount; the count of writes accepted by Halo is reported separately.
  • Around 120 CIPP tool and parameter descriptions were corrected against the current upstream API so agents act on what the endpoint actually does. Notable corrections include the SharePoint permissions tool (it adds or removes a site collection administrator, not general access to a site), the SharePoint site creation tool (hyphens survive in the generated site URL), the Teams voice number assignment tool (the number type is required on the assign path), the alerting and audit-log tools, and site deletion (no recovery window is promised where upstream does not assert one).
  • Retired platform tool names no longer appear in any derived view of an agent's tool set. The effective-tools response, the approval cap count, deploy comparisons and the Portal's callable and cost figures now all agree and exclude names the platform has removed. Stored agent definitions and version snapshots are untouched, so the names remain visible for migration and support.
  • Two tools are now marked destructive and go through the consent gate: the Office app deployment tool (it writes and assigns synchronously, can target all tenants, and can uninstall existing Office versions) and the mailbox restore tool (one of its operations deletes a restore request).

Bug fixes

  • Adding Autopilot devices now sends a JSON array of device objects, and the forwarding option on user offboarding now sends the shape the upstream API expects.
  • Tool trim proposals no longer treat retired tool names as anchors. An agent whose only required tool had been retired could previously produce a proposal that removed every tool it could actually call, and that proposal saved cleanly — recovery required restoring an earlier version.
  • Quotation line updates no longer report a value as persisted when the endpoint provides no way to confirm it. That case is now reported as unverified and points you at the quotation read tool. A batch containing both discarded and unconfirmed values now names both, and a call in which a value demonstrably moved is no longer described as having changed nothing.
  • A failed read-back after a Halo quotation write is no longer presented as a timeout that will be retried automatically. Halo may already have accepted the write, so the message now says explicitly not to retry blindly.
  • The domain deletion tool now refuses a raw override that would retarget the deletion at a different domain than the one you reviewed.
  • The install wizard no longer lets a selection made up entirely of retired tools reach the Install step.

UI & UX changes

  • The template install wizard separates tools removed from the platform from tools awaiting a connector. The "enable your connector" warning and its link no longer appear for tools that no subscription can bring back; those get their own notice.
  • Retired recommended tools in the install wizard render disabled instead of offering a checkbox the installer silently ignores.
  • The hint under a disabled Install button now gives the correct reason, including for a selection consent cannot unblock.
  • Bulk removal in the template editor is offered only for tools removed from the platform. For tools missing from your catalog, per-name removal remains, since deletion is usually the wrong repair there.

Breaking changes

  • CIPP tools previously documented an escape hatch that let a raw field override replace the tool's own operation value ("at the caller's own risk"). That path is now refused. Agents or integrations relying on it will receive a refusal instead of a dispatched call; use the tool's own operation parameter.
  • The Office app deployment tool and the mailbox restore tool now require destructive-action consent. Unattended flows using them will need the consent path.
  • successCount in bulk ticket updates now excludes rows whose result could not be confirmed. If you parse that field, expect lower counts where Halo accepted a write StackJack could not verify.
  • Saving an agent whose tool chain references a tool retired from the platform is now refused, including on the API path where no tool policy is supplied. Remove or replace the retired step before saving.