Skip to content

VPP: previously added token can still be used to add App Store apps after Apple MDM is turned off #54115

Description

@AndreyKizimenko

Fleet versions

  • Discovered: rc-minor-fleet-v4.93.0 (f16843c)

Web browser and operating system: Chrome on macOS


💥 Actual behavior

Image

After Apple MDM is turned off, a VPP token that was added earlier still works: Software > Add software > App store lists the token's Apple apps, and they can be added to a fleet. That contradicts Settings > Integrations > MDM, which says "To enable Volume Purchasing Program (VPP), first turn on Apple (macOS, iOS, iPadOS) MDM." and no longer shows the token.

🛠️ Expected behavior

When Apple MDM is off, App Store (VPP) apps can't be listed or added, as the Settings copy says. The App store tab shows the "VPP isn't enabled (MDM required)" empty state.

🧑‍💻 Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. With Apple MDM on, add a VPP token in Settings > Integrations > MDM > VPP and make it available to "All fleets".
  2. Turn off Apple MDM. The VPP card now says to turn on Apple MDM first.
  3. Go to Software > Add software > App store, platform Apple. The token's apps are listed.
  4. Pick an app and click Add software. It's added to the fleet's library.

🕯️ More info (optional)

Neither layer checks Apple MDM:

  • Backend: GetAppStoreApps and AddAppStoreApp (ee/server/service/vpp.go:686, :760) only check authz and whether a token exists. GET /api/v1/fleet/software/app_store_apps?fleet_id=0 returns 113 apps with Apple MDM off.
  • Frontend: SoftwareAppStoreVpp.tsx:155 gates only on teamHasVPPToken, not on mdm.enabled_and_configured.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

#g-apple-at-workProduct group focused on Apple devicesbugSomething isn't working as documented~released bugThis bug was found in a stable release.

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions