mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-06 06:25:13 +02:00
Include read-only Windows CLI profile smoke checks
This commit is contained in:
commit
ebd8d14d04
1 file changed
+13
-1
@@ -12,4 +12,16 @@ foreach ($policy in $catalog) {
|
||||
$context = Get-WelaHostContext
|
||||
$plan = Get-WelaAuditProfilePlan -Profile wela-2.2.0 -Role $context.Role -Build $context.Build -Current $current
|
||||
Assert-WelaAuditProfileTarget -Plan $plan -Context $context -Current $current
|
||||
Write-Host "PASS: queried all $($current.Count) effective audit policies on $($context.Role) build $($context.Build); no settings changed."
|
||||
$temp = Join-Path ([System.IO.Path]::GetTempPath()) ('wela-cli-audit-' + [guid]::NewGuid().ToString() + '.json')
|
||||
try {
|
||||
# Exercise real script dispatch and export without printing the 59-row table or changing policy.
|
||||
& (Join-Path $PSScriptRoot '../WELA.ps1') audit -Profile wela-2.2.0 -PlanPath $temp 6>$null | Out-Null
|
||||
$export = Get-Content -LiteralPath $temp -Raw -ErrorAction Stop | ConvertFrom-Json -ErrorAction Stop
|
||||
if ($export.policies.Count -ne 59 -or $export.role -ne $context.Role -or $export.build -ne $context.Build -or $export.profile -ne 'wela-2.2.0') {
|
||||
throw 'CLI audit export did not preserve all policies and the detected role/build.'
|
||||
}
|
||||
if (@($export.policies | Where-Object { $null -eq $_.currentMask }).Count -ne 0) {
|
||||
throw 'CLI audit unexpectedly exported unknown effective policy values.'
|
||||
}
|
||||
} finally { Remove-Item -LiteralPath $temp -Force -ErrorAction SilentlyContinue }
|
||||
Write-Host "PASS: queried all $($current.Count) effective audit policies on $($context.Role) build $($context.Build); CLI audit JSON verified; no settings changed."
|
||||
Reference in new issue
Block a user