MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3Describe "Acl cmdlets are available and operate properly" -Tag CI {4 Context "Windows ACL test" {5 BeforeAll {6 $originalDefaultParameterValues = $PSDefaultParameterValues.Clone()7 $PSDefaultParameterValues["It:Skip"] = -not $IsWindows8 }9 10 It "Get-Acl returns an ACL DirectorySecurity object" {11 $ACL = Get-Acl $TESTDRIVE12 $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity13 }14 15 It "Get-Acl -LiteralPath HKLM:Software\Classes\*" {16 $ACL = Get-Acl -LiteralPath HKLM:Software\Classes\*17 $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity18 }19 20 It "Get-Acl -LiteralPath .\Software\Classes\*" {21 $currentPath = Get-Location22 Set-Location -LiteralPath HKLM:\23 $ACL = Get-Acl -LiteralPath .\Software\Classes\*24 $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity25 $currentPath | Set-Location26 }27 28 It "Get-Acl -LiteralPath ." {29 $currentPath = Get-Location30 Set-Location -LiteralPath $TESTDRIVE31 $ACL = Get-Acl -LiteralPath .32 $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity33 $currentPath | Set-Location34 }35 36 It "Get-Acl -LiteralPath .." {37 $currentPath = Get-Location38 Set-Location -LiteralPath $TESTDRIVE39 $ACL = Get-Acl -LiteralPath ..40 $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity41 $currentPath | Set-Location42 }43 44 It "Get-Acl -Path .\Software\Classes\" {45 $currentPath = Get-Location46 Set-Location -LiteralPath HKLM:\47 $ACL = Get-Acl -Path .\Software\Classes\48 $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity49 $currentPath | Set-Location50 }51 52 It "Get-Acl -Path ." {53 $currentPath = Get-Location54 Set-Location -LiteralPath $TESTDRIVE55 $ACL = Get-Acl -Path .56 $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity57 $currentPath | Set-Location58 }59 60 It "Get-Acl -Path .." {61 $currentPath = Get-Location62 Set-Location -LiteralPath $TESTDRIVE63 $ACL = Get-Acl -Path ..64 $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity65 $currentPath | Set-Location66 }67 68 It "Set-Acl can set the ACL of a directory" {69 Setup -d testdir70 $directory = "$TESTDRIVE/testdir"71 $acl = Get-Acl $directory72 $accessRule = [System.Security.AccessControl.FileSystemAccessRule]::New("Everyone","FullControl","ContainerInherit,ObjectInherit","None","Allow")73 $acl.AddAccessRule($accessRule)74 { $acl | Set-Acl $directory } | Should -Not -Throw75 76 $newacl = Get-Acl $directory77 $newrule = $newacl.Access | Where-Object { $accessrule.FileSystemRights -eq $_.FileSystemRights -and $accessrule.AccessControlType -eq $_.AccessControlType -and $accessrule.IdentityReference -eq $_.IdentityReference }78 $newrule | Should -Not -BeNullOrEmpty79 }80 81 It "Can edit SD that contains an orphaned SID" {82 $badSid = [System.Security.Principal.SecurityIdentifier]::new("S-1-5-1234-5678")83 $currentUserSid = [System.Security.Principal.WindowsIdentity]::GetCurrent().User84 85 $testFilePath = "TestDrive:\pwsh-acl-test.txt"86 $testFile = New-Item -Path $testFilePath -ItemType File -Value 'foo' -Force87 88 # We should be able to set an SD entry to an untranslatable SID89 $fileSecurity = $testFilePath | Get-Acl90 $fileSecurity.SetGroup($badSid)91 Set-Acl -Path $testFile -AclObject $fileSecurity92 93 # We should be able to get the SD with an untranslatable SID94 $setSD = Get-Acl -Path $testFile95 $setSD.GetGroup([System.Security.Principal.SecurityIdentifier]) | Should -Be $badSid96 97 # We should be able to set it back to a known SID98 $setSD.SetGroup($currentUserSid)99 Set-Acl -Path $testFile -AclObject $setSD100 101 $actual = Get-Acl -Path $testFile102 $actualGroup = $actual.GetGroup([System.Security.Principal.SecurityIdentifier])103 $actualGroup | Should -Be $currentUserSid104 }105 106 AfterAll {107 $global:PSDefaultParameterValues = $originalDefaultParameterValues108 }109 }110}111 