Browse Source

test: cover the SecurityDescriptor parameter sets without tests

Clear-NTFSAccess, Disable-NTFSAccessInheritance,
Enable-NTFSAccessInheritance, Clear-NTFSAudit, and
Enable-NTFSAuditInheritance change a descriptor of
Get-NTFSSecurityDescriptor in memory only, and the item changes when
Set-NTFSSecurityDescriptor writes it. Get-NTFSAccess, Get-NTFSOwner, and
Get-NTFSAudit return for a descriptor what they return for its path.
All pass elevated and as a basic user in both editions; the audit tests
skip without the Security privilege.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
ai/release-5.0.0-rc6
Raimund Andree 4 days ago
parent
commit
c8b728ecbc
  1. 146
      Tests/SecurityDescriptorSets.Tests.ps1

146
Tests/SecurityDescriptorSets.Tests.ps1

@ -0,0 +1,146 @@
<#
Tests the SecurityDescriptor parameter sets that no other test file covers, with the module built in
NTFSSecurity\bin\Release on files in a sandbox folder. The cmdlets change a descriptor of Get-NTFSSecurityDescriptor
in memory only, and the item changes when Set-NTFSSecurityDescriptor writes the descriptor; the cmdlets that read
return what their Path parameter set returns. Tests of audit entries need the Security privilege and skip without
it.
#>
[Diagnostics.CodeAnalysis.SuppressMessageAttribute(
'PSUseDeclaredVarsMoreThanAssignments', '', Justification = 'Pester shares variables between blocks.'
)]
param ()
BeforeDiscovery {
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
$holdsSecurityPrivilege = Test-PrivilegeHeld -Name 'SeSecurityPrivilege'
}
BeforeAll {
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
$modulePath = Join-Path -Path $PSScriptRoot -ChildPath '..\NTFSSecurity\bin\Release\NTFSSecurity.psd1'
Import-Module -Name $modulePath -Force -ErrorAction Stop
$sandbox = New-TestSandbox -Name 'SecurityDescriptorSets'
Push-Location -LiteralPath $sandbox
$sidType = [System.Security.Principal.SecurityIdentifier]
function Get-ExplicitAccessCount {
param ([System.Security.AccessControl.FileSystemSecurity] $Acl)
@($Acl.GetAccessRules($true, $false, $sidType)).Count
}
}
AfterAll {
Pop-Location
Remove-TestSandbox -Sandbox $sandbox
Remove-Module -Name NTFSSecurity -Force -ErrorAction SilentlyContinue
}
Describe 'Cmdlets that change a security descriptor in memory' {
It 'Clear-NTFSAccess should remove the explicit access entries of the descriptor' {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'ClearAccess'
Add-NTFSAccess -Path $file -Account 'S-1-1-0' -AccessRights ReadData
$sd = Get-NTFSSecurityDescriptor -Path $file
Clear-NTFSAccess -SecurityDescriptor $sd -ErrorAction Stop
Get-ExplicitAccessCount -Acl $sd.SecurityDescriptor | Should -Be 0
Get-ExplicitAccessCount -Acl (Get-Acl -LiteralPath $file) | Should -Be 1
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
Get-ExplicitAccessCount -Acl (Get-Acl -LiteralPath $file) | Should -Be 0
}
It 'Disable-NTFSAccessInheritance should protect the DACL of the descriptor and keep the inherited entries' {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'DisableAccess'
$inheritedCount = @((Get-Acl -LiteralPath $file).GetAccessRules($false, $true, $sidType)).Count
$sd = Get-NTFSSecurityDescriptor -Path $file
Disable-NTFSAccessInheritance -SecurityDescriptor $sd -ErrorAction Stop
$sd.SecurityDescriptor.AreAccessRulesProtected | Should -BeTrue
(Get-Acl -LiteralPath $file).AreAccessRulesProtected | Should -BeFalse
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
$acl = Get-Acl -LiteralPath $file
$acl.AreAccessRulesProtected | Should -BeTrue
Get-ExplicitAccessCount -Acl $acl | Should -Be $inheritedCount
}
It 'Enable-NTFSAccessInheritance should let the DACL of the descriptor inherit' {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'EnableAccess'
Disable-NTFSAccessInheritance -Path $file -RemoveInheritedAccessRules
$sd = Get-NTFSSecurityDescriptor -Path $file
Enable-NTFSAccessInheritance -SecurityDescriptor $sd -ErrorAction Stop
$sd.SecurityDescriptor.AreAccessRulesProtected | Should -BeFalse
(Get-Acl -LiteralPath $file).AreAccessRulesProtected | Should -BeTrue
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
$acl = Get-Acl -LiteralPath $file
$acl.AreAccessRulesProtected | Should -BeFalse
@($acl.GetAccessRules($false, $true, $sidType)) | Should -Not -BeNullOrEmpty
}
It 'Clear-NTFSAudit should remove the explicit audit entries of the descriptor' -Skip:(-not $holdsSecurityPrivilege) {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'ClearAudit'
Add-NTFSAudit -Path $file -Account 'S-1-1-0' -AccessRights ReadData -InheritanceFlags None -PropagationFlags None
$sd = Get-NTFSSecurityDescriptor -Path $file
Clear-NTFSAudit -SecurityDescriptor $sd -ErrorAction Stop
@($sd.SecurityDescriptor.GetAuditRules($true, $false, $sidType)) | Should -BeNullOrEmpty
@(Get-NTFSAudit -Path $file -ExcludeInherited) | Should -HaveCount 1
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
@(Get-NTFSAudit -Path $file -ExcludeInherited) | Should -BeNullOrEmpty
}
It 'Enable-NTFSAuditInheritance should let the SACL of the descriptor inherit' -Skip:(-not $holdsSecurityPrivilege) {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'EnableAudit'
Disable-NTFSAuditInheritance -Path $file
$sd = Get-NTFSSecurityDescriptor -Path $file
$sd.SecurityDescriptor.AreAuditRulesProtected | Should -BeTrue
Enable-NTFSAuditInheritance -SecurityDescriptor $sd -ErrorAction Stop
$sd.SecurityDescriptor.AreAuditRulesProtected | Should -BeFalse
(Get-NTFSInheritance -Path $file).AuditInheritanceEnabled | Should -BeFalse
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
(Get-NTFSInheritance -Path $file).AuditInheritanceEnabled | Should -BeTrue
}
}
Describe 'Cmdlets that read a security descriptor in memory' {
BeforeAll {
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'Read'
Add-NTFSAccess -Path $file -Account 'S-1-1-0' -AccessRights ReadData
}
It 'Get-NTFSAccess should return the entries that it returns for the path' {
$expected = @(Get-NTFSAccess -Path $file | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.IsInherited })
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSAccess -ErrorAction Stop)
$result | Should -Not -BeNullOrEmpty
($result | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.IsInherited }) -join ';' | Should -Be ($expected -join ';')
$result | ForEach-Object -Process { $_.FullName | Should -Be $file }
}
It 'Get-NTFSOwner should return the owner that it returns for the path' {
$expected = (Get-NTFSOwner -Path $file).Owner.Sid
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSOwner -ErrorAction Stop)
$result | Should -HaveCount 1
$result[0].Owner.Sid | Should -Be $expected
$result[0].FullName | Should -Be $file
}
It 'Get-NTFSAudit should return the audit entries that it returns for the path' -Skip:(-not $holdsSecurityPrivilege) {
Add-NTFSAudit -Path $file -Account 'S-1-1-0' -AccessRights ReadData -InheritanceFlags None -PropagationFlags None
$expected = @(Get-NTFSAudit -Path $file | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.AuditFlags })
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSAudit -ErrorAction Stop)
$result | Should -HaveCount 1
($result | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.AuditFlags }) -join ';' | Should -Be ($expected -join ';')
}
}
Loading…
Cancel
Save