90 lines
3.9 KiB
Markdown
90 lines
3.9 KiB
Markdown
# Release 0.2.2
|
|
|
|
Export and naming robustness update.
|
|
|
|
Included:
|
|
|
|
- `Export-And-Publish.ps1` now treats `GpoName` and repository `PolicyName` as separate concepts.
|
|
- `PolicyName` is optional and is automatically normalized when it contains spaces, umlauts, path separators or other unsupported characters.
|
|
- The resolved repository name is printed before the AD backup and upload start.
|
|
- `-StrictPolicyName` retains fail-fast validation when automatic normalization is not desired.
|
|
- `gpoctl` validates policy and profile names locally and reports the offending value before sending an HTTP request.
|
|
|
|
# Release 0.2.1
|
|
|
|
Container deployment update.
|
|
|
|
Included:
|
|
|
|
- Root-level multi-stage `Dockerfile` for reproducible source builds.
|
|
- Root-level `compose.yml` with persistent named volume, healthcheck and log rotation.
|
|
- Non-root runtime user, read-only root filesystem, dropped Linux capabilities and `no-new-privileges`.
|
|
- Direct TLS and reverse-proxy HTTP modes using the same image.
|
|
- `.env.example`, `.dockerignore` and TLS directory guidance.
|
|
- Compatibility deployment files under `deploy/`.
|
|
|
|
Validated in the build environment:
|
|
|
|
- Compose YAML parsing and environment interpolation.
|
|
- Dockerfile structure and build-context completeness.
|
|
- Native Go build and complete Go test suite.
|
|
|
|
A Docker daemon was not available in the build environment, so an actual image build and container startup could not be executed here.
|
|
|
|
# Release 0.2.0
|
|
|
|
Web administration release.
|
|
|
|
Included:
|
|
|
|
- Embedded, dependency-free German WebUI served directly by `gpo-server` under `/ui/`.
|
|
- Dashboard for policy, version, profile and client health metrics.
|
|
- Browser upload workflow with semantic duplicate detection, notes and forced versions.
|
|
- Full policy/version browsing, administrative artifact retrieval and guarded deletion.
|
|
- Ordered profile editor with `latest` or pinned versions and drag-equivalent move controls.
|
|
- Searchable and filterable client status view.
|
|
- Stateless eight-hour `HttpOnly` admin sessions signed with the admin secret.
|
|
- CSRF protection for all cookie-authenticated mutations.
|
|
- Restrictive Content Security Policy and additional browser security headers.
|
|
- New API deletion endpoints for policies, versions, profiles and stored client reports.
|
|
- Conflict protection for policy/profile references and pinned versions.
|
|
|
|
Validated in the build environment:
|
|
|
|
- `go test -race ./...`
|
|
- `go vet ./...`
|
|
- JavaScript syntax validation with Node.js.
|
|
- Linux amd64 and Windows amd64 builds.
|
|
- HTTP end-to-end flow covering embedded assets, login cookie, CSRF enforcement, Bearer-token compatibility, policy upload, profile creation and client reports.
|
|
|
|
Browser screenshot automation could not be executed because the managed Chromium installation blocks navigation to local test servers with `ERR_BLOCKED_BY_ADMINISTRATOR`. The UI assets and browser-facing API were still exercised through unit and HTTP integration tests.
|
|
|
|
# Release 0.1.0
|
|
|
|
Initial MVP release.
|
|
|
|
Included:
|
|
|
|
- File-backed Go server with admin/client authentication.
|
|
- Multiple policy objects and immutable versions.
|
|
- Semantic change detection for GPO payload files.
|
|
- Ordered profiles with `latest` or pinned versions.
|
|
- HMAC-signed manifests and SHA-256 artifact verification.
|
|
- Windows agent with safe extraction, local LGPO backup, ordered apply, rollback attempt and status reporting.
|
|
- Admin CLI and PowerShell deployment scripts.
|
|
- Docker, systemd and example configurations.
|
|
|
|
Validated in the build environment:
|
|
|
|
- `go test -race ./...`
|
|
- `go vet ./...`
|
|
- Linux amd64 builds.
|
|
- Windows amd64 cross-builds.
|
|
- End-to-end server/API test covering upload, duplicate detection, forced versions, `latest` profile resolution, HMAC manifest signature validation and ETag/304 handling.
|
|
|
|
Not validated in this Linux build environment:
|
|
|
|
- Execution of `LGPO.exe` on a real Windows Server.
|
|
- Scheduled Task registration on each supported Windows Server version.
|
|
- Functional equivalence of every possible Group Policy client-side extension.
|