mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
12 KiB
12 KiB
Changelog
All notable changes to this project are documented in this file.
The format is based on Keep a Changelog. Releases up to 4.2.6 are described in the version history.
Unreleased
Added
- Publish the documentation in the
wiki, generated from the
Docsfolder after every change, with a sidebar that lists all cmdlets - Link the release notes in the PowerShell Gallery to this changelog
Changed
- Breaking: require Windows PowerShell 5.1 or PowerShell 7, and declare support for both editions in the module manifest (#61); the manifest declared PowerShell 2.0 and .NET Framework 3.5, although the module needs .NET Framework 4.5.2
- Rename the
-PassThurparameter ofRemove-Item2to-PassThru;-PassThurstill works as an alias (#64) - Publish the module as a Release build that contains only the module
files; 4.2.6 was a Debug build with debug symbols and a copy of
System.Management.Automation.dll - Document every cmdlet with synopsis, description, parameters, examples, inputs, outputs, and notes, checked against the source code
- Rewrite the home, concepts, examples, and contributor pages to match the current cmdlets, including module settings, privileges, and long paths
- Move the version history and the installation instructions from the wiki into the documentation, and complete the version history with the release dates from the PowerShell Gallery, the missing notes for 4.2.2, 4.2.5, and 4.2.6, and detailed notes for 4.2.4
- Describe the module as a PowerShell module in the manifest, which the PowerShell Gallery shows; it said Windows PowerShell, although the module supports PowerShell 7 as well
- Rename
-RemoveInheritedAccessRulesofDisable-NTFSAuditInheritanceto-RemoveInheritedAuditRulesand-RemoveExplicitAccessRulesofEnable-NTFSAuditInheritanceto-RemoveExplicitAuditRules, because they act on audit entries; the old names still work as aliases - Breaking:
Set-NTFSInheritancekeeps entries like the dedicated cmdlets:-AccessInheritanceEnabled $falsenow copies the inherited access entries into the DACL instead of removing them, and-AuditInheritanceEnabled $truenow keeps the explicit audit entries. A script that used-AccessInheritanceEnabled $falseto drop the inherited access entries now leaves them in place, which grants broader access than before. To remove the entries, useDisable-NTFSAccessInheritance -RemoveInheritedAccessRulesorEnable-NTFSAuditInheritance -RemoveExplicitAuditRules - Breaking:
Get-ChildItem2 -Attributesreturns the items that have any of the listed attributes, likeGet-ChildItem; it returned only the items that had all of them. A call that lists several attributes now returns more items, including hidden and system items when those are in the list, so review calls whose result is deleted or whose permissions are changed. To get the old result, filter withWhere-Object, as the cmdlet page shows. An empty value, such as0, is now an error; it returned every item, also the hidden ones (#5) - Breaking: remove the alias
SizeofLengthOnDiskfrom the files ofGet-ChildItem, which made the import fail in Windows PowerShell when another module had added aSizemember; useLengthOnDisk(#82)
Deprecated
- Deprecate NTFSSecurity as a whole: the project will be archived soon. Move to WindowsAccessControl, which is also on the PowerShell Gallery
- Deprecate the
-PassThuralias ofRemove-Item2; use-PassThru - Deprecate the
MACTripleDESvalue ofGet-FileHash2 -Algorithm: it uses a random key, so its result differs on every call; the cmdlet now warns when you use it
Fixed
- Fix
Get-Help, which showed only the syntax: ship the help fileen-US\NTFSSecurity.dll-Help.xmlgenerated from the cmdlet documentation, including the links thatGet-Help -Onlineopens, instead of the outdatedNTFSSecurity-Help.xml - Fix documentation examples that did not work, such as restoring permissions from a CSV file and filtering entries by account
- Remove
Show-NTFSSimpleAccess, which no longer exists, and duplicate entries from the cmdlets that the module manifest exports and the PowerShell Gallery lists - Fix
Set-NTFSInheritance, which failed with "Nullable object must have a value" when-AccessInheritanceEnabledor-AuditInheritanceEnabledwas omitted; an omitted parameter now leaves its section unchanged - Fix
Get-ChildItem2, which stopped with anInvalidCastExceptionwhen-Pathpointed to a file; it now returns the file, likeGet-ChildItem - Fix
Get-FileHash2, which stopped at a folder in-Pathand didn't hash the files that followed it; folders are now skipped - Fix
Get-NTFSAudit, which returned nothing without the Security privilege instead of an error, and which returned the entries of the previous item again after a path whose security descriptor it couldn't read; it also no longer takes ownership of an item whose audit entries it can't read, which didn't help and could leave the owner changed - Fix
Get-NTFSAccess, which returned the entries of the previous item again after a path whose ACL it couldn't read - Fix
Add-NTFSAudit, whose-Accountand-AccessRightsparameters were both at position 2, so that positional calls failed;-AccessRightsis now at position 3, like inRemove-NTFSAudit(#4) - Fix
-PassThruofAdd-NTFSAuditwith-SecurityDescriptorand ofRemove-NTFSAuditwith-Path, which returned access entries; both now return the audit entries - Fix the
InheritanceEnabledproperty of audit entries, which reported the inheritance of the access entries; it now reports whether the audit entries are inherited - Fix
Get-NTFSInheritance -SecurityDescriptor, which reportedAuditInheritanceEnabledas$truefor a security descriptor that was read without its audit section; it now reports$null, like-Path - Fix
Get-NTFSOwner, which wrote a "The pipeline has been stopped" error for every path when a command such asSelect-Object -First 1stopped the pipeline, and which repeated a failed read instead of reporting the denied access - Fix
Copy-Item2, which failed with aDirectoryNotFoundExceptionwhen it copied a folder that contained files - Fix
Disable-Privileges, which couldn't disable the privileges when the module settingEnablePrivilegeswas$false - Fix the inheritance cmdlets, which enabled the Backup, Restore, Take
Ownership, and Security privileges even when the module setting
EnablePrivilegeswas$false, and left them enabled - Fix the
Inheritscolumn of theGet-ChildItem2output, which showedTruefor every item, also for items whose inheritance is disabled - Fix
Add-NTFSAccess,Remove-NTFSAccess,Add-NTFSAudit, andRemove-NTFSAudit, which failed with "Parameter set cannot be resolved" for-SecurityDescriptorwithout-AppliesTo,-InheritanceFlags, or-PropagationFlags;-AppliesTois now mandatory in theSimpleparameter sets, so such a command uses the flag parameters and their defaults, as for a path - Fix
Get-NTFSEffectiveAccess:-ExcludeNoneAccessEntriesnow leaves out items without access, the cmdlet uses the current location when-Pathis omitted, and-SecurityDescriptorreturns the effective access of the security descriptor; before, all three returned nothing or ignored the parameter - Fix
Get-NTFSOrphanedAccess,Get-NTFSOrphanedAudit, andGet-NTFSSimpleAccess, which ignored-Accountand-SecurityDescriptor;Get-NTFSOrphanedAuditnow writes one object per entry instead of one collection per item,Get-NTFSOrphanedAccessno longer repeats the entries of the previous item after a failed read, and the output ofGet-NTFSSimpleAccesshas a table view - Restore the
-RemoveSpecificswitch ofRemove-NTFSAccess, which version 4.1 introduced but later versions lacked, and add it toRemove-NTFSAudit: with it, the cmdlets remove only an entry that matches exactly - Fix
Copy-Item2,Move-Item2, andRemove-Item2, which skipped the remaining paths of-Pathafter a path that didn't exist or, for copy and move, a file that already existed at the destination - Fix
Remove-NTFSAccessandRemove-NTFSAudit, which went on with a path that didn't exist, wrote a second, misleadingRemoveAceError, and with-PassThrustopped with aNullReferenceException - Fix
-PassThruofEnable-NTFSAccessInheritance,Disable-NTFSAccessInheritance,Enable-NTFSAuditInheritance,Disable-NTFSAuditInheritance, andSet-NTFSInheritance, which returned the unchanged state of an item also when the change failed, so that the inheritance looked disabled (#74) - Fix the error of
New-NTFSHardLinkfor a missing-Target, which said that the target path existed - Fix
Get-FileHash2, which wrote a result for a file that it couldn't read, with the hash of the previous file - Fix
-PassThruofAdd-NTFSAccess,Add-NTFSAudit,Remove-NTFSAccess, andRemove-NTFSAudit, which returned the unchanged entries of an item also when the change failed - Fix the cmdlets that take ownership of an item to repeat an operation that was denied: when the second attempt failed as well, the account that ran the cmdlet stayed the owner of the item; now the previous owner is restored
- Fix
-PassThruofEnable-PrivilegesandDisable-Privileges, which wrote the privileges as one collection instead of one object per privilege, and ofNew-NTFSSymbolicLink, which returned a file object for a link to a folder - Declare the output types of
Test-Path2,Get-FileHash2,Add-NTFSAudit,Remove-NTFSAudit,Copy-Item2,Move-Item2,Remove-Item2, and the inheritance cmdlets correctly, so thatGet-Commandand tab completion report the objects they write - Fix the verbose messages of
Copy-Item2andMove-Item2, which named the source path as the destination, and ofDisable-Privileges, which said that the privileges were enabled, and the spelling of the privilege in the warning ofGet-NTFSEffectiveAccess - Fix
-PassThruofCopy-Item2,Move-Item2, andRemove-Item2, which wrote the item also when-WhatIfor a declined confirmation skipped the operation - Fix
Get-FileHash2in PowerShell 7, where it failed for every algorithm;RIPEMD160andMACTripleDES, which .NET lacks there, now stop the cmdlet with an error that names the algorithm and points to Windows PowerShell 5.1 - Fix a
FormatExceptionin the cmdlets for a path with braces, such asC:\Data\{Archive}: their messages formatted the path a second time (#3) - Fix a
NullReferenceExceptionin every cmdlet when a variable namedPWDin the scope of the caller, such as a loop variable, hid the automatic variable; the cmdlets now read the current location from the session, and only for a relative path (#86) - Fix file and folder objects passed by position, such as
Get-NTFSOwner $folder, which Windows PowerShell bound as the name of the item, so the cmdlets looked for it in the current location (#88) - Fix
Remove-NTFSAccessfor an entry with a generic right such asGenericAll, which Windows keeps in the inherit-only entries of folders; it failed with "The value '269484032' is not valid" (#17) - Fix
Enable-NTFSAuditInheritance,Disable-NTFSAuditInheritance, andSet-NTFSInheritance -AuditInheritanceEnabled, which failed with "Access is denied" for a file or folder without audit entries, also in an elevated session with the Security privilege