Private/Assert-NSPToolkitRootSecure.ps1

function Test-NSPToolkitRootAcl {
    # $true when -Path's access list is cut off from its parent and only Administrators and SYSTEM
    # are allowed - the ACL Set-NSPToolkitRootAcl applies. A missing folder is not secure.
    param([Parameter(Mandatory)][string]$Path)
    if (-not (Test-Path -LiteralPath $Path -PathType Container)) { return $false }
    try { $acl = Get-Acl -LiteralPath $Path -ErrorAction Stop } catch { return $false }
    if (-not $acl.AreAccessRulesProtected) { return $false }
    $allowed = 'S-1-5-32-544', 'S-1-5-18'
    foreach ($rule in $acl.GetAccessRules($true, $true, [Security.Principal.SecurityIdentifier])) {
        if ($rule.AccessControlType -eq 'Allow' -and $allowed -notcontains $rule.IdentityReference.Value) { return $false }
    }
    return $true
}

function Assert-NSPToolkitRootSecure {
    <#
        Fail closed before secrets are written under the Toolkit root (security review SEC-B2): the
        root must be limited to Administrators and SYSTEM. An elevated session repairs it; otherwise
        this throws and nothing is written.
    #>

    param(
        [Parameter(Mandatory)][string]$Root,
        [string]$Reason = 'secrets'
    )
    if (Test-NSPToolkitRootAcl -Path $Root) { return }
    $identity = [Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()
    if ((Test-Path -LiteralPath $Root -PathType Container) -and $identity.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
        Write-Host "Locking $Root down to Administrators and SYSTEM before saving $Reason." -ForegroundColor DarkGray
        Set-NSPToolkitRootAcl -Path $Root
        if (Test-NSPToolkitRootAcl -Path $Root) { return }
    }
    throw "Not saving $Reason`: $Root is not limited to Administrators and SYSTEM. Run the tool elevated so the folder can be locked down."
}