Repository navigation
Let deletable_admins match a name prefix ending in * - #35
Open
rodchristiansen wants to merge 1 commit into
Open
rodchristiansen wants to merge 1 commit into
rodchristiansen wants to merge 1 commit into
Conversation
deletable_admins matched names exactly, so a family of numbered admin accounts had to be listed one by one, and an entry for the base name never matched its numbered siblings. An entry ending in a single * is now a case-insensitive prefix. A bare * or a * anywhere else is ignored with a warning, since it would lift the delete_admins guard for every admin. Exclusions still win over every entry.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
deletable_adminsmatched account names exactly. A family of numbered admin accounts had to be listed one by one, and an entry for the base name never matched its numbered siblings.admin-*could not be expressed.What changed
DeletableAdminMatcher: an entry is an exact name, or a prefix ending in a single*. Both match case-insensitively.admin-*matchesadmin-1andAdmin-Lab, notadminoradmin-.*, or a*anywhere but the end, is ignored and the run logs a warning, because it would opt every admin in and lift thedelete_adminsguard.delete_admins: falsestays the guard. The list is consulted only for accounts that are local admins while the guard is on, in both the main pass and the orphan pass.PolicyConfigdoc comment mention the prefix form.Testing
DeletableAdminMatcherTestscover exact and prefix matching, case, exclusions winning, rejected*forms, blanks and duplicates. All 10 pass on macOS when compiled againstnet10.0with just the matcher and its tests.net10.0-windowson macOS with no warnings. Windows CI builds the whole solution, WinUI app included, and runs the full suite: 86/86 pass.Before merging
deletable_adminslists contain no entry with a*that should be read literally. None is expected, since account names cannot contain*.admin*does not match a bareadmin. Keep the exact entry beside the prefix when both should be deletable.