fix(auth): harden Windows auth store privacy
This commit is contained in:
@@ -57,6 +57,10 @@ func ReadCanonicalRegular(path string, maximum int64) ([]byte, error) {
|
||||
}
|
||||
|
||||
func openWindowsComponent(path string, directory bool) (windows.Handle, error) {
|
||||
return openWindowsComponentWithAccess(path, directory, windows.GENERIC_READ)
|
||||
}
|
||||
|
||||
func openWindowsComponentWithAccess(path string, directory bool, access uint32) (windows.Handle, error) {
|
||||
flags := uint32(windows.FILE_FLAG_OPEN_REPARSE_POINT)
|
||||
if directory {
|
||||
flags |= windows.FILE_FLAG_BACKUP_SEMANTICS
|
||||
@@ -65,7 +69,7 @@ func openWindowsComponent(path string, directory bool) (windows.Handle, error) {
|
||||
}
|
||||
handle, err := windows.CreateFile(
|
||||
windows.StringToUTF16Ptr(path),
|
||||
windows.GENERIC_READ,
|
||||
access,
|
||||
windowsRetainedHandleShareMode,
|
||||
nil,
|
||||
windows.OPEN_EXISTING,
|
||||
|
||||
Reference in New Issue
Block a user