Skip to main content

StackJack 0.1.0.5228+008b273

StackJack 0.1.0.5228+008b273

This release fixes a set of connector defects across CIPP, Hudu, Halo, Acronis, Ingram Micro and Datto EDR, most of them tools that could not succeed under any input. Several CIPP tools now require the tenant or record selector they always needed, and a new CIPP tool lists GDAP relationships.

New features

  • CIPP: cipp_list_gdap_relationships lists all GDAP relationships (optionally filtered by id). Previously nothing exposed this list; tools whose descriptions said to use cipp_list_gdap_access "to find the GDAP id" now point here.
  • CIPP: cipp_universal_search_v2 gains an optional type parameter (Users, Groups, Applications or Licenses; Users by default). The tool searches one data type per call across the tenants your CIPP connection is scoped to; its description previously overstated what it covered.

Improvements

  • CIPP: cipp_list_jit_admin description now explains that with AllTenants, an empty result with a queue id means the estate cache is still loading, and names cipp_get_queue_status as the tool to poll.
  • CIPP: cipp_cipp_db_cache now describes what its Name and Types parameters actually do (a cache-sync job is started; AllTenants fans it across every managed tenant).
  • Acronis: acronis_get_users_me description now states that it cannot succeed on a StackJack connection and points to acronis_get_client instead.
  • Halo: the filtersJson examples on halo_list_ticket_type_details and halo_list_status_details named a filter the endpoint does not have, so the filter was silently ignored and an unfiltered list came back. The examples now use parameters the endpoint accepts.
  • Hudu: when a Hudu API key lacks password access, the error returned now says so directly instead of suggesting a wrong region or instance.

Bug fixes

  • Datto EDR credentials could not be saved. The connector form rejected every save with an "all fields are required" message even when both fields were filled. Saving now works.
  • Acronis connections were being disabled automatically. The credential health check used a call that rejects API-client credentials, so a correctly configured Acronis connection was disabled shortly after being saved. The check now uses the right call and valid connections stay enabled.
  • Hudu: hudu_expiration_alerts and hudu_network_documentation_gaps failed on every call since the connector shipped, because some Hudu list responses come back as a bare list rather than a wrapped object. Both now work. In addition, the expiration type filter is now applied correctly, and expiration rows are read from the fields Hudu actually returns, so expirations_by_type groups on the real expiration type and the owning record fields are populated instead of blank.
  • Hudu: documentation coverage no longer fails when the API key has no password access. Previously one permission error discarded the whole result. The tool now scores over the facets it could read, returns password counts as null rather than zero, and always includes passwords_included, coverage_facets, coverage_facets_counted and passwords_unavailable_reason so the denominator is explicit. hudu_password_audit still fails loudly in this case, since passwords are the whole point of that tool.
  • Halo: filtersJson rejected numbers and booleans on halo_list_ticket_type_details, halo_list_status_details and halo_list_timesheet_events. A filter such as {"type_id": 12} was reported as malformed JSON, which sent agents into a retry loop. Numbers and booleans are now accepted; null-valued filters are dropped; nested objects or arrays are refused with a message that states the actual problem.
  • Halo: halo_add_action no longer accepts both note and noteHtml together. Halo does not merge them, so supplying both left unrendered HTML in the action. Exactly one is now required: note for plain text, noteHtml for HTML. Supplying both or neither is refused before anything is sent to Halo, with an error that states the rule. The purpose-built wrappers (halo_add_internal_note, halo_log_time, halo_change_ticket_status_with_note) are unchanged.
  • CIPP: cipp_list_gdap_access called a single-relationship endpoint with no id and always failed. It now takes a required id and returns that relationship's access assignments.
  • CIPP: cipp_all_tenant_compliance never asked for all tenants, so it returned a "not onboarded in Lighthouse" error for everyone. It now queries the estate correctly; the description explains the Microsoft 365 Lighthouse prerequisite and what that error means when it does occur.
  • CIPP: cipp_list_azure_ad_connect_status returned data for the MSP's own partner tenant while presenting it as an estate-wide report. It now requires tenantFilter and describes itself accurately.
  • CIPP: cipp_list_tenant_allow_block failed with a 403 whenever no tenant was given. It now requires tenantFilter; AllTenants is served from CIPP's cached reporting data.
  • CIPP: cipp_list_tenant_alignment is estate-wide by design; its description now says the accepted tenantFilter has no effect.
  • CIPP: cipp_list_shared_mailbox_account_enabled returned an empty 500 and cipp_list_check_ext_alerts returned the entire instance's alert table (exceeding the response size limit) because neither sent a tenant. Both now require tenantFilter.
  • CIPP: fifteen tools sent no parameters at all even though the CIPP endpoint behind each one reads a selector. Depending on the tool this produced a hard error, an empty list that read as "nothing found", or data from the wrong tenant. Now:
  • Required tenantFilter: cipp_list_global_address_list, cipp_list_mailbox_restores, cipp_list_sharepoint_admin_url, cipp_list_teams_lis_location, cipp_list_jit_admin, cipp_list_breaches_tenant, cipp_list_csp_sku, cipp_list_users_and_groups, cipp_list_db_cache.
  • Required tenantFilter plus a second selector: cipp_list_quarantine_message (Identity) and cipp_list_user_trusted_blocked_senders (UserID); neither could succeed before.
  • cipp_cipp_db_cache: required tenantFilter and Name, optional Types.
  • cipp_universal_search_v2: required searchTerms, optional limit.
  • cipp_list_breaches_account: required account.
  • cipp_app_insights_query: required query.
  • cipp_list_audit_log_test and cipp_offboarding_job_status are broken in CIPP itself; their descriptions now say the tool is expected to fail until CIPP fixes them.
  • Ingram Micro: ingram_estimate_freight rejected every request because its description said shipToAddress was an array, while Ingram accepts an object. The description now says object, and a one-element array is unwrapped automatically so existing callers keep working.

Breaking changes

  • The CIPP tools listed above now require selectors (tenantFilter, id, Identity, UserID, Name, searchTerms, account, query) that were previously omitted. Calls without them are now refused with a validation error rather than failing or returning wrong data upstream. No parameter or tool was removed.
  • halo_add_action now refuses calls that supply both note and noteHtml, or neither. note is no longer required on its own; exactly one of the two must be supplied.