5d58c5f5ffb0e89c2de2228af1e24960b985dbfb
5189
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
194f0cfb8f |
Fix SSO callback URLs doubling the subpath under a URL prefix
Fixes #46641 When Fleet runs under a subpath, server_url already includes that subpath, so appending url_prefix again produced a doubled ACS callback path (e.g. https://host/subpath/subpath/api/v1/fleet/sso/callback), breaking SAML authentication for both login and MDM end user authentication. Drop url_prefix from the callback URL construction so the path is appended directly to server_url, which is the full external base URL. Fixes the same flaw in all five ACS-construction sites: login SSO initiate and callback, and MDM SSO initiate plus both callback branches. |
||
|
|
8b737cc87c |
Fix duplicated URL prefix in transactional email links for subpath deployments
Fixes #46642 When Fleet is deployed under a subpath, server_url already carries that subpath, so the email link base was being built as server_url + url_prefix, duplicating the path (e.g. https://host/subpath/subpath/login/reset) and producing 404 links. Use server_url directly as the link base, matching how the rest of the codebase already treats server_url as the full external base URL. |
||
|
|
657ba985c3 |
Fix returned values on MDM command results endpoint (#48296)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # Fix tagging of hostnames on returned MDM command results so all returned results have a hostname # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed an issue where some MDM command results could return without hostnames. * Improved result visibility so only hosts the caller is allowed to see are included. * Ensured team-scoped users see only their permitted results, while global admins continue to see all available results. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a2af2d97a0 |
Adding BYOD backend changes (#47716)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** #23242 Backend changes for Apple BYOD (personal) MDM enrollment. - Adds a `byod` enrollment path that distinguishes personal devices from organization-owned devices. - Persists per-host Apple MDM enrollment access rights in a new `host_mdm_apple_enrollment_permissions` table so SCEP/ACME renewal honours Apple's monotonic-narrowing invariant (permissions can never be widened on profile replacement). - Surfaces wipe/lock/clear-passcode allowed flags on host details for manually-enrolled Apple hosts. - Renames the personal enrollment status label to `On (manual - personal)`. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [ ] QA'd all new/changed functionality manually ### Test plan - Manual (profile) enrollment, company-owned: device receives full access rights; wipe/lock/clear-passcode allowed. - Manual (profile) enrollment, personal (BYOD via `byod=1`): device receives narrowed access rights (no device lock/erase); host details show wipe/lock/clear-passcode disabled. - SCEP/ACME renewal for each of the above: renewed profile preserves the original ServerURL (incl. `byod=1`) and the stored (narrowed) access rights; Apple does not reject the replacement. - Renewal batching: multiple company-owned hosts collapse into a single InstallProfile command; a BYOD host gets its own command. - Account-Driven User Enrollment (ADUE): enroll a personal device via ADUE and confirm it is inherently restricted (Apple `UserEnrollment` mode — no device lock/erase regardless of AccessRights), and that its SCEP renewal succeeds and preserves the account-driven enrollment profile. - Deleted-then-returned device: delete a still-enrolled BYOD host in Fleet, let it check back in, and confirm a subsequent SCEP renewal still uses the narrowed permissions. ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added personal (BYOD) Apple MDM enrollment support across manual profiles, OTA enrollments, and SCEP/ACME certificate renewals, with access rights generated appropriately. * Apple host details now surface per-device permission flags for wipe, lock, and clear passcode when available. * Enrollment status text now shows personal manual enrollments as “On (manual - personal)”. * **Bug Fixes** * Enforced remote wipe/lock (and clear passcode) permissions correctly for personal devices, including persistence across renewals. * Host deletion cleanup now removes newly tracked enrollment permission data. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d563ed21a1 |
Add activity and enable managed account fleets endpoint (#48273)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #44153 - Adds mdm enabled and configured checks for the update fleet endpoint - Adds activity creation for the update fleet endpoint + gitops apply # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] Timeouts are implemented and retries are limited to avoid infinite loops - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [ ] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [x] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [ ] Verified that any relevant UI is disabled when GitOps mode is enabled <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added activity logs when the managed local account setting is enabled or disabled. * Managed local account updates now work consistently through both the Update Fleet endpoint and GitOps. * **Bug Fixes** * Prevented enabling managed local account unless macOS MDM is enabled and configured. * No activity is created when the setting is saved without any actual change. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c226a3feab |
On var change resend Android certificate templates and managed app configs (#48278)
**Related issue:** Resolves #36681, #48042 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [ ] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Certificate templates and managed Android app configurations now keep track of referenced variables. * Variable changes can now trigger automatic re-sending of affected profiles and app availability updates. * **Bug Fixes** * Resend behavior now refreshes certificate templates when related variable values change. * Android managed app configurations are re-queued when their variables are updated. * **Database** * Added support for variable tracking on certificate templates and Android app configurations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
608bd2764c |
