Skip to content

Make the GUI Prefs tab read-only until unlocked as administrator - #57

Merged
rodchristiansen merged 1 commit into
mainfrom
feature/gui-prefs-unlock
Oct 5, 2026
Merged

rodchristiansen merged 1 commit into
mainfrom
feature/gui-prefs-unlock

Conversation

@rodchristiansen

Copy link
Copy Markdown
Contributor

What

The Prefs tab in Managed Bootstrap Install is now read-only unless the app runs elevated.

  • A non-elevated window shows "Settings are read-only. Unlock to change them (requires administrator)." with an Unlock button.
  • Unlock relaunches the app's own exe through UAC with --prefs, so the new window opens on the Prefs tab, and the non-elevated window closes once the elevated one has started. Cancelling the UAC prompt leaves the window as it was, with no error dialog.
  • When elevated, fields are editable and auto-save to HKLM\SOFTWARE\BootstrapMate\Settings through ConfigManager.SaveMachineSettings. The save writes only the keys the tab shows, so reporting, signature and baseline settings already in HKLM are not reset to defaults. Policy-managed keys stay locked even when elevated.

Settings source

  • ConfigManager no longer reads or writes HKCU\SOFTWARE\BootstrapMate\Settings. Settings come from CLI arguments, policy, HKLM machine settings, or the built-in default.
  • The CLI drops --save-settings-file (settings from a JSON file). --save-settings now writes HKLM.
  • Any values previously saved per-user by the GUI are no longer read; set them again from an elevated Prefs tab, by policy, or in HKLM.

Tests

  • New PrefsElevation helper in Core (argument parsing, edit decision, UAC-cancel detection, relaunch start info), with unit tests in PrefsElevationTests.
  • dotnet test tests/BootstrapMate.Core.Tests: 102 passed. Solution and the App (x64) build clean.

Not verified

The interactive flow (UAC prompt, accept and cancel, handoff to the elevated window, editing and saving) needs a manual test on a device.

Settings now live only in HKLM\SOFTWARE\BootstrapMate\Settings. The GUI shows them
read-only and offers Unlock, which relaunches the app elevated through UAC on the
Prefs tab and closes the non-elevated window. Cancelling UAC leaves the tab as it was.
When elevated, edits auto-save through ConfigManager.SaveMachineSettings, limited to
the keys the tab shows; policy-managed keