mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
On Unix systems, fallback to plaintext manipulation instead of using the DPAPI which is not available. ## PR Context Currently, existing scripts that use SecureString cmdlets fail with an error complaining about crypt32.dll not being available. This change allows these cmdlets to be used, but there is no encryption of the string. .Net already [states](https://docs.microsoft.com/en-us/dotnet/api/system.security.securestring?view=netcore-2.1#remarks) that the contents of a SecureString are not encrypted on .Net Core. Fix https://github.com/PowerShell/PowerShell/issues/1654 Co-authored-by: Travis Plunk <travis.plunk@microsoft.com>
32 lines
1.4 KiB
PowerShell
32 lines
1.4 KiB
PowerShell
# Copyright (c) Microsoft Corporation. All rights reserved.
|
|
# Licensed under the MIT License.
|
|
Describe "SecureString conversion tests" -Tags "CI" {
|
|
BeforeAll {
|
|
$string = "ABCD"
|
|
$secureString = [System.Security.SecureString]::New()
|
|
$string.ToCharArray() | foreach-object { $securestring.AppendChar($_) }
|
|
}
|
|
|
|
It "using null arguments to ConvertFrom-SecureString produces an exception" {
|
|
{ ConvertFrom-SecureString -secureString $null -key $null } |
|
|
Should -Throw -ErrorId "ParameterArgumentValidationErrorNullNotAllowed,Microsoft.PowerShell.Commands.ConvertFromSecureStringCommand"
|
|
}
|
|
|
|
It "using a bad key produces an exception" {
|
|
$badkey = [byte[]]@(1,2)
|
|
{ ConvertFrom-SecureString -securestring $secureString -key $badkey } |
|
|
Should -Throw -ErrorId "Argument,Microsoft.PowerShell.Commands.ConvertFromSecureStringCommand"
|
|
}
|
|
|
|
It "Can convert to a secure string" {
|
|
$ss = ConvertTo-SecureString -AsPlainText -Force abcd
|
|
$ss | Should -BeOfType SecureString
|
|
}
|
|
It "can convert back from a secure string" {
|
|
$secret = "abcd"
|
|
$ss1 = ConvertTo-SecureString -AsPlainText -Force $secret
|
|
$ss2 = convertfrom-securestring $ss1 | convertto-securestring
|
|
[pscredential]::New("user",$ss2).GetNetworkCredential().Password | Should -Be $secret
|
|
}
|
|
}
|