From 022c67caa6cb65c4e77feef93776e00d78d900d6 Mon Sep 17 00:00:00 2001 From: Raimund Andree Date: Mon, 5 Oct 2026 02:13:06 +0200 Subject: [PATCH] fix: correct the verbose and warning messages that named the wrong state Copy-Item2 and Move-Item2 named the source path as the destination, Disable-Privileges said that the privileges were now enabled, and the warning of Get-NTFSEffectiveAccess misspelled the privilege. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant --- CHANGELOG.md | 4 ++++ NTFSSecurity/AccessCmdlets/GetEffectiveAccess.cs | 2 +- NTFSSecurity/ItemCmdlets/CopyItem2.cs | 4 ++-- NTFSSecurity/ItemCmdlets/MoveItem2.cs | 4 ++-- NTFSSecurity/OtherCmdlets.cs | 2 +- Tests/Access.Tests.ps1 | 9 +++++++++ Tests/ItemCmdlets.Tests.ps1 | 12 ++++++++++++ Tests/Privileges.Tests.ps1 | 9 +++++++++ 8 files changed, 40 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a523644..13a3ca5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -142,5 +142,9 @@ The format is based on `Add-NTFSAudit`, `Remove-NTFSAudit`, `Copy-Item2`, `Move-Item2`, `Remove-Item2`, and the inheritance cmdlets correctly, so that `Get-Command` and tab completion report the objects they write +- Fix the verbose messages of `Copy-Item2` and `Move-Item2`, which named the + source path as the destination, and of `Disable-Privileges`, which said + that the privileges were enabled, and the spelling of the privilege in + the warning of `Get-NTFSEffectiveAccess` [Unreleased]: https://github.com/raandree/NTFSSecurity/compare/4.2.6...HEAD diff --git a/NTFSSecurity/AccessCmdlets/GetEffectiveAccess.cs b/NTFSSecurity/AccessCmdlets/GetEffectiveAccess.cs index d929bbf..bf1334c 100644 --- a/NTFSSecurity/AccessCmdlets/GetEffectiveAccess.cs +++ b/NTFSSecurity/AccessCmdlets/GetEffectiveAccess.cs @@ -72,7 +72,7 @@ namespace NTFSSecurity securityPrivilege = privControl.GetPrivileges().Where(priv => priv.Privilege == ProcessPrivileges.Privilege.Security).ToList(); if (securityPrivilege.Count() == 0) { - this.WriteWarning("The user does not hold the Security Privliege and might not be able to read the effective permissions"); + this.WriteWarning("The user does not hold the Security privilege and might not be able to read the effective permissions."); } else { diff --git a/NTFSSecurity/ItemCmdlets/CopyItem2.cs b/NTFSSecurity/ItemCmdlets/CopyItem2.cs index ed373da..1e1dd60 100644 --- a/NTFSSecurity/ItemCmdlets/CopyItem2.cs +++ b/NTFSSecurity/ItemCmdlets/CopyItem2.cs @@ -99,7 +99,7 @@ namespace NTFSSecurity if (ShouldProcess(resolvedPath, "Copy File")) { ((FileInfo)item).CopyTo(actualDestination, force ? CopyOptions.None : CopyOptions.FailIfExists, PathFormat.RelativePath); - WriteVerbose(string.Format("File '{0}' copied to '{0}'", resolvedPath, destination)); + WriteVerbose(string.Format("File '{0}' copied to '{1}'", resolvedPath, actualDestination)); } } else @@ -110,7 +110,7 @@ namespace NTFSSecurity // DirectoryNotFoundException for the first file. Directory.CreateDirectory(actualDestination); ((DirectoryInfo)item).CopyTo(actualDestination, force ? CopyOptions.None : CopyOptions.FailIfExists, PathFormat.RelativePath); - WriteVerbose(string.Format("Directory '{0}' copied to '{0}'", resolvedPath, destination)); + WriteVerbose(string.Format("Directory '{0}' copied to '{1}'", resolvedPath, actualDestination)); } } diff --git a/NTFSSecurity/ItemCmdlets/MoveItem2.cs b/NTFSSecurity/ItemCmdlets/MoveItem2.cs index 33d7369..dfbb22e 100644 --- a/NTFSSecurity/ItemCmdlets/MoveItem2.cs +++ b/NTFSSecurity/ItemCmdlets/MoveItem2.cs @@ -99,7 +99,7 @@ namespace NTFSSecurity if (ShouldProcess(resolvedPath, "Move File")) { ((FileInfo)item).MoveTo(actualDestination, force ? MoveOptions.ReplaceExisting : MoveOptions.CopyAllowed, PathFormat.RelativePath); - WriteVerbose(string.Format("File '{0}' moved to '{0}'", resolvedPath, destination)); + WriteVerbose(string.Format("File '{0}' moved