From 6f1ad9d93b67986ba643f5862bf46c14edea1dbe Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Sat, 19 Sep 2026 02:33:12 +0900 Subject: [PATCH] Verify safe HTML evidence across PowerShell JSON encoders --- tests/NativeProviders.Tests.ps1 | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/tests/NativeProviders.Tests.ps1 b/tests/NativeProviders.Tests.ps1 index 33d2b4f8..e0b340a4 100644 --- a/tests/NativeProviders.Tests.ps1 +++ b/tests/NativeProviders.Tests.ps1 @@ -165,7 +165,13 @@ try { $html = Get-Content -LiteralPath $htmlPath -Raw Assert-Equal ($html -match 'Not installed') $true 'HTML retains absent-feature state' Assert-Equal ($html -match 'PermissionDenied') $true 'HTML retains denied-access reason' - Assert-Equal ($html -match '<provider-test>') $true 'HTML encodes untrusted error text' + # Windows PowerShell JSON escapes angle brackets as Unicode; PowerShell 7 may + # leave them for HtmlEncode. Both must safely preserve the original evidence. + $htmlRows = @([regex]::Matches($html, '(?s)
(.*?)
') | ForEach-Object { + [System.Net.WebUtility]::HtmlDecode($_.Groups[1].Value) | ConvertFrom-Json + }) + $htmlErrorText = ($htmlRows | ForEach-Object { $_.NativeSources.Channel.Error.Message }) -join ' ' + Assert-Equal ($htmlErrorText -match '') $true 'HTML encoding preserves untrusted error text' Assert-Equal ($html -match '') $false 'HTML never interprets error text as markup' Assert-Equal ($output -match '(?m)^Applocker: Conditional') $true 'Console does not summarize AppLocker as enabled' Assert-Equal ($output -match 'Native provider rules remain unconfirmed') $true 'Console explains conservative coverage'