Team Ai
Datasetpublic

MegaBites-AI/Windows-powershell

sourceHugging Facemitupdated 6mo agoView on Hugging Face
0likes372downloads
AclCmdlets.Tests.ps1111 linesDownload Raw Back to Microsoft.PowerShell.Security
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3Describe "Acl cmdlets are available and operate properly" -Tag CI {4    Context "Windows ACL test" {5        BeforeAll {6            $originalDefaultParameterValues = $PSDefaultParameterValues.Clone()7            $PSDefaultParameterValues["It:Skip"] = -not $IsWindows8        }9 10        It "Get-Acl returns an ACL DirectorySecurity object"  {11            $ACL = Get-Acl $TESTDRIVE12            $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity13        }14 15        It "Get-Acl -LiteralPath HKLM:Software\Classes\*"  {16            $ACL = Get-Acl -LiteralPath HKLM:Software\Classes\*17            $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity18        }19 20        It "Get-Acl -LiteralPath .\Software\Classes\*"  {21            $currentPath = Get-Location22            Set-Location -LiteralPath HKLM:\23            $ACL = Get-Acl -LiteralPath .\Software\Classes\*24            $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity25            $currentPath | Set-Location26        }27 28        It "Get-Acl -LiteralPath ."  {29            $currentPath = Get-Location30            Set-Location -LiteralPath $TESTDRIVE31            $ACL = Get-Acl -LiteralPath .32            $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity33            $currentPath | Set-Location34        }35 36        It "Get-Acl -LiteralPath .."  {37            $currentPath = Get-Location38            Set-Location -LiteralPath $TESTDRIVE39            $ACL = Get-Acl -LiteralPath ..40            $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity41            $currentPath | Set-Location42        }43 44        It "Get-Acl -Path .\Software\Classes\"  {45            $currentPath = Get-Location46            Set-Location -LiteralPath HKLM:\47            $ACL = Get-Acl -Path .\Software\Classes\48            $ACL | Should -BeOfType System.Security.AccessControl.RegistrySecurity49            $currentPath | Set-Location50        }51 52        It "Get-Acl -Path ."  {53            $currentPath = Get-Location54            Set-Location -LiteralPath $TESTDRIVE55            $ACL = Get-Acl -Path .56            $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity57            $currentPath | Set-Location58        }59 60        It "Get-Acl -Path .."  {61            $currentPath = Get-Location62            Set-Location -LiteralPath $TESTDRIVE63            $ACL = Get-Acl -Path ..64            $ACL | Should -BeOfType System.Security.AccessControl.DirectorySecurity65            $currentPath | Set-Location66        }67 68        It "Set-Acl can set the ACL of a directory" {69            Setup -d testdir70            $directory = "$TESTDRIVE/testdir"71            $acl = Get-Acl $directory72            $accessRule = [System.Security.AccessControl.FileSystemAccessRule]::New("Everyone","FullControl","ContainerInherit,ObjectInherit","None","Allow")73            $acl.AddAccessRule($accessRule)74            { $acl | Set-Acl $directory } | Should -Not -Throw75 76            $newacl = Get-Acl $directory77            $newrule = $newacl.Access | Where-Object { $accessrule.FileSystemRights -eq $_.FileSystemRights -and $accessrule.AccessControlType -eq $_.AccessControlType -and $accessrule.IdentityReference -eq $_.IdentityReference }78            $newrule | Should -Not -BeNullOrEmpty79        }80 81        It "Can edit SD that contains an orphaned SID" {82            $badSid = [System.Security.Principal.SecurityIdentifier]::new("S-1-5-1234-5678")83            $currentUserSid = [System.Security.Principal.WindowsIdentity]::GetCurrent().User84 85            $testFilePath = "TestDrive:\pwsh-acl-test.txt"86            $testFile = New-Item -Path $testFilePath -ItemType File -Value 'foo' -Force87 88            # We should be able to set an SD entry to an untranslatable SID89            $fileSecurity = $testFilePath | Get-Acl90            $fileSecurity.SetGroup($badSid)91            Set-Acl -Path $testFile -AclObject $fileSecurity92 93            # We should be able to get the SD with an untranslatable SID94            $setSD = Get-Acl -Path $testFile95            $setSD.GetGroup([System.Security.Principal.SecurityIdentifier]) | Should -Be $badSid96 97            # We should be able to set it back to a known SID98            $setSD.SetGroup($currentUserSid)99            Set-Acl -Path $testFile -AclObject $setSD100 101            $actual = Get-Acl -Path $testFile102            $actualGroup = $actual.GetGroup([System.Security.Principal.SecurityIdentifier])103            $actualGroup | Should -Be $currentUserSid104        }105 106        AfterAll {107            $global:PSDefaultParameterValues = $originalDefaultParameterValues108        }109    }110}111