Use well-known SIDs for icacls tweak principals (#5045)

This commit is contained in:
owenn
2026-09-02 15:14:56 -05:00
committed by GitHub
parent 8f7b12bc0d
commit 87dd643176
2 changed files with 37 additions and 6 deletions
+6 -6
View File
@@ -99,10 +99,10 @@
"category": "Essential Tweaks", "category": "Essential Tweaks",
"panel": "1", "panel": "1",
"InvokeScript": [ "InvokeScript": [
"icacls \"$Env:LocalAppData\\Packages\\Microsoft.WindowsStore_8wekyb3d8bbwe\\LocalState\\store.db\" /deny Everyone:F" "icacls \"$Env:LocalAppData\\Packages\\Microsoft.WindowsStore_8wekyb3d8bbwe\\LocalState\\store.db\" /deny *S-1-1-0:F"
], ],
"UndoScript": [ "UndoScript": [
"icacls \"$Env:LocalAppData\\Packages\\Microsoft.WindowsStore_8wekyb3d8bbwe\\LocalState\\store.db\" /grant Everyone:F" "icacls \"$Env:LocalAppData\\Packages\\Microsoft.WindowsStore_8wekyb3d8bbwe\\LocalState\\store.db\" /grant *S-1-1-0:F"
], ],
"link": "https://winutil.christitus.com/code-reference/tweaks/essential-tweaks/disablestoresearch" "link": "https://winutil.christitus.com/code-reference/tweaks/essential-tweaks/disablestoresearch"
}, },
@@ -647,7 +647,7 @@
"InvokeScript": [ "InvokeScript": [
" "
# Deny permission to remove OneDrive folder # Deny permission to remove OneDrive folder
icacls $Env:OneDrive /deny \"Administrators:(D,DC)\" icacls $Env:OneDrive /deny \"*S-1-5-32-544:(D,DC)\"
Write-Host \"Uninstalling OneDrive...\" Write-Host \"Uninstalling OneDrive...\"
Start-Process -FilePath (Join-Path $Env:SystemRoot \"System32\\OneDriveSetup.exe\") -ArgumentList '/uninstall' -Wait Start-Process -FilePath (Join-Path $Env:SystemRoot \"System32\\OneDriveSetup.exe\") -ArgumentList '/uninstall' -Wait
@@ -661,7 +661,7 @@
Remove-Item \"$Env:ProgramData\\Microsoft OneDrive\" -Recurse -Force Remove-Item \"$Env:ProgramData\\Microsoft OneDrive\" -Recurse -Force
# Grant back permission to access OneDrive folder # Grant back permission to access OneDrive folder
icacls $Env:OneDrive /grant \"Administrators:(D,DC)\" icacls $Env:OneDrive /grant \"*S-1-5-32-544:(D,DC)\"
if (-not (Get-ChildItem -Path $Env:OneDrive)) { if (-not (Get-ChildItem -Path $Env:OneDrive)) {
Remove-Item -Path $Env:OneDrive -Recurse Remove-Item -Path $Env:OneDrive -Recurse
@@ -991,12 +991,12 @@
New-Item -Path $RazerPath -ItemType Directory New-Item -Path $RazerPath -ItemType Directory
} }
icacls $RazerPath /deny \"Everyone:(W)\" icacls $RazerPath /deny \"*S-1-1-0:(W)\"
" "
], ],
"UndoScript": [ "UndoScript": [
" "
icacls \"$Env:SystemRoot\\Installer\\Razer\" /remove:d Everyone icacls \"$Env:SystemRoot\\Installer\\Razer\" /remove:d *S-1-1-0
" "
], ],
"link": "https://winutil.christitus.com/code-reference/tweaks/z--advanced-tweaks---caution/razerblock" "link": "https://winutil.christitus.com/code-reference/tweaks/z--advanced-tweaks---caution/razerblock"
+31
View File
@@ -227,6 +227,37 @@ Describe "Tweaks config" {
$locationServices | Should -HaveCount 1 $locationServices | Should -HaveCount 1
$locationServices[0].StartupType | Should -Be "Disabled" $locationServices[0].StartupType | Should -Be "Disabled"
} }
$icaclsPrincipalCases = @(
@{
Path = (Join-Path $configRoot "tweaks.json")
Tweak = "WPFTweaksDisableStoreSearch"
Sid = '*S-1-1-0'
ExpectedCount = 2
}
@{
Path = (Join-Path $configRoot "tweaks.json")
Tweak = "WPFTweaksRazerBlock"
Sid = '*S-1-1-0'
ExpectedCount = 2
}
@{
Path = (Join-Path $configRoot "tweaks.json")
Tweak = "WPFTweaksRemoveOneDrive"
Sid = '*S-1-5-32-544'
ExpectedCount = 2
}
)
It "identifies the <Tweak> icacls principal by SID" -TestCases $icaclsPrincipalCases {
param([string]$Path, [string]$Tweak, [string]$Sid, [int]$ExpectedCount)
$tweaks = Get-Content -Path $Path -Raw | ConvertFrom-Json
$scripts = (@($tweaks.$Tweak.InvokeScript) + @($tweaks.$Tweak.UndoScript)) -join "`n"
$sidCount = ([regex]::Matches($scripts, [regex]::Escape($Sid))).Count
$sidCount | Should -Be $ExpectedCount -Because "$Tweak must pass $Sid to icacls at every call site instead of a localized account name"
}
} }
Describe "Preset config" { Describe "Preset config" {