Restrict conditional access Okta IdP asset endpoints to privileged roles (#48294)
# Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`. - [x] Input data is properly validated (authorization policy change only). ## Testing - [x] Added/updated automated tests — the role matrix in `TestConditionalAccessGetIdPSigningCertAuth` and `TestConditionalAccessGetIdPAppleProfileAuth` now asserts observer and observer+ are denied; `go test ./server/authz/` confirms the policy compiles. - [x] QA'd all new/changed functionality manually — covered by the automated role-matrix tests for this authz-only change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Tightened access to conditional access identity provider assets so only higher-privilege roles can read them. * Users with observer and observer+ roles can no longer access these endpoints. * Updated validation coverage to reflect the revised access behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d079bda8b3 |
Fix required password reset logging users out (#48287)
# Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Summary Fixes a regression from #47860 where `PerformRequiredPasswordReset` cleared **all** sessions (including the one the user was actively using), causing an error after completing the forced password reset. **Issue:** #47860 changed `setNewPassword(ctx, user, password, false)` to `true`, which calls `DestroyAllSessionsForUser`. This broke the first-login flow for new users: they'd complete the password reset successfully but then get a 401 because their own session was destroyed. **Fix:** Revert to `clearSessions=false`, then selectively destroy all sessions except the current one using `ListSessionsForUser` + `DestroySession`. This preserves the user's active session while still invalidating any other sessions. ## Reproduction 1. Create a new user (admin_forced_password_reset defaults to true) 2. Log in as the new user in an incognito window 3. Complete the required password reset 4. **Before fix:** 401 error, user is logged out 5. **After fix:** User lands on the home screen normally ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually - [x] Confirmed that the fix is not expected to adversely impact load test results ### QA results **Test 1: Security scenario (original #47860 goal)** | Step | Result | |------|--------| | Admin flags user for required password reset | Sessions cleared, `force_password_reset=true` | | Attacker logs in with old password | Gets restricted session (401 on `/hosts`) | | Real user performs required password reset | Succeeds, `force_password_reset=false` | | Attacker session invalidated | **PASS** (401 on `/me`) | | Real user session preserved | **PASS** (200 on `/me`) | | New password works | **PASS** | | Old password rejected | **PASS** | **Test 2: Regression fix (Lucas's repro)** | Step | Result | |------|--------| | Create new user (forced reset defaults to true) | `force_password_reset=true` | | Log in as new user | Token received | | Complete required password reset | Succeeds, `force_password_reset=false` | | User session still works after reset | **PASS** (200 on `/me`) | |
||
|
|
07ebe1d836 |
Check if host is still on script's team before executing batch (#48244)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Scheduled batch script execution now re-checks host team membership at execution time, skipping any hosts moved to a different team before the batch runs. * Added a clear “team mismatch” incompatibility outcome and ensured incompatible hosts are not queued for execution. * **Tests** * Expanded script scheduling tests to cover host-to-team transfers between scheduling and execution, including updated incompatibility counts and per-host expectations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
214619d935 |
Refactor makeAndroidAppAvailable to use staggered job queuing (#47880)
**Related issue:** Resolves #47543 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Updated Android app availability to use staggered batch jobs instead of processing everything at once, improving throughput and smoothing workload. * **New Features** * Added batched handling that can perform per-host managed configuration substitution when variables are present, including scheduling “pending apply config” updates when required. * **Configuration** * Reduced the default Android batch size (`mdm.android_batch_size`) to 100. * **Bug Fixes / Tests** * Updated unit and integration tests to verify batching, staggering timing, full host coverage, and order-independent policy application behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1b64b6104a |
Fix NDES not using the same retry clearing method as SmallStep for macos (#48105)
**Related issue:** Resolves #46291 |
||
|
|
26414db4ea |
Restrict authorization for team membership operations (#48201)
**Related issue:** N/A # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] Reproduced the issue and verified the fix - [x] QA'd all new/changed functionality manually ## Summary - Introduced a more granular authorization action for team membership management - Updated OPA policy and service-layer authorization accordingly - Added comprehensive authorization test coverage ## Reproduction Verified that with the previous authorization check, an API-only user with team-scoped write access could call `PATCH /api/latest/fleet/teams/{id}/users` to modify team membership without restriction. After the fix, the operation correctly returns a 403 Forbidden for non-admin roles. Admin users retain full access to manage team membership. **Test**: `TestGitOpsCannotManageTeamMembers` in `server/service/teams_test.go` explicitly exercises this scenario and confirms the fix. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Tightened team member management so adding/removing team users now requires a dedicated team-membership write permission (global admins and team admins only, scoped appropriately). * Prevented GitOps users from modifying team membership, including self-promotion to admin. * Updated enterprise integration expectations to return **403 Forbidden** for blocked membership change attempts. * **Tests** * Expanded authorization test coverage for team member write access across roles and team scopes. * Added coverage ensuring GitOps cannot manage team members, while valid team admins can. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c041c6c24f |
Fix batch script execution validations (#48243)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved validation for batch script execution requests. * Added an extra authorization check before a batch script can be scheduled, helping ensure only permitted actions proceed. * Expanded test coverage for role-based access during batch script execution. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
faff41e41d |
Fix My device page software sorting by display name (#45836)
**Related issue:** Closes #43673 (remaining issue reported by @getvictor after PR #44873) ## Changes The "My device" page / host details software tab sorts software by `software_titles.name` (often an installer filename) instead of the custom display name. PR #44873 fixed this for the global `/software/titles` endpoint but missed the host-specific `ListHostSoftware` query path. **Fix:** Add a `LEFT JOIN software_title_display_names` to the outer query wrapper in `ListHostSoftware`, and update `hostSoftwareAllowedOrderKeys` to use `COALESCE(NULLIF(stdn.display_name, ''), name)` so display names are used for sorting when set. **1 file changed:** `server/datastore/mysql/software.go` # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: Dante Catalfamo <43040593+dantecatalfamo@users.noreply.github.com> |
||
|
|
d66242856f |
Disambiguate FMAs sharing macOS bundle IDs (#47951)
Fix handling of Fleet-maintained apps that share a macOS bundle identifier (e.g. Firefox and Firefox ESR). Removed the blind rename from UpsertMaintainedApp and added ReconcileMaintainedAppSoftwareNames: a two-pass, idempotent reconciliation that (1) renames titles tied to a single FMA via installer links and (2) heuristically renames by bundle identifier only when the identifier maps to exactly one FMA name. Updated team join logic to prefer matching by installer link and fall back to bundle identifier, changed GetFMANamesByIdentifier to omit ambiguous identifiers, added a call to reconcile during the maintained-apps sync, and extended the datastore interface and mock accordingly. Added tests and a manifest check for known shared identifiers, plus a changelog entry. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42445 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] Timeouts are implemented and retries are limited to avoid infinite loops - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [ ] Confirmed that the fix is not expected to adversely impact load test results - [ ] Alerted the release DRI if additional load testing is needed ## Database migrations - [ ] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [ ] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [ ] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [ ] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [ ] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [ ] Verified that any relevant UI is disabled when GitOps mode is enabled ## fleetd/orbit/Fleet Desktop - [ ] Verified compatibility with the latest released version of Fleet (see [Must rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md)) - [ ] If the change applies to only one platform, confirmed that `runtime.GOOS` is used as needed to isolate changes - [ ] Verified that fleetd runs on macOS, Linux and Windows - [ ] Verified auto-update works from the released version of component to the new version (see [tools/tuf/test](../tools/tuf/test/README.md)) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes * Fixed an issue where macOS apps sharing a bundle identifier (e.g., Firefox and Firefox ESR) would incorrectly report each other as already installed and could have their software titles unexpectedly changed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
20af889c56 | Add regression test for #46604 (#46613) | ||
|
|
997a4097c4 | Add docs for chart bounded context (#47877) | ||
|
|
6336443f37 | Report mobile devices in "hosts online" (#47222) | ||
|
|
82f7405f19 | Allow setting default vuln chart filters via GitOps (#47634) | ||
|
|
b784de80b0 |
Cancel software install records instead of deleting when an installer is deleted (#48127)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #47348 Does two things: - Removes the software_installers and software_titles joins. These could be null, but we would still want to create software install records for these installs even if the installer or title were deleted. - Changes every case where a host_software_installs is deleted into setting the canceled flag to 1 on that row. It also updates some comments. `deletePendingSoftwareInstallsForPolicy` had a comment that said it should be called _after_ deleting a policy, but that seems wrong and was not actually reflected in the code even when it was originally added. It should be called _before_ deleting the policy so that the siua.policy_id column is still available before it gets set to null by the FK constraint. Same for `deletePendingHostScriptExecutionsForPolicy`. Also removes the `NOTE(mna): ...` comment, because it seems like the code works as intended and only the comments were wrong. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] Timeouts are implemented and retries are limited to avoid infinite loops - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Prevented a 500 error when late software installation results are reported after the related installer has been deleted. * Pending software install entries are now preserved as **canceled** (instead of being deleted) during installer, policy, and batch update flows, keeping results consistent. * Improved correctness of intermediate failure recording and setup-experience deletion behavior, including distinguishing **canceled** vs **removed** installs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
705f4db3a3 |
Fix data race in CVE tests (#48070)
Fixes: https://github.com/fleetdm/fleet/actions/runs/28003942578. New run: https://github.com/fleetdm/fleet/actions/runs/28026451929. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Improved test fixture logic for more reliable test execution. **Note:** This release contains internal testing improvements with no end-user-facing changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
25973b3974 |
Authorize query read when creating a policy from query_id
When creating a fleet or global policy from an existing query (via query_id) load the referenced query and authorize ActionRead on it before its fields are copied, in both fleet policies and global policies. |
||
|
|
a93c61722d |
Android certs support all idp vars (#48100)
**Related issue:** Resolves #36774 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Certificate templates now support additional variables for subject names and SANs, including host platform and identity-provider-derived fields such as username (local part), groups, department, and full name. * **Bug Fixes** * Improved validation and error handling for missing host or identity-provider data during template variable substitution. * **Tests** * Expanded coverage for supported/unsupported variables, correct placeholder replacement, caching behavior, and RFC 4514 escaping in DN-related values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
81f2edec65 |
Improve fleet scope validation for software title lookups (#48034)
## Summary Ensures that `SoftwareTitleByID` validates fleet scope for all non-nil `team_id` values, including zero. Previously the scope check was only applied when `team_id > 0`. ## Reproduction Added a unit test (`TestSoftwareTitleByIDTeamIDZero`) that sets up a fleet-scoped user on fleet 1, then calls `SoftwareTitleByID` with `team_id=0`. Before this change, the call succeeded. After, it correctly returns 403. Also confirmed that a global admin calling with `team_id=0` still succeeds, and that all existing `TestServiceSoftwareTitlesAuth` subtests continue to pass. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Enhanced fleet scope validation for software title lookups, including correct handling when a team scope value is set to `0`. * **Tests** * Added unit test coverage for software title retrieval authorization behavior when the team scope value is `0`. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b55d45806c |
Align software category name comparison with DB (#47983)
Normalize category name comparisons to match MySQL's utf8mb4_unicode_ci collation (case-insensitive and ignoring Unicode variation selectors) to avoid duplicate-entry errors. Add normalizeSoftwareCategoryName and SoftwareCategoryNamesEqual (server/fleet/software.go) and use them where categories are deduped (ee/server/service/software_installers.go). Make batch insert idempotent by using ON DUPLICATE KEY UPDATE in the MySQL batch insert (server/datastore/mysql/software.go). Add tests for name-equality behavior and idempotent batch inserts (server/fleet/software_test.go, server/datastore/mysql/software_test.go). This prevents collisions between visually identical emoji forms (e.g. with/without U+FE0F) and tolerates concurrent/default category inserts. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #47981 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] Timeouts are implemented and retries are limited to avoid infinite loops - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [ ] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [ ] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [ ] Confirmed that the fix is not expected to adversely impact load test results - [ ] Alerted the release DRI if additional load testing is needed ## Database migrations - [ ] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [ ] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [ ] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [ ] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [ ] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [ ] Verified that any relevant UI is disabled when GitOps mode is enabled ## fleetd/orbit/Fleet Desktop - [ ] Verified compatibility with the latest released version of Fleet (see [Must rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md)) - [ ] If the change applies to only one platform, confirmed that `runtime.GOOS` is used as needed to isolate changes - [ ] Verified that fleetd runs on macOS, Linux and Windows - [ ] Verified auto-update works from the released version of component to the new version (see [tools/tuf/test](../tools/tuf/test/README.md)) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed GitOps runs failing due to software category duplicate-entry errors when names contain certain Unicode characters (e.g., emoji variation selectors). * **Improvements** * Enhanced software category deduplication to properly handle Unicode-equivalent names. * Made batch category insertion operations idempotent to prevent duplicate-key errors. * **Tests** * Added tests for software category idempotency and Unicode character handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8e94d5e820 |
Remove unused migration tests (#48074)
This is just removing tests that are never run (always skipped), see: https://github.com/fleetdm/fleet/blob/7fa7e8f26d108c9421ed7b8e83ffde4468dab6ba/server/datastore/mysql/migrations/tables/migration_test.go#L101-L110 - [X] QA'd all new/changed functionality manually |
||
|
|
a972ca21b0 |
Add "Support" default software category (#47923)
**Related issue:** Resolves #48064 Adds a new default self-service software category, rendered as **🛟 Support**, alongside the existing six defaults (Browsers, Communication, Developer tools, Productivity, Security, Utilities). ## What changed **Backend (Go)** - `server/fleet/software.go` — added `🛟 Support` to `DefaultSelfServiceCategoryNames` (seeds new fleets) and `"Support": "🛟 Support"` to `LegacySoftwareCategoryNames` (so GitOps/FMA manifests can reference the non-emoji `Support`). - New migration `20260619120000_AddSupportSoftwareCategory` — inserts the global default (`team_id=0`) and backfills every existing fleet. Timestamps pinned for deterministic schema dumps; `INSERT IGNORE` guards the `(team_id, name)` unique key. - `schema.sql` regenerated via `tools/dbutils`. - `cmd/maintained-apps/main.go` — added `Support` to the FMA validator allowlist. **Frontend** - `frontend/interfaces/software.ts` — added `"Support"` to the `SoftwareCategory` union. - `frontend/pages/hosts/details/cards/Software/SelfService/helpers.ts` — added `{ label: "🛟 Support", value: "Support" }` to the fallback list. **Docs** - `docs/Configuration/yaml-files.md` — documented `Support` as a supported GitOps category. ## Note on sort order `ListSoftwareCategories` does `ORDER BY name` under `utf8mb4_unicode_ci`, which sorts by the word after the (ignorable) emoji. `🛟 Support` is therefore placed between `🔐 Security` and `🛠️ Utilities`. # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually Verified against a dockerized MySQL: - Migration test `TestUp_20260619120000` - `TestSoftware/SoftwareCategoryCRUD` (order-sensitive assertion) - `TestSelfServiceCategoriesCRUD` + `TestDeviceSelfServiceCategories` integration tests - `cmd/maintained-apps` tests, ee categories test, `go vet`, `make lint-go-incremental` (0 issues) - `tools/dbutils` schema regeneration matches ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [x] Verified the setting is documented (GitOps `categories` supported values in `docs/Configuration/yaml-files.md`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Introduced the "🛟 Support" category as a new self-service software classification option. Users can now better organize support-related applications within their software catalog. The category is available globally across all teams, providing improved organization and discovery capabilities for support applications alongside utilities and other existing software categories. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
eb48eb37f8 |
Made team label membership checks more robust
When creating a manual label, make the checks around manual host more robust. |
||
|
|
47db1a63bd |
Fix host software details dropping pending installs/uninstalls (#47954)
**Related issue:** Related to #47839 Follow-up to #47949 (same root cause, same issue). That PR fixed the OR-dominance drop out in the software *title summary* queries; this applies the same fix to the four per-host queries behind a host's *software details* page. A host with more than one queued install or uninstall for the same installer, VPP app, or in-house app could disappear from its software details page: the old self anti-join's `(priority < OR created_at >)` predicate let two rows eliminate each other, so neither survived. This rewrites those four queries (`hostSoftwareInstalls`, `hostSoftwareUninstalls`, `hostVPPInstalls`, `hostInHouseInstalls`) to rank with `ROW_NUMBER()` and keep one row per item. No performance change — these are per-host queries. # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] `SELECT *` is avoided and SQL injection is prevented (named placeholders used for all values in the modified statements). ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed an issue where installers, VPP apps, and in-house apps could disappear from a host's software details page when multiple install or uninstall actions were queued for the same item. * **Tests** * Added regression tests to prevent this issue from recurring. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cf32a02fbc |
Bump migrations that conflict with v4.87 (#48002)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves migration failure dsicussed here: https://fleetdm.slack.com/archives/C019WG4GH0A/p1782131309693279 20260610172952_AddHasACMEPayloadToHostMDMAppleProfiles.go was backported to v4.87 but had a newer timestamp so would have conflicted with migrations merged in the frist few days of v4.89 development # Checklist for submitter If some of the following don't apply, delete the relevant line. No changes file as this is ultimately an `unreleased-bug` - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for policy gating in setup workflows. * Added support for BYOD fleet and enrollment tracking capabilities. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f138f6b646 |
Fix TestUpgradeCodesFromMaintainedApps after Cloudflare WARP rename (#47953)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # Cloudflare WARP was renamed to Cloudflare One, and this test used it's name in the fleet_maintained_apps table # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] Timeouts are implemented and retries are limited to avoid infinite loops - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually N/A but needed for CI check <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated Windows WARP integration tests to use current product naming conventions when querying fleet-maintained applications, ensuring test accuracy across both verification and setup phases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3f5b58888f |
Fix software title page timeout for large upcoming-activity backlogs (#47949)
**Related issue:** Resolves #47839 The software title details page (`GET /api/v1/fleet/software/titles/{id}`) could take minutes to load and return a 500 or 502 when an installer, VPP app, or in-house app was scoped to many hosts. The cause was the status summary query. To find each host's most recent pending activity, it joined `upcoming_activities` to itself, and an `OR` in the join condition stopped MySQL from using an index. The query got much slower as the pending backlog grew. This rewrites the query in all three summary functions (`GetSummaryHostSoftwareInstalls`, `GetSummaryHostVPPAppInstalls`, `GetSummaryHostInHouseAppInstalls`) to use a `ROW_NUMBER()` window function. It filters to the installer or app first, then picks each host's most recent activity, which removes the self-join. It also fixes a related bug where the old `OR` condition could drop a host from the counts. Verified live against a 6,000-host backlog. The page went from ~12.7s to ~1.1s with identical status counts. # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-chan ges.md#changes-files) for more information. - [x] `SELECT *` is avoided and SQL injection is prevented (named placeholders used for all values in the modified statements). ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually ## Before (reproduction): [before.webm](https://github.com/user-attachments/assets/f03154d5-6062-42e3-81d3-ce33b0809145) ## After (fix): [after.webm](https://github.com/user-attachments/assets/b6d1ce53-7778-4023-84b7-56c49d846649) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed software title details pages timing out for installers, VPP apps, and in-house apps when hosts have large backlogs of pending activities. * Improved pending software install status selection to prevent hosts from being dropped or counted inconsistently when multiple upcoming activities exist. * **Tests** * Added regression coverage for upcoming-per-host counting without dropouts when multiple queued activity entries share the same host and app context. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0301aea831 |
Add more filtering to Vulnerability Exposure chart (frontend) (#47674)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** For #44746 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually - [x] Changing the filters in the UI causes the related API params to be set - [x] Changing the software filters causes the "filtered" tooltip to show up and include info about software filters - [x] Changing the host filters causes the "filtered" tooltip to show up and include info about host filters - [x] Changing both host and software filters causes the "filtered" tooltip to show up and include info about both filters - [x] CVE search works and utilizes infinite scroll <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Added software category filtering options to vulnerability charts. * Added EPSS range filtering with validation to refine results. * Added known exploit toggle and CVE exclusion capabilities. * Improved filter status display with tabbed interface. * **Tests** * Added comprehensive test coverage for software filtering and validation logic. * **Style** * Enhanced filter UI styling and interactivity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fcd99a1842 |
Fix GenerateHostStatusStatistics query so that hosts enrolled chart is accurate (#47791)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #47605 # Details The queries in GenerateHostStatusStatistics (which feeds the host_summary API) were incorrectly filtering out hosts that had been removed from ABM from the denominator (i.e. "total hosts") count, while keeping them in the per-platform counts. This PR fixes the query so that the sum of the platforms matches the total. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually **Before** <img width="499" height="420" alt="image" src="https://github.com/user-attachments/assets/9b8d22bc-1dac-49e6-9d2f-8ce9ffda5f17" /> **After** <img width="501" height="420" alt="image" src="https://github.com/user-attachments/assets/fe3705b7-9a90-4d9c-a9dc-b04b2905f3fb" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed an issue causing incorrect platform percentage breakdowns in the "Hosts enrolled" dashboard chart. * Corrected host status calculations to ensure accurate total and per-platform host counts by properly handling device enrollment assignment records. * **Tests** * Added regression tests to validate the correct handling of device enrollment records in host status calculations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5368b99636 |
Policy status page: automation activity history, reset endpoint, and details UI
Resolves #38670 Adds the backend and frontend for the Policy status page — a historical, per-host view of policy automation outcomes — plus a way to reset a policy's results. |
||
|
|
208715e2c8 |
Update some GitOps error messages for clarity (#47134)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #45639 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [ ] QA'd all new/changed functionality manually A bit hard to replicate these ones, but they're text changes only. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved error message clarity for macOS setup assistant and bootstrap package workflows, including more precise identification of the failed operation (such as verifying or uploading) and better details for script-reading failures. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c370a9672b |
Add CVE chart filtering and non-critical CVE data collection (backend) (#47470)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #44746 # Details * Adds the ability to filter historical CVE data by software type, EPSS, CVSS, CVE ID (exclude only) and "has known exploit" * Hard-codes the CVSS filter to 9.0+ for now, since that's the only data that's been collected thus far * Un-gates the collection code so that it will collect CVE data for _all_ severities (but still in the restricted set of software) Related PRs [update the front-end](https://github.com/fleetdm/fleet/pull/47674) to allow sending these filters, and [update GitOps](https://github.com/fleetdm/fleet/pull/47634) to allow changing the default filters. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [X] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually ### Manual test plan — CVE chart filtering (backend smoke test) #### Setup - Premium dev server running with a few hosts carrying vulnerable software (so `cve_meta` / `software_cve` / `operating_system_vulnerabilities` are populated) - Chart data present — collector ran once, or seeded: `go run ./tools/charts-backfill --dataset cve --use-tracked-cves --days 7` - API token exported and helper set: ```bash BASE=https://localhost:8080/api/v1/fleet/charts peak() { curl -sk -H "Authorization: Bearer $TOKEN" "$BASE/$1" | jq '[.data[].value] | max'; } #### Checks (compare against the no-filter baseline) - [x] Baseline returns data — GET /charts/cve?days=7 returns a data series; .filters is empty/default - [x] Severity force-pinned to critical — cve?days=7 and cve?days=7&severity_min=0&severity_max=10 give identical peaks (no low-severity leak; client severity ignored) - [x] Category narrowing — software_categories=browsers ≤ baseline; software_categories=os,browsers,office,adobe == baseline - [x] OS category includes kernel — software_categories=os returns OS-vuln + Linux-kernel CVE counts - [x] Known-exploit narrowing — known_exploit=true ≤ baseline - [x] EPSS narrowing — epss_min=0.9 ≤ baseline; epss_min=0&epss_max=1 == baseline (EPSS is 0.0–1.0 on the API) - [x] Exclude is subtractive + tolerant — excluding a visible CVE lowers/keeps counts; exclude_cves=CVE-0000-00000 == baseline (no-op) - [x] Filters echo back — filtered requests return applied values under .filters - [x] Uptime untouched — GET /charts/uptime?days=7 returns its normal series - [x] Free-tier safety (optional) — on non-Premium, /charts/cve returns an empty series, no error - [x] > 0 rows from: SELECT COUNT(DISTINCT scd.entity_id) AS below_critical FROM host_scd_data scd JOIN cve_meta cm ON cm.cve = scd.entity_id WHERE scd.dataset='cve' AND cm.cvss_score < 9.0; - (confirms lower-severity CVEs are stored) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary of changes * **New Features** * Added advanced CVE chart request filters: software categories, known-exploit flag, EPSS min/max, severity min/max, and excluded CVEs. * Expanded CVE chart coverage to use the full “collectible” CVE set, with filtering applied when serving chart data. * **Tests** * Added coverage for collecting collectible CVEs and resolving chart entities based on filter combinations and exclusions. * **Chores** * Updated CVE chart backfill to use collectible CVE discovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ad52492c78 |
Undo rename from utilities to support (#47881)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # ## Testing - [ ] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually Tested with fleet maintained apps and VPP in UI and gitops For unreleased bug fixes in a release candidate, one of: - [ ] Confirmed that the fix is not expected to adversely impact load test results - [ ] Alerted the release DRI if additional load testing is needed ## Database migrations N/A since this is just editing the existing migration - [ ] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [ ] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [ ] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [x] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [x] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - newly added custom category, or default category, was cleared if was not in the yaml file - [ ] Verified that any relevant UI is disabled when GitOps mode is enabled <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Corrected the “Productivity” category emoji/name and the “Utilities” category emoji/name across the system for consistent display and behavior. * **Tests** * Updated unit, integration, and handler tests to expect the corrected category strings and delete-button labels. * **Chores** * Refreshed database seed data and migration/test expectations to align default and per-team category names, preserving IDs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2044c77243 |
Improve session handling during password reset (#47860)
# Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Summary Align `PerformRequiredPasswordReset` with the other two password-change paths (`ChangePassword` and `ResetPassword`) by clearing sessions on completion. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually - [x] Confirmed that the fix is not expected to adversely impact load test results <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Password reset process now clears all active sessions. When a required password reset is enforced, users are automatically logged out of all active sessions and must re-authenticate with their new password. This improves security by ensuring users cannot maintain access to the account during a password reset operation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
013ccf406e |
45640 Add activity feed entry when a custom Apple or Windows MDM command is run (#47743)
**Related issue:** Resolves #45640 - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Running custom MDM commands on Apple or Windows devices now creates activity log entries that appear in both the global activity feed and host-specific activity feeds. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
97f28d632b |
Fixed Windows MDM not re-installing fleetd (#47852)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #47259 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Windows MDM now properly re-installs fleetd when a device is wiped and re-enrolled via Autopilot/Entra, preventing the Enrollment Status Page from hanging. * **Tests** * Added comprehensive test coverage for fleetd presence detection across multiple enrollment scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e44d6f0136 |
Miscellaneous API doc fixes (#47884)
A bunch of little things I found while working on an unrelated PR awhile back (handled here to reduce API design diff): + Fix broken link formatting + Finish up incomplete "Cancel batch script docs" + Fix ordering of "Get vulnerability" sections + Remove note about feature being GitOps-only (no longer true) + Add missing link to section contents + Add missing endpoint to `api_endpoints.yml` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added ability to cancel running batch script executions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b32ceb72e1 |
Added variables in Android configuration profiles (#47750)
**Related issue:** Resolves https://github.com/fleetdm/fleet/issues/41968 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [ ] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for using Fleet variables (`$FLEET_VAR_HOST_*`) in Android configuration profiles, enabling per-host dynamic value substitution during deployment. * **Improvements** * Strengthened Android profile validation to reject unsupported Fleet variables and prevent invalid placements (for example, using variables in JSON object keys or non-string fields). * Enhanced deployment behavior when variables can’t be resolved for a host, marking affected profiles as delivery failed and avoiding partial policy application. * Improved Android per-host rollout by applying installs in staggered batches for smoother throughput. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ad22a31d96 |
Docs: Mark remaining experimental endpoints/parameters as stable (#47848)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **`api_endpoints.yml`** * Added new Fleet API documentation entries for creating configuration profiles and updating setup experience. * Added documentation for creating Android web apps. * Expanded Android Enterprise coverage by adding a new “Get Android Enterprise” entry (kept disabled). * Added complete documentation for certificate authority management, including list, retrieve, update, and delete. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d26d298e2 |
fixed update teams not updating appconfig, and team delete not cleaning up appconfig (#47826)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Unreleased bugs while going through test plan # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Apple Business Manager (ABM) token team assignments now stay synchronized when team defaults change across BYOD, macOS, iOS, and iPadOS. * “No team” selections are now saved as cleared (empty) assignments for cleaner configuration output. * Improved ABM token cleanup during team deletion to remove references tied to the deleted team. * **Tests** * Added/extended coverage for ABM token team update behavior (including invalid team handling and nil inputs) and deletion cleanup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a619660636 |
Fix out-of-order Windows MDM fleetd install commands (#47683) (#47736)
The fleetd install Add and Exec were enqueued as two separate Windows MDM commands ordered only by created_at (1-second granularity), so they could be delivered Exec-before-Add. The device then ran DownloadInstall on a not-yet-created node, returned 404, and fleetd never installed, which could hang the Windows Autopilot Enrollment Status Page. Enqueue them as a single command so Add always precedes Exec. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #47683 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed intermittent fleetd installation failures during Windows MDM enrollment that could cause the Windows Autopilot Enrollment Status Page to hang. * **Documentation** * Updated Windows MDM fleetd installation documentation to reflect the fix. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a2757a1d7c |
Don't require end user auth on orbit re-enrollment (#46300) (#47740)
Windows and Linux hosts that had already orbit-enrolled were prompted for end user authentication (an SSO browser tab) when fleetd re-enrolled after a service restart, node key file loss, or osquery DB rebuild. Hosts enrolled before EUA was enabled have no host_mdm_idp_accounts row, so the service-layer EUA gate treated every re-enroll like a brand-new device. Before returning END_USER_AUTH_REQUIRED, EnrollOrbit now checks whether a host matching the enrollment identifiers already exists and previously held an orbit node key (HostPreviouslyOrbitEnrolled, reusing matchHostDuringEnrollment's semantics). If so, the re-enroll proceeds without prompting. Genuinely new devices, and hosts moved to a different Fleet server, are still gated. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #46300 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit **Bug Fixes** * Fixed unnecessary end-user authentication prompts for Windows and Linux hosts during fleetd re-enrollment after a service restart. Previously enrolled devices can now re-enroll without being prompted for SSO authentication, while new devices still require the appropriate authentication. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b28e6ceaaf |
filter OS versions platforms (#47742)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #46322 I'm not sure why, but it already had pagination? I suspect the frontend filtering was breaking it, so I moved the platform filtering to the backend via the `MatchQuery` query param. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Fixed pagination for OS version lists containing more than 8 entries. * Improved OS version filtering so platform queries are applied consistently before pagination, yielding correct results and counts. * Enhanced OS version list coverage with a new test validating platform-specific filtering and ordering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e4025a8193 |
Always display Windows ESP error when software install fails (#47522)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #45948 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Timeouts are implemented and retries are limited to avoid infinite loops ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Updated Windows ESP failure copy with clearer “Reset your device to try again…” wording. * When not all apps are required, added a **“Reset PC and Continue Anyway”** soft-block option and continuable error text that lists failed app names with truncation (“N more”). * **Bug Fixes** * Improved SyncML generation by escaping XML-sensitive characters in embedded text. * **Tests** * Added/expanded unit and property-based tests covering continuable error formatting, soft-block behavior, and SyncML XML escaping. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
435c6e130b |
Display instructions needed for SSO-enabled accounts with fleetctl (#46768)
**Related issue:** Resolves #21818 # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. ## Testing - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The CLI now detects when SSO is enabled on the server and shows a warning directing users to authenticate with an API token (with guidance link) instead of email/password. * **Bug Fixes** * Authentication error messaging is now SSO-aware, improving guidance when credential login fails. * **Tests** * Added coverage to verify the authentication guidance changes correctly based on whether SSO is enabled. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Juan Fernandez <juan@fleetdm.com> |