Block getting help from network locations in restricted remoting sessions (#20593)

This commit is contained in:
Travis Plunk
2023-10-31 16:06:15 -07:00
committed by GitHub
parent edfc3bd992
commit 687383bcc1
9 changed files with 166 additions and 35 deletions
@@ -1,6 +1,8 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.
Import-Module HelpersCommon
Describe 'Online help tests for PowerShell Cmdlets' -Tags "Feature" {
# The csv files (V2Cmdlets.csv and V3Cmdlets.csv) contain a list of cmdlets and expected HelpURIs.
@@ -61,3 +63,18 @@ Describe 'Get-Help -Online is not supported on Nano Server and IoT' -Tags "CI" {
{ Get-Help Get-Help -Online } | Should -Throw -ErrorId "InvalidOperation,Microsoft.PowerShell.Commands.GetHelpCommand"
}
}
Describe 'Get-Help should throw on network paths' -Tags "CI" {
BeforeAll {
$script:skipTest = -not $IsWindows
}
It "Get-Help should throw not on <command>" -Skip:$skipTest -TestCases (Get-HelpNetworkTestCases -PositiveCases) {
param(
$Command,
$ExpectedError
)
{ Get-Help -Name $Command } | Should -Not -Throw
}
}
@@ -106,7 +106,6 @@ Describe "JEA session Transcript script test" -Tag @("Feature", 'RequireAdminOnW
Unregister-PSSessionConfiguration -Name JEA -Force -ErrorAction SilentlyContinue
}
}
}
Describe "JEA session Get-Help test" -Tag @("CI", 'RequireAdminOnWindows') {
@@ -155,6 +154,34 @@ Describe "JEA session Get-Help test" -Tag @("CI", 'RequireAdminOnWindows') {
Remove-Item $RoleCapDirectory -Recurse -Force -ErrorAction SilentlyContinue
}
}
It "Get-Help should throw <ExpectedError> on <command>" -TestCases (Get-HelpNetworkTestCases) {
param(
$Command,
$ExpectedError
)
[string] $RoleCapDirectory = (New-Item -Path "$TestDrive\RoleCapability" -ItemType Directory -Force).FullName
[string] $PSSessionConfigFile = "$RoleCapDirectory\TestConfig.pssc"
$configurationName = 'RestrictedWithNoGetHelpProxy'
try
{
New-PSSessionConfigurationFile -Path $PSSessionConfigFile `
-SessionType Empty `
-LanguageMode NoLanguage `
-ModulesToImport 'Microsoft.PowerShell.Utility', 'Microsoft.PowerShell.Core' `
-VisibleCmdlets 'Get-command', 'measure-object', 'select-object', 'enter-pssession', 'get-formatdata', 'out-default', 'out-file', 'exit-pssession', 'get-help'
Register-PSSessionConfiguration -Name $configurationName -Path $PSSessionConfigFile -Force -ErrorAction SilentlyContinue
$scriptBlock = [scriptblock]::Create("Get-Help -Name $Command")
{Invoke-Command -ConfigurationName $configurationName -ComputerName localhost -ScriptBlock $scriptBlock -ErrorAction Stop} |
Should -Throw -ErrorId $ExpectedError
}
finally
{
Unregister-PSSessionConfiguration -Name $configurationName -Force -ErrorAction SilentlyContinue
Remove-Item $RoleCapDirectory -Recurse -Force -ErrorAction SilentlyContinue
}
}
}
Describe "Remoting loopback tests" -Tags @('CI', 'RequireAdminOnWindows') {
@@ -358,6 +385,7 @@ Describe "Remoting loopback tests" -Tags @('CI', 'RequireAdminOnWindows') {
$session = New-RemoteSession -ConfigurationName $endPoint
try {
$result = Invoke-Command -Session $session -ScriptBlock { $Host.Version }
Write-Verbose "host version: $result" -Verbose
$result | Should -Be $PSVersionTable.PSVersion
}
finally {