MegaBites-AI/Windows-powershell
0372
1// Copyright (c) Microsoft Corporation.2// Licensed under the MIT License.3 4#if !UNIX5 6using System.Management.Automation;7using System.Management.Automation.Provider;8using System.Security.AccessControl;9using Microsoft.PowerShell.Commands.Internal;10 11namespace Microsoft.PowerShell.Commands12{13 /// <summary>14 /// Provider that provides access to Registry through cmdlets. This provider15 /// implements <see cref="System.Management.Automation.Provider.NavigationCmdletProvider"/>,16 /// <see cref="System.Management.Automation.Provider.IPropertyCmdletProvider"/>,17 /// <see cref="System.Management.Automation.Provider.IDynamicPropertyCmdletProvider"/>,18 /// <see cref="System.Management.Automation.Provider.ISecurityDescriptorCmdletProvider"/>19 /// interfaces.20 /// </summary>21 public sealed partial class RegistryProvider :22 NavigationCmdletProvider,23 IPropertyCmdletProvider,24 IDynamicPropertyCmdletProvider,25 ISecurityDescriptorCmdletProvider26 {27 #region ISecurityDescriptorCmdletProvider members28 29 /// <summary>30 /// Gets the security descriptor for the item specified by <paramref name="path"/>.31 /// </summary>32 /// <param name="path">33 /// The path to the item.34 /// </param>35 /// <param name="sections">36 /// Specifies the parts of a security descriptor to retrieve.37 /// </param>38 /// <returns>39 /// Nothing. An object that represents the security descriptor for the item40 /// specified by path is written to the WriteSecurityDescriptorObject method.41 /// </returns>42 public void GetSecurityDescriptor(string path,43 AccessControlSections sections)44 {45 ObjectSecurity sd = null;46 IRegistryWrapper key = null;47 48 // Validate input first.49 if (string.IsNullOrEmpty(path))50 {51 throw PSTraceSource.NewArgumentNullException(nameof(path));52 }53 54 if ((sections & ~AccessControlSections.All) != 0)55 {56 throw PSTraceSource.NewArgumentException(nameof(sections));57 }58 59 path = NormalizePath(path);60 61 key = GetRegkeyForPathWriteIfError(path, false);62 63 if (key != null)64 {65 try66 {67 sd = key.GetAccessControl(sections);68 }69 catch (System.Security.SecurityException e)70 {71 WriteError(new ErrorRecord(e, e.GetType().FullName, ErrorCategory.PermissionDenied, path));72 return;73 }74 75 WriteSecurityDescriptorObject(sd, path);76 }77 }78 79 /// <summary>80 /// Sets the security descriptor for the item specified by <paramref name="path"/>81 /// </summary>82 /// <param name="path">83 /// The path to the item to set the security descriptor on.84 /// </param>85 /// <param name="securityDescriptor">86 /// The new security descriptor for the item.87 /// </param>88 public void SetSecurityDescriptor(89 string path,90 ObjectSecurity securityDescriptor)91 {92 IRegistryWrapper key = null;93 94 if (string.IsNullOrEmpty(path))95 {96 throw PSTraceSource.NewArgumentException(nameof(path));97 }98 99 if (securityDescriptor == null)100 {101 throw PSTraceSource.NewArgumentNullException(nameof(securityDescriptor));102 }103 104 path = NormalizePath(path);105 106 ObjectSecurity sd;107 if (TransactionAvailable())108 {109 sd = securityDescriptor as TransactedRegistrySecurity;110 111 if (sd == null)112 {113 throw PSTraceSource.NewArgumentException(nameof(securityDescriptor));114 }115 }116 else117 {118 sd = securityDescriptor as RegistrySecurity;119 120 if (sd == null)121 {122 throw PSTraceSource.NewArgumentException(nameof(securityDescriptor));123 }124 }125 126 key = GetRegkeyForPathWriteIfError(path, true);127 128 if (key != null)129 {130 //131 // the caller already checks for the following exceptions:132 // -- UnauthorizedAccessException133 // -- PrivilegeNotHeldException134 // -- NotSupportedException135 // -- SystemException136 //137 try138 {139 key.SetAccessControl(sd);140 }141 catch (System.Security.SecurityException e)142 {143 WriteError(new ErrorRecord(e, e.GetType().FullName, ErrorCategory.PermissionDenied, path));144 return;145 }146 catch (System.UnauthorizedAccessException e)147 {148 WriteError(new ErrorRecord(e, e.GetType().FullName, ErrorCategory.PermissionDenied, path));149 return;150 }151 152 WriteSecurityDescriptorObject(sd, path);153 }154 }155 156 /// <summary>157 /// Creates a new empty security descriptor.158 /// </summary>159 /// <param name="path">160 /// The path to the item whose type is to be used when161 /// creating a new descriptor.162 /// </param>163 /// <param name="sections">164 /// Specifies the parts of a security descriptor to create.165 /// </param>166 /// <returns>167 /// An instance of <see cref="System.Security.AccessControl.ObjectSecurity"/> object.168 /// </returns>169 /// <remarks><paramref name="path"/> and <paramref name="sections"/> are not used by this method.</remarks>170 public ObjectSecurity NewSecurityDescriptorFromPath(171 string path,172 AccessControlSections sections)173 {174 if (TransactionAvailable())175 {176 return new TransactedRegistrySecurity();177 }178 else179 {180 return new RegistrySecurity(); // sections);181 }182 }183 184 /// <summary>185 /// Creates a new empty security descriptor.186 /// </summary>187 /// <param name="type">188 /// The type of item associated with this security descriptor189 /// </param>190 /// <param name="sections">191 /// Specifies the parts of a security descriptor to create.192 /// </param>193 /// <returns>194 /// An instance of <see cref="System.Security.AccessControl.ObjectSecurity"/> object.195 /// </returns>196 public ObjectSecurity NewSecurityDescriptorOfType(197 string type,198 AccessControlSections sections)199 {200 if (TransactionAvailable())201 {202 return new TransactedRegistrySecurity();203 }204 else205 {206 return new RegistrySecurity(); // sections);207 }208 }209 210 #endregion ISecurityDescriptorCmdletProvider members211 }212}213#endif // !UNIX214 