Skip to content

feat: add Config write/property functions, completing the Config API area - #123

Merged
mikemadeja merged 3 commits into
developfrom
feature/config-management
Sep 28, 2026
Merged

mikemadeja merged 3 commits into
developfrom
feature/config-management

Conversation

@mikemadeja

Copy link
Copy Markdown
Owner

Summary

  • Extends Get-PiHoleConfig with -Element (request one subset of the config tree, e.g. "dns/upstreams") and -Detailed.
  • Adds Set-PiHoleConfig (PATCH /config), Add-PiHoleConfigArrayItem/Remove-PiHoleConfigArrayItem (PUT/DELETE /config/{element}/{value}, for array-type settings like dns/hosts and dns/cnameRecords - this is where local DNS records and CNAMEs live), and Get-PiHoleConfigProperty (the list of settings that can never be changed via the API).
  • All three write functions require the app password's app_sudo flag to be enabled in Pi-hole (Settings > All Settings) - Pi-hole blocks config changes from app passwords by default, and there's no way to enable it via the API itself (that would defeat the point of the restriction). This is documented in each function's .DESCRIPTION.
  • Adds ConvertTo-PiHoleFriendlyErrorMessage (Private/Misc.ps1), used by the three write functions' error handling: Pi-hole's own error responses carry a clearer message/hint than the generic HTTP exception text, and for the app_sudo case specifically, a concrete pointer to where to enable it - previously the module surfaced only "403 (Forbidden)" or "400 (Bad Request)" with no explanation of why or how to fix it.

This completes the "Config" area from the API coverage audit (5 of 5 operations implemented).

Test plan

  • All behavior verified directly against the real Pi-hole server, both with app_sudo disabled (confirming the 403 and its improved error message) and enabled (confirming a real config value can be changed and reverted, an array item can be added and removed, and a genuinely read-only property (misc.readOnly) is correctly rejected with a clear reason).
  • 18 new/updated Pester integration tests across the 5 functions, all passing against the real server. Write-path tests change and restore only a harmless debug flag (debug.api) or a fake TEST-NET-1 host entry - never real DNS/DHCP/network behavior.
  • Confirmed server config fully restored to its original state after every test run and after regenerating docs/EXAMPLES.md.
  • Invoke-ScriptAnalyzer clean against the full module.
  • Full non-integration Pester unit suite passes (4/4; unaffected by this change).

🤖 Generated with Claude Code

…area

Extends Get-PiHoleConfig with -Element (request one subset of the
config tree, e.g. "dns/upstreams") and -Detailed. Adds Set-PiHoleConfig
(PATCH /config), Add/Remove-PiHoleConfigArrayItem (PUT/DELETE
/config/{element}/{value}, for array-type settings like dns/hosts and
dns/cnameRecords), and Get-PiHoleConfigProperty (the list of settings
that can never be changed via the API).

All three write functions require the app password's "app_sudo" flag
to be enabled in Pi-hole (Settings > All Settings) - Pi-hole blocks
config changes from app passwords by default, and there's no way to
enable it via the API itself (avoiding that would defeat the point).
Verified against a real server with app_sudo both disabled and
enabled: a real config value can be changed and reverted, an
array item can be added and removed, and a genuinely read-only
property (misc.readOnly) is correctly rejected.

Adds ConvertTo-PiHoleFriendlyErrorMessage (Private/Misc.ps1), used by
the three write functions' error handling: Pi-hole's own error
responses carry a clearer message/hint than the generic HTTP exception
text, and for the app_sudo case specifically, a concrete pointer to
where to enable it - previously the module surfaced only "403
(Forbidden)" or "400 (Bad Request)" with no explanation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
mikemadeja and others added 2 commits September 28, 2026 15:02
…agement

# Conflicts:
#	README.md
#	docs/EXAMPLES.md
Resolves the README.md/docs/EXAMPLES.md conflicts from merging develop
(which now includes PR #122's Client Management and Network
Information) by regenerating both from the merged source instead of
hand-resolving generated-file diffs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mikemadeja
mikemadeja merged commit db8341e into develop Sep 28, 2026
3 checks passed
@mikemadeja mikemadeja mentioned this pull request Sep 28, 2026
1 task done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant