v0.1.3
psRadiantOne v0.1.3
First release. Everything below is new, so the entries are grouped by the area of the RadiantOne API
they cover rather than split into added, changed and fixed.
Added
Session & authentication
Connect-R1Session/Disconnect-R1Session/Get-R1Session,Update-R1AuthTokenand
Reset-R1Password.-BaseURItakes the API endpoint address, which on a cloud tenant is the
control panel address with/apiappended; both are listed in the EOC Application Endpoints panel.
An expired password is surfaced byConnect-R1Sessionas the reset information the API returns,
whoseresetTokendrivesReset-R1Password.Disconnect-R1Sessiontakes-Forceto clear the local session where the token could not be
revoked. Revoking requiresSCOPE_AUTH_TOKEN_REVOKE; without it the token stays valid, so by
default the failure is reported and the session left in place, keeping the revocation retryable.Test-R1AdapTokenandTest-R1CallerPrivilege.Get-R1AccessToken,New-R1AccessToken,Remove-R1AccessToken. The token value is returned only
when it is created and cannot be retrieved again.
Users, roles and the directory manager
Get-R1FIDUser,New-R1FIDUser,Set-R1FIDUser,Remove-R1FIDUserandSet-R1FIDUserRole.
Get-R1FIDUserfollows the API's cursor pagination and returns every page. Roles may be supplied
when creating or updating a user, which the API accepts despite the schema marking them read-only.Get-R1FIDRole,New-R1FIDRole,Set-R1FIDRole,Remove-R1FIDRole.Get-R1DirectoryManager/Set-R1DirectoryManager,Get-R1SpecialGroup/Set-R1SpecialGroup.
Security settings
- Access control:
Get-R1AccessControlSetting/Set-R1AccessControlSetting,Get-R1Aci,
New-R1Aci,Set-R1Aci,Remove-R1Aci,Get-R1AciLocationandTest-R1Aci. - Attribute encryption:
Get-R1AttributeEncryption/Set-R1AttributeEncryption,
Get-R1AttributeEncryptionKmsSetting/Set-R1AttributeEncryptionKmsSettingand
Update-R1AttributeEncryptionKey. - Client certificate truststore:
Get-R1TruststoreCertificate,Add-R1TruststoreCertificate,
Remove-R1TruststoreCertificateandExport-R1TruststoreCertificate. - External token validators:
Get-R1TokenValidator,New-R1TokenValidator,Set-R1TokenValidator
andRemove-R1TokenValidator. - OIDC providers:
Get-R1OidcProvider,New-R1OidcProvider,Set-R1OidcProvider,
Remove-R1OidcProvider,Get-R1OidcLoginInfo,Get-R1OidcDiscoveryEndpoint,
Get-R1OidcDiscoveryInfoandGet-R1OidcScopesClaim. - Audit logging:
Get-R1AuditLogSetting/Set-R1AuditLogSettingandExport-R1AuditLog. - Password policies:
Get-R1PasswordPolicy,Set-R1PasswordPolicy,Remove-R1PasswordPolicy,
Get-R1PasswordDictionary,Add-R1PasswordDictionaryWord,Remove-R1PasswordDictionaryWord,
Get-R1PasswordEncryptionandTest-R1PasswordStrengthRule.
