mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
128 lines
5.9 KiB
128 lines
5.9 KiB
<#
|
|
Tests the output types of the cmdlets of the module built in NTFSSecurity\bin\Release: the [OutputType] that
|
|
Get-Command reports, and the objects that -PassThru writes. Tests that need a privilege skip without it and run
|
|
in CI, whose runners are elevated.
|
|
#>
|
|
[Diagnostics.CodeAnalysis.SuppressMessageAttribute(
|
|
'PSUseDeclaredVarsMoreThanAssignments', '', Justification = 'Pester shares variables between blocks.'
|
|
)]
|
|
param ()
|
|
|
|
BeforeDiscovery {
|
|
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
|
|
$holdsBackupPrivilege = Test-PrivilegeHeld -Name 'SeBackupPrivilege'
|
|
$canCreateSymbolicLinks = Test-PrivilegeHeld -Name 'SeCreateSymbolicLinkPrivilege'
|
|
|
|
$itemTypes = @('Alphaleonis.Win32.Filesystem.FileInfo', 'Alphaleonis.Win32.Filesystem.DirectoryInfo')
|
|
$declaredTypes = @(
|
|
@{ Name = 'Test-Path2'; Types = @('System.Boolean') }
|
|
@{ Name = 'Get-FileHash2'; Types = @('Alphaleonis.Win32.Filesystem.FileInfo+Hash') }
|
|
@{ Name = 'Add-NTFSAudit'; Types = @('Security2.FileSystemAuditRule2') }
|
|
@{ Name = 'Remove-NTFSAudit'; Types = @('Security2.FileSystemAuditRule2') }
|
|
@{ Name = 'Copy-Item2'; Types = $itemTypes }
|
|
@{ Name = 'Move-Item2'; Types = $itemTypes }
|
|
@{ Name = 'Remove-Item2'; Types = $itemTypes }
|
|
@{ Name = 'Enable-NTFSAccessInheritance'; Types = @('Security2.FileSystemInheritanceInfo') }
|
|
@{ Name = 'Disable-NTFSAccessInheritance'; Types = @('Security2.FileSystemInheritanceInfo') }
|
|
@{ Name = 'Enable-NTFSAuditInheritance'; Types = @('Security2.FileSystemInheritanceInfo') }
|
|
@{ Name = 'Disable-NTFSAuditInheritance'; Types = @('Security2.FileSystemInheritanceInfo') }
|
|
@{ Name = 'Set-NTFSInheritance'; Types = @('Security2.FileSystemInheritanceInfo') }
|
|
)
|
|
}
|
|
|
|
BeforeAll {
|
|
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
|
|
$modulePath = Join-Path -Path $PSScriptRoot -ChildPath '..\NTFSSecurity\bin\Release\NTFSSecurity.psd1'
|
|
Import-Module -Name $modulePath -Force -ErrorAction Stop
|
|
$sandbox = New-TestSandbox -Name 'OutputTypes'
|
|
Push-Location -LiteralPath $sandbox
|
|
}
|
|
|
|
AfterAll {
|
|
Pop-Location
|
|
Remove-TestSandbox -Sandbox $sandbox
|
|
Remove-Module -Name NTFSSecurity -Force -ErrorAction SilentlyContinue
|
|
}
|
|
|
|
Describe 'Declared output types' {
|
|
It '<Name> should declare the type of the objects it writes' -ForEach $declaredTypes {
|
|
@((Get-Command -Name $Name).OutputType.Name) | Should -Be $Types
|
|
}
|
|
|
|
# Before 5.0.0-rc4, Get-FileHash2 declared the AlphaFS FileInfo, although it writes objects with the type name
|
|
# that its format view uses (#111).
|
|
It 'Get-FileHash2 should declare the type name of the objects it writes' {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'Hash'
|
|
|
|
$result = Get-FileHash2 -Path $file
|
|
|
|
$result.PSObject.TypeNames[0] | Should -BeExactly @((Get-Command -Name Get-FileHash2).OutputType.Name)[0]
|
|
}
|
|
}
|
|
|
|
Describe 'Privilege cmdlets with -PassThru' {
|
|
BeforeAll {
|
|
# The tests enable and disable the privileges of the test process; AfterAll restores the states they had (#110).
|
|
$fileSystemPrivileges = 'TakeOwnership', 'Restore', 'Backup', 'Security'
|
|
$enabledBefore = @(Get-Privileges | Where-Object -FilterScript {
|
|
$_.Privilege.ToString() -in $fileSystemPrivileges -and $_.PrivilegeState -eq 'Enabled'
|
|
} | ForEach-Object -Process { $_.Privilege })
|
|
}
|
|
|
|
AfterEach {
|
|
Disable-Privileges -ErrorAction SilentlyContinue -WarningAction SilentlyContinue
|
|
}
|
|
|
|
AfterAll {
|
|
$process = [System.Diagnostics.Process]::GetCurrentProcess()
|
|
foreach ($privilege in $enabledBefore) {
|
|
$null = [ProcessPrivileges.ProcessExtensions]::EnablePrivilege($process, $privilege)
|
|
}
|
|
}
|
|
|
|
# Before 5.0.0, -PassThru wrote the privileges as one collection. The access token of a basic user holds one
|
|
# privilege only, so the test compares with the privileges that the token holds.
|
|
It 'Enable-Privileges should write one object per privilege' {
|
|
$result = @(Enable-Privileges -PassThru -ErrorAction SilentlyContinue)
|
|
|
|
$result | Should -HaveCount @(Get-Privileges).Count
|
|
$result | ForEach-Object -Process { $_ | Should -BeOfType [ProcessPrivileges.PrivilegeAndAttributes] }
|
|
}
|
|
|
|
It 'Disable-Privileges should write one object per privilege' -Skip:(-not $holdsBackupPrivilege) {
|
|
Enable-Privileges -ErrorAction SilentlyContinue
|
|
|
|
$result = @(Disable-Privileges -PassThru -WarningAction SilentlyContinue)
|
|
|
|
$result.Count | Should -BeGreaterThan 1
|
|
$result | ForEach-Object -Process { $_ | Should -BeOfType [ProcessPrivileges.PrivilegeAndAttributes] }
|
|
}
|
|
}
|
|
|
|
Describe 'New-NTFSSymbolicLink with -PassThru' {
|
|
# Before 5.0.0, the cmdlet returned a file object for a link to a folder as well.
|
|
It 'Should return a folder object for a link to a folder' -Skip:(-not $canCreateSymbolicLinks) {
|
|
$folder = New-TestSandboxItem -Sandbox $sandbox -Name 'Target' -Directory
|
|
$link = Join-Path -Path $sandbox -ChildPath 'FolderLink'
|
|
Assert-TestSandboxPath -Sandbox $sandbox -Path $link
|
|
|
|
$result = New-NTFSSymbolicLink -Path $link -Target $folder -PassThru
|
|
|
|
$result | Should -BeOfType [Alphaleonis.Win32.Filesystem.DirectoryInfo]
|
|
}
|
|
}
|
|
|
|
Describe 'Cmdlet classes' {
|
|
# Before 5.0.0, these classes declared members that nothing used.
|
|
It '<_> should declare no Path property, which was never a parameter' -ForEach @(
|
|
'Enable-Privileges', 'Disable-Privileges', 'Get-Privileges'
|
|
) {
|
|
(Get-Command -Name $_).ImplementingType.GetProperty('Path') | Should -BeNullOrEmpty
|
|
}
|
|
|
|
It 'Remove-Item2 should declare no filter field' {
|
|
$flags = [System.Reflection.BindingFlags]'NonPublic, Instance'
|
|
|
|
(Get-Command -Name 'Remove-Item2').ImplementingType.GetField('filter', $flags) | Should -BeNullOrEmpty
|
|
}
|
|
}
|
|
|