Add soft delete for revoked devices
Admins could only revoke devices, so never-enrolled and revoked inventory rows piled up with no way to remove them. Soft-delete is limited to REVOKED devices (revoke first), and ITAM GC now hard-deletes PENDING/REVOKED orphans with no API key, postures, or valid enrollment token—including user tombstones without history. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -37,7 +37,7 @@ var FullAccessPolicy = policy.NewPolicy(
|
||||
"ITAM Full Access",
|
||||
policy.Allow(
|
||||
ActionDeviceList, ActionEmployeeDeviceList, ActionDeviceGet, ActionDeviceCreate,
|
||||
ActionDeviceEnroll, ActionDeviceRevoke, ActionDeviceAssignOwner,
|
||||
ActionDeviceEnroll, ActionDeviceRevoke, ActionDeviceDelete, ActionDeviceAssignOwner,
|
||||
ActionDevicePostureList,
|
||||
).WithSID("itam-full-access").When(organizationCondition),
|
||||
policy.Allow(ActionEmployeeDeviceGet).
|
||||
|
||||
Reference in New Issue
Block a user