test(items,audit): resolve the findings of the independent review of the tests
Items: the comparison of Get-Privileges with whoami compares the State only
where whoami prints the English words, because the column is localized. The
rows 'as an array with an empty element' of Copy-Item2 and Move-Item2 now pass
an array: a switch unrolls @(''), so they had passed the plain empty string. The
empty-path rows of both cmdlets run in a folder of their own, so that a guard
that regressed would copy or move an empty folder and not the sandbox into
itself.
Audit: a piped AppliesTo property does not select PathSimple, the default set
PathComplex binds and the property is dropped (a descriptor object does select
SDSimple), so the rows named PathSimple bound PathComplex. The PathSimple rows
of Add-NTFSAudit and Remove-NTFSAudit now name -AppliesTo and pipe the rest,
and the Add rows use a folder and assert the scope of the new entry (None, not
the default ContainerInherit and ObjectInherit). The descriptor rows assert the
entry in the descriptor and, after Set-NTFSSecurityDescriptor, on disk.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
@ -117,13 +117,16 @@ Describe 'Audit cmdlets with a security descriptor that has no audit section' {
Describe'Add-NTFSAudit'{
Context'Binding -Path from the pipeline by property name'{
# -AppliesTo is named for the Simple row, not piped: an object with an AppliesTo property binds the default set
# PathComplex and the property is dropped (the folders show it: the scope of the entry stays the default one), so
# only the named parameter selects PathSimple.
It'Should add the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and leave the DACL unchanged'-ForEach@(
Context'Binding -Path from the pipeline by property name'{
# -AppliesTo is named for the Simple row, not piped: a piped AppliesTo property would be dropped for a path (the
# default set PathComplex wins), so only the named parameter selects PathSimple.
It"Should remove the audit entry for the piped <Set> object that exists, write a ReadFileError for the one that does not, and keep the other account's entry"-ForEach@(