to '{1}'", resolvedPath, actualDestination)); } } else @@ -107,7 +107,7 @@ namespace NTFSSecurity if (ShouldProcess(resolvedPath, "Move Directory")) { ((DirectoryInfo)item).MoveTo(actualDestination, force ? MoveOptions.ReplaceExisting : MoveOptions.CopyAllowed, PathFormat.RelativePath); - WriteVerbose(string.Format("Directory '{0}' moved to '{0}'", resolvedPath, destination)); + WriteVerbose(string.Format("Directory '{0}' moved to '{1}'", resolvedPath, actualDestination)); } } diff --git a/NTFSSecurity/OtherCmdlets.cs b/NTFSSecurity/OtherCmdlets.cs index b34aa17..82bba44 100644 --- a/NTFSSecurity/OtherCmdlets.cs +++ b/NTFSSecurity/OtherCmdlets.cs @@ -100,7 +100,7 @@ namespace NTFSSecurity } this.DisableFileSystemPrivileges(); - this.WriteVerbose("The privileges 'TakeOwnership', 'Restore' and 'Backup' are now enabled."); + this.WriteVerbose("The privileges 'TakeOwnership', 'Restore' and 'Backup' are now disabled."); if (passThru) { diff --git a/Tests/Access.Tests.ps1 b/Tests/Access.Tests.ps1 index bede5be..49a67bc 100644 --- a/Tests/Access.Tests.ps1 +++ b/Tests/Access.Tests.ps1 @@ -10,6 +10,7 @@ BeforeDiscovery { Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force # With the Restore privilege, Windows may grant writing the DACL despite a deny entry. $canBypassWriteDeny = Test-PrivilegeHeld -Name 'SeRestorePrivilege' + $holdsSecurityPrivilege = Test-PrivilegeHeld -Name 'SeSecurityPrivilege' } BeforeAll { @@ -55,6 +56,14 @@ Describe 'Get-NTFSEffectiveAccess' { Set-Acl -LiteralPath $effectiveFile -AclObject $acl } + # Before 5.0.0, the warning misspelled the privilege as "Privliege". + It 'Should warn once that the Security privilege is missing' -Skip:$holdsSecurityPrivilege { + Get-NTFSEffectiveAccess -Path $effectiveFile -WarningVariable accessWarnings -WarningAction SilentlyContinue | Out-Null + + $accessWarnings | Should -HaveCount 1 + $accessWarnings[0].Message | Should -BeExactly 'The user does not hold the Security privilege and might not be able to read the effective permissions.' + } + It 'Should leave out an account without access when -ExcludeNoneAccessEntries is used' { $result = @(Get-NTFSEffectiveAccess -Path $effectiveFile -Account 'S-1-5-32-546' -ExcludeNoneAccessEntries -WarningAction SilentlyContinue -ErrorAction Stop) diff --git a/Tests/ItemCmdlets.Tests.ps1 b/Tests/ItemCmdlets.Tests.ps1 index 31a5f48..e68ad3d 100644 --- a/Tests/ItemCmdlets.Tests.ps1 +++ b/Tests/ItemCmdlets.Tests.ps1 @@ -116,6 +116,18 @@ Describe 'Copy-Item2, Move-Item2, and Remove-Item2 with several paths' { $itemErrors | Should -HaveCount 1 Join-Path -Path $destination -ChildPath 'Second.txt' | Should -Exist } + + # Before 5.0.0, the verbose message named the source path as the destination. + It ' should name the destination in the verbose message' -ForEach @( + @{ Command = 'Copy-Item2'; Verb = 'copied' } + @{ Command = 'Move-Item2'; Verb = 'moved' } + ) { + $target = Join-Path -Path $destination -ChildPath 'First.txt' + + $messages = & $Command -Path $first -Destination $destination -Verbose 4>&1 + + $messages.Message | Should -Contain ("File '{0}' {1} to '{2}'" -f $first, $Verb, $target) + } } Describe 'Copy-Item2' { diff --git a/Tests/Privileges.Tests.ps1 b/Tests/Privileges.Tests.ps1 index 1ebfa5d..70a5852 100644 --- a/Tests/Privileges.Tests.ps1 +++ b/Tests/Privileges.Tests.ps1 @@ -59,6 +59,15 @@ Describe 'Disable-Privileges' { $privilegeWarnings | Should -BeNullOrEmpty Get-BackupPrivilegeState | Should -Be 'Disabled' } + + # Before 5.0.0, the verbose message said that the privileges were now enabled. + It 'Should say in the verbose message that the privileges are disabled' -Skip:(-not $holdsPrivileges) { + Enable-Privileges + + $messages = Disable-Privileges -Verbose -WarningAction SilentlyContinue 4>&1 + + $messages.Message | Should -Contain "The privileges 'TakeOwnership', 'Restore' and 'Backup' are now disabled." + } } }