Skip to content

Let deletable_admins match a name prefix ending in * - #35

Open
rodchristiansen wants to merge 1 commit into
mainfrom
feature/deletable-admins-prefix-workitem-4381
Open

rodchristiansen wants to merge 1 commit into
mainfrom
feature/deletable-admins-prefix-workitem-4381

Conversation

@rodchristiansen

@rodchristiansen rodchristiansen commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

deletable_admins matched account names exactly. A family of numbered admin accounts had to be listed one by one, and an entry for the base name never matched its numbered siblings. admin-* could not be expressed.

What changed

  • New DeletableAdminMatcher: an entry is an exact name, or a prefix ending in a single *. Both match case-insensitively. admin-* matches admin-1 and Admin-Lab, not admin or admin-.
  • A bare *, or a * anywhere but the end, is ignored and the run logs a warning, because it would opt every admin in and lift the delete_admins guard.
  • Exclusions still win: an excluded account never matches, whatever the list says.
  • delete_admins: false stays the guard. The list is consulted only for accounts that are local admins while the guard is on, in both the main pass and the orphan pass.
  • README gains an Administrators section with a table of entry forms. The Prefs placeholder and the PolicyConfig doc comment mention the prefix form.

Testing

  • New DeletableAdminMatcherTests cover exact and prefix matching, case, exclusions winning, rejected * forms, blanks and duplicates. All 10 pass on macOS when compiled against net10.0 with just the matcher and its tests.
  • The CLI and test project cross-build for net10.0-windows on macOS with no warnings. Windows CI builds the whole solution, WinUI app included, and runs the full suite: 86/86 pass.

Before merging

  • CI is green on Windows: build clean, full suite 86/86 passing.
  • Check that the fleet's deletable_admins lists contain no entry with a * that should be read literally. None is expected, since account names cannot contain *.
  • An entry like admin* does not match a bare admin. Keep the exact entry beside the prefix when both should be deletable.

deletable_admins matched names exactly, so a family of numbered admin accounts had to be listed one by one, and an entry for the base name never matched its numbered siblings. An entry ending in a single * is now a case-insensitive prefix. A bare * or a * anywhere else is ignored with a warning, since it would lift the delete_admins guard for every admin. Exclusions still win over every entry.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant