mirror of https://github.com/raandree/NTFSSecurity
Browse Source
Security review of this branch, Major findings: - M4: Get-NTFSAudit took ownership of an item whose SACL it couldn't read. Ownership grants no access to the SACL, so the retry always failed, and it left the owner changed. The cmdlet now writes a ReadSecurityError with the category PermissionDenied, as Get-NTFSOwner does since defect 9; the page says so. - M1: Remove-TestSandbox reset the ACLs recursively before it removed the links. Measured: icacls /reset /T did not follow the junction (the target's explicit entry stayed), but the links now go first anyway; a folder that denies listing gets a reset without /T. New test: the ACL of a junction target stays unchanged. - m4: Assert-TestSandboxPath now rejects a path below a link, which can point outside the sandbox (new test, failed before). - M5: the Inherits column reads one ACL per displayed item; the Get-ChildItem2 page names the cost and how to avoid it. - M2: the comment of the CI-only Get-NTFSAudit repeat test states what it guards; Access.Tests.ps1 guards the same loop fix without elevation. - M3, the stale hash of Get-FileHash2, is fixed on ai/defects-c. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant <ai@example.com>pull/100/head
9 changed files with 65 additions and 24 deletions
Loading…
Reference in new issue