Prefer to render enrollment instructions by platform tab - #51593
Draft
Leanngove wants to merge 2 commits into
Draft
Prefer to render enrollment instructions by platform tab#51593Leanngove wants to merge 2 commits into
Leanngove wants to merge 2 commits into
Conversation
…ing (#50883) The Add hosts modal now passes a `platform` query param on each tab's enrollment link, and enroll-ota.html prefers it over user-agent guessing when present (falling back to guessing for links without it, e.g. an admin previewing an Android link on a desktop browser no longer sees "Apple MDM is turned off"). The platform hint also survives the IdP SSO redirect round-trip. Also reworks the QR handoff affordance: removed from the macOS page, added to the Android and iOS/iPadOS pages so a desktop browser (Mac or Windows) previewing those links gets a QR-only view to hand off to the actual device, instead of written steps meant for that device.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #51593 +/- ##
==========================================
+ Coverage 68.31% 68.59% +0.28%
==========================================
Files 3951 3969 +18
Lines 252699 253743 +1044
Branches 13512 13885 +373
==========================================
+ Hits 172627 174056 +1429
+ Misses 64633 64247 -386
- Partials 15439 15440 +1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Add hosts modal now passes a
platformquery param on each tab's enrollment link, and enroll-ota.html prefers it over user-agent guessing when present (preventing an admin previewing an Android link on a desktop browser seeing "Apple MDM is turned off", for example)The platform param also survives the IdP SSO redirect round-trip
Also removes QR code from MacOS enrollment page
QR code is added to the Android and iOS/iPadOS pages so a desktop browser (Mac or Windows) previewing those links gets a QR-only view to hand off to the actual device, instead of written steps meant for that device
Enrollment instruction matrix
What
/enroll(enroll-ota.html) renders for every combination of Android MDM state, Apple MDM state, the device opening the link, whether the link carries aplatformquery parameter, and how the separatefully_managed=trueflag interacts with all of it.Legend: 🛑 error only · ✅ full written instructions · 📱 QR-only (no written steps)
Links that include a
platformparameter(generated by the Add hosts modal — one per tab)
platform=androidplatform=ios/ipadplatform=macosplatform=androidplatform=ios/ipadplatform=macosplatform=ios/ipadplatform=androidLinks with no
platformparameter (guessed from the user agent)Notes
platformparameter (orfully_managed) matches the device actually opening the link. Whatever the query params say is what renders, regardless of the real device — e.g. aplatform=androidlink opened on an actual iPhone renders the Android template (Enroll button and all) directly on that iPhone.Related issue: Resolves #50883
Checklist for submitter
If some of the following don't apply, delete the relevant line.
Changes file added for user-visible changes in
changes/,orbit/changes/oree/fleetd-chrome/changes.See Changes files for more information.
Input data is properly validated,
SELECT *is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters.Timeouts are implemented and retries are limited to avoid infinite loops
If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes
Testing
Added/updated automated tests
Where appropriate, automated tests simulate multiple hosts and test for host isolation (updates to one hosts's records do not affect another)
QA'd all new/changed functionality manually
For unreleased bug fixes in a release candidate, one of:
Database migrations
COLLATE utf8mb4_unicode_ci).New Fleet configuration settings
If you didn't check the box above, follow this checklist for GitOps-enabled settings:
fleetctl generate-gitopsfleetd/orbit/Fleet Desktop
runtime.GOOSis used as needed to isolate changes