StackJack 0.1.0.5228+008b273
StackJack 0.1.0.5228+008b273
This release fixes a set of connector defects across CIPP, Hudu, Halo, Acronis, Ingram Micro and Datto EDR, most of them tools that could not succeed under any input. Several CIPP tools now require the tenant or record selector they always needed, and a new CIPP tool lists GDAP relationships.
New features
- CIPP:
cipp_list_gdap_relationshipslists all GDAP relationships (optionally filtered byid). Previously nothing exposed this list; tools whose descriptions said to usecipp_list_gdap_access"to find the GDAP id" now point here. - CIPP:
cipp_universal_search_v2gains an optionaltypeparameter (Users, Groups, Applications or Licenses; Users by default). The tool searches one data type per call across the tenants your CIPP connection is scoped to; its description previously overstated what it covered.
Improvements
- CIPP:
cipp_list_jit_admindescription now explains that withAllTenants, an empty result with a queue id means the estate cache is still loading, and namescipp_get_queue_statusas the tool to poll. - CIPP:
cipp_cipp_db_cachenow describes what itsNameandTypesparameters actually do (a cache-sync job is started;AllTenantsfans it across every managed tenant). - Acronis:
acronis_get_users_medescription now states that it cannot succeed on a StackJack connection and points toacronis_get_clientinstead. - Halo: the
filtersJsonexamples onhalo_list_ticket_type_detailsandhalo_list_status_detailsnamed a filter the endpoint does not have, so the filter was silently ignored and an unfiltered list came back. The examples now use parameters the endpoint accepts. - Hudu: when a Hudu API key lacks password access, the error returned now says so directly instead of suggesting a wrong region or instance.
Bug fixes
- Datto EDR credentials could not be saved. The connector form rejected every save with an "all fields are required" message even when both fields were filled. Saving now works.
- Acronis connections were being disabled automatically. The credential health check used a call that rejects API-client credentials, so a correctly configured Acronis connection was disabled shortly after being saved. The check now uses the right call and valid connections stay enabled.
- Hudu:
hudu_expiration_alertsandhudu_network_documentation_gapsfailed on every call since the connector shipped, because some Hudu list responses come back as a bare list rather than a wrapped object. Both now work. In addition, the expiration type filter is now applied correctly, and expiration rows are read from the fields Hudu actually returns, soexpirations_by_typegroups on the real expiration type and the owning record fields are populated instead of blank. - Hudu: documentation coverage no longer fails when the API key has no password access. Previously one permission error discarded the whole result. The tool now scores over the facets it could read, returns password counts as
nullrather than zero, and always includespasswords_included,coverage_facets,coverage_facets_countedandpasswords_unavailable_reasonso the denominator is explicit.hudu_password_auditstill fails loudly in this case, since passwords are the whole point of that tool. - Halo:
filtersJsonrejected numbers and booleans onhalo_list_ticket_type_details,halo_list_status_detailsandhalo_list_timesheet_events. A filter such as{"type_id": 12}was reported as malformed JSON, which sent agents into a retry loop. Numbers and booleans are now accepted; null-valued filters are dropped; nested objects or arrays are refused with a message that states the actual problem. - Halo:
halo_add_actionno longer accepts bothnoteandnoteHtmltogether. Halo does not merge them, so supplying both left unrendered HTML in the action. Exactly one is now required:notefor plain text,noteHtmlfor HTML. Supplying both or neither is refused before anything is sent to Halo, with an error that states the rule. The purpose-built wrappers (halo_add_internal_note,halo_log_time,halo_change_ticket_status_with_note) are unchanged. - CIPP:
cipp_list_gdap_accesscalled a single-relationship endpoint with no id and always failed. It now takes a requiredidand returns that relationship's access assignments. - CIPP:
cipp_all_tenant_compliancenever asked for all tenants, so it returned a "not onboarded in Lighthouse" error for everyone. It now queries the estate correctly; the description explains the Microsoft 365 Lighthouse prerequisite and what that error means when it does occur. - CIPP:
cipp_list_azure_ad_connect_statusreturned data for the MSP's own partner tenant while presenting it as an estate-wide report. It now requirestenantFilterand describes itself accurately. - CIPP:
cipp_list_tenant_allow_blockfailed with a 403 whenever no tenant was given. It now requirestenantFilter;AllTenantsis served from CIPP's cached reporting data. - CIPP:
cipp_list_tenant_alignmentis estate-wide by design; its description now says the acceptedtenantFilterhas no effect. - CIPP:
cipp_list_shared_mailbox_account_enabledreturned an empty 500 andcipp_list_check_ext_alertsreturned the entire instance's alert table (exceeding the response size limit) because neither sent a tenant. Both now requiretenantFilter. - CIPP: fifteen tools sent no parameters at all even though the CIPP endpoint behind each one reads a selector. Depending on the tool this produced a hard error, an empty list that read as "nothing found", or data from the wrong tenant. Now:
- Required
tenantFilter:cipp_list_global_address_list,cipp_list_mailbox_restores,cipp_list_sharepoint_admin_url,cipp_list_teams_lis_location,cipp_list_jit_admin,cipp_list_breaches_tenant,cipp_list_csp_sku,cipp_list_users_and_groups,cipp_list_db_cache. - Required
tenantFilterplus a second selector:cipp_list_quarantine_message(Identity) andcipp_list_user_trusted_blocked_senders(UserID); neither could succeed before. cipp_cipp_db_cache: requiredtenantFilterandName, optionalTypes.cipp_universal_search_v2: requiredsearchTerms, optionallimit.cipp_list_breaches_account: requiredaccount.cipp_app_insights_query: requiredquery.cipp_list_audit_log_testandcipp_offboarding_job_statusare broken in CIPP itself; their descriptions now say the tool is expected to fail until CIPP fixes them.- Ingram Micro:
ingram_estimate_freightrejected every request because its description saidshipToAddresswas an array, while Ingram accepts an object. The description now says object, and a one-element array is unwrapped automatically so existing callers keep working.
Breaking changes
- The CIPP tools listed above now require selectors (
tenantFilter,id,Identity,UserID,Name,searchTerms,account,query) that were previously omitted. Calls without them are now refused with a validation error rather than failing or returning wrong data upstream. No parameter or tool was removed. halo_add_actionnow refuses calls that supply bothnoteandnoteHtml, or neither.noteis no longer required on its own; exactly one of the two must be supplied.