Platform settings
- Configuration pairs:
Get-/Set-R1ChangeLogSetting,Get-/Set-R1GlobalAttributeSetting,
Get-/Set-R1LdapClientAccess,Get-/Set-R1LdapClientAccessMapping,
Get-/Set-R1RestClientAccess,Get-/Set-R1ControlPanelConfiguration,
Get-/Set-R1GlobalLimit,Get-/Set-R1AccessRegulationLimit,Get-/Set-R1BackendLimit,
Get-/Set-R1CustomLimitandGet-/Set-R1Feature. - Log settings:
Get-R1LogSetting/Set-R1LogSetting, addressing a component, a data source or a
plugin, andGet-R1LogTimezone. - Identity observability:
Get-/Set-R1PipelineConnectorConfig,Get-R1PipelineConnectorType,
Reset-R1PipelineConnector,Suspend-R1Pipeline,Resume-R1Pipelineand
Invoke-R1PipelineConnectorScript. - Entry statistics:
Get-R1Operation,New-R1Operation,Stop-R1Operation,Resume-R1Operation
andGet-R1Statistic. - Licensing:
Get-R1License,Set-R1LicenseandRead-R1License. - Deployment and dashboard readers:
Get-R1Dashboard,Get-R1DashboardLink,Get-R1ProductVersion,
Get-R1ServiceSummary,Get-R1WhatsNew,Get-R1SaasConfiguration,Get-R1LoginPageInfo,
Get-R1ControlPanelMessage.
Directory namespace
- Global namespace settings:
Get-R1GlobalInterceptionSetting/Set-R1GlobalInterceptionSetting,
Get-R1GlobalSpecialAttribute/Set-R1GlobalSpecialAttributeandGet-R1GlobalDynamicGroup. - Naming contexts:
Get-R1NamingContext,Get-R1NamingContextChild,New-R1NamingContext,
Remove-R1NamingContext,Enable-R1NamingContext/Disable-R1NamingContext,
New-R1NamingContextLabel,New-R1NamingContextContent,New-R1NamingContextContainerand
New-R1NamingContextLink. The two list commands follow the offset pagination of the API and return
every page. No total is reported by the API, so the end of a collection is recognised by a page
holding fewer nodes than were asked for. - Interception scripts:
Get-R1InterceptionScript,Import-R1InterceptionScript,
Remove-R1InterceptionScript,Get-R1InterceptionScriptLibrary,
Import-R1InterceptionScriptLibrary,Remove-R1InterceptionScriptLibrary,
Get-R1GlobalInterceptionScript/Set-R1GlobalInterceptionScript,
Test-R1InterceptionScriptCodeandNew-R1InterceptionScriptJar. The two upload commands take a
local file path and send it as multipart form data, which works on Windows PowerShell as well as
PowerShell 7. - Namespace utilities:
Test-R1LdapFilter,Test-R1ComputedAttributeName,
Test-R1JoinCondition,Get-R1JoinCondition,Get-R1DynamicGroupFormatand
Get-R1LinkedAttributeDefault. The three Test commands return a boolean; where the API also
reports why a value was rejected, that reason is written to the verbose stream. - Naming context special attributes, virtual tree and relationship tree:
Get-R1NamingContextSpecialAttribute/Set-R1NamingContextSpecialAttribute,
Get-R1NamingContextVirtualTreeProperty/Set-R1NamingContextVirtualTreePropertyand
Get-R1NamingContextRelationshipTree. - Namespace views:
Get-R1NamespaceViewandRemove-R1NamespaceView.
Directory schema
- Object classes:
Get-R1DirectoryObjectClass,New-R1DirectoryObjectClass,
Set-R1DirectoryObjectClass,Remove-R1DirectoryObjectClassandGet-R1DirectoryObjectClassParent. - Attributes:
Get-R1DirectoryAttribute,New-R1DirectoryAttribute,Set-R1DirectoryAttribute,
Remove-R1DirectoryAttributeandGet-R1DirectoryAttributeSyntax.Get-R1DirectoryAttribute
returns attribute names by default and full definitions when-includeAllPropertiesis specified,
following the form the API reports in its response. - Schema files:
Get-R1DirectorySchemaFile,Export-R1DirectorySchemaFile,
Import-R1DirectorySchemaFileandRemove-R1DirectorySchemaFile. Import takes either a local file,
sent as multipart form data, or the name of a file already on the server.
Data catalog
- Schemas:
Get-R1Schema,New-R1Schema,Set-R1Schema,Remove-R1Schema,
Get-R1SchemaFullObject/Set-R1SchemaFullObject,Get-R1SchemaAssociatedView,
New-R1GeneratedSchema,Get-R1PublishedSchemaandPublish-R1Schema.
Set-R1SchemaFullObjectupdates a schema together with its tables, fields and relationships in one
request.Publish-R1Schemareplaces the whole published set, so a name left out is unpublished. - Schema tables and relationships:
Get-R1SchemaTable,New-R1SchemaTable,Set-R1SchemaTable,
Remove-R1SchemaTable,Add-R1SchemaTable,Get-R1SchemaTableField/Set-R1SchemaTableField,
Get-R1SchemaRelationship,New-R1SchemaRelationship,New-R1RecursiveSchemaRelationship,
Set-R1SchemaRelationship,Remove-R1SchemaRelationship,Get-R1SchemaRelationshipTree,
Merge-R1SchemaObjectandNew-R1SchemaDerivedView.Add-R1SchemaTableappends tables by name;
Set-R1SchemaTableFieldreplaces the whole field collection. - Data sources:
Get-R1DataSource,New-R1DataSource,Set-R1DataSource,Remove-R1DataSource,
Copy-R1DataSource,Search-R1DataSource,Test-R1DataSourceConnection,Get-R1DataSourceObject,
Get-R1DataSourceTable,Get-R1DataSourceGroup,Add-R1DataSourceSchemaLink,
Remove-R1DataSourceSchemaLink,Import-R1DataSourceandExport-R1DataSource.
New-R1DataSourcehas a parameter set per kind of source: LDAP, database and custom.
The API does not return the bind password, soSet-R1DataSourcesends null rather than the empty
string it reads back, which the API documents as leaving the stored password alone. Supply
-passwordto change it, or-useExistingCredentialsto keep every stored password. - Data source types and plugins:
Get-R1DataSourceType,New-R1DataSourceType,
Set-R1DataSourceType,Remove-R1DataSourceType,Test-R1DataSourceType,
Get-R1DataSourcePlugin,Add-R1DataSourcePlugin,Remove-R1DataSourcePlugin,
Get-R1DataSourcePluginLibrary/Set-R1DataSourcePluginLibrary,Get-R1DataSourcePluginClass,
Import-R1DataSourceType,Get-R1DataSourceTypeImport,Complete-R1DataSourceTypeImport,
Remove-R1DataSourceTypeImport,Get-R1DataSourceTypeImportMeta,
New-R1DataSourceTypeImportMeta,Set-R1DataSourceTypeImportMeta,
Remove-R1DataSourceTypeImportMetaandExport-R1DataSourceType.
Types do not all carry the same properties, soSet-R1DataSourceTypebuilds its request from what
the API returned rather than from a fixed list. Uploading templates creates a session which is then
inspected, imported or discarded. - Libraries:
Get-R1Library,Search-R1Library,Import-R1Library,Set-R1Library,
Remove-R1Library,Clear-R1Library,Get-R1LibraryDependency/Set-R1LibraryDependencyand
Get-R1LibraryDependent. - JDBC drivers:
Get-R1JdbcDriverFile,Import-R1JdbcDriver,Remove-R1JdbcDriverand
Get-R1JdbcDriverLibrary/Set-R1JdbcDriverLibrary. - Data migration:
Get-R1MigrationPlan,New-R1MigrationPlan,Get-R1MigrationStatus,
Get-R1MigrationLog,Get-R1MigrationExport,Export-R1MigrationData,Stop-R1Migrationand
Clear-R1Migration. OnlyGet-R1MigrationStatusanswers when no operation is running; the others
report an error, so check the status first. - Private files:
Import-R1PrivateFileandRemove-R1PrivateFile. - Data preview:
Get-R1LdapDataPreview, which reads from an LDAP source without creating a schema. - Schema comparison:
Compare-R1Schemareturns the differences between a schema and its data source,
andInvoke-R1SchemaDiffapplies them, either updating the schema or saving the result as a new one.
Directory browser
- Entries:
Get-R1DirectoryEntry,New-R1DirectoryEntry,Set-R1DirectoryEntry,
Remove-R1DirectoryEntry,Rename-R1DirectoryEntry,Move-R1DirectoryEntryand
Reset-R1DirectoryEntryPassword.Get-R1DirectoryEntryboth browses and searches: supply a filter
and a scope to search, and it follows the cursor until every page has been read. - Group membership:
Get-R1DirectoryEntryMember,Set-R1DirectoryEntryMemberand
Search-R1DirectoryEntryMember. Explicit membership by default, dynamic with-Dynamic. - Saved searches:
Get-R1DirectorySearchInfo/Set-R1DirectorySearchInfo, which store the search
tabs and history the control panel shows rather than performing a search. - LDIF:
Export-R1DirectoryLdifwrites to the server,Save-R1DirectoryLdifdownloads,
Import-R1DirectoryLdiftakes a local or a server file,Get-R1DirectoryLdifFileand
Remove-R1DirectoryLdifFilemanage what is stored. Test-R1DirectoryAuthenticationandClose-R1DirectoryPagedSearch.
Task management
- Scheduler:
Get-R1TaskScheduler/Set-R1TaskScheduler,Start-R1TaskScheduler,
Stop-R1TaskSchedulerandRestart-R1TaskScheduler. - Tasks:
Get-R1Task,Set-R1Task,Remove-R1Task,Start-R1Task,Stop-R1Task,
New-R1CustomTaskandGet-R1TaskLog.
Get-R1TaskLog -Tailfollows a running log, and the endpoint does not close the response when it
reaches the end, so the request is bounded by-TimeoutSecand returns what arrived within it.
New-R1CustomTaskuploads a compiled class and a properties file together.
Configuration promotion and the file manager
- Promotion:
Get-R1PromotionState,Get-R1PromotionSetting,Start-R1PromotionStaging,
Get-R1PromotionStagedResource,Test-R1PromotionStagedResource,Clear-R1PromotionStaging,
Export-R1Configuration,Import-R1Configuration,Get-R1ConfigurationExportReportand
Get-R1ConfigurationImportReport.Import-R1Configuration -apply $falseis a dry run. - File manager:
Get-R1FileManagerDirectory,New-R1FileManagerDirectory,
Remove-R1FileManagerDirectory,Rename-R1FileManagerDirectory,Get-R1FileContent,
Set-R1FileContent,Import-R1File,Export-R1File,Remove-R1FileandNew-R1Jar. Reset-R1DashboardLink, which restores the default dashboard links.
Notes
These are the behaviours worth knowing before using the module, rather than a record of changes.
- Updates read before they write. The RadiantOne update endpoints replace the resource rather
than merging into it: a property absent from the request is cleared, and a permission absent from a
role resets to NONE, with the API returning 200 either way. EverySet-*command issuing a PUT
therefore retrieves the resource first and sends it back with the supplied values applied over it,
so a property left unspecified keeps its current value. Two consequences: those commands issue two
requests, and the account needs permission to read the resource as well as to change it. A test
enforces this and requires a written reason for each of the few commands exempt from it. - Some commands replace a whole collection.
Set-R1FIDUserRole,Set-R1LdapClientAccessMapping
andSet-R1CustomLimittake the complete collection, so anything omitted is removed. Their help
says so, andSet-R1Featureavoids the trap by retrieving every flag and changing only those named. - Secrets are sent as UTF8 bytes, not as strings, so Windows PowerShell parameter binding and
module logging cannot capture the plaintext. - Sixteen commands have not been exercised against a live deployment and say so in their help,
each with the reason: the endpoint is absent on a SaaS tenant (licensing), no account available
could read it (backend limits, log settings), nothing was configured to read (token validators), or
exercising it risked unrecoverable damage (attribute encryption, key rotation, the directory
manager password). PUT /settings-service/oidc_providersis deliberately not exposed. It replaces the entire
collection of providers with the array supplied, deleting any provider left out of it.
Set-R1OidcProvideraddresses a single provider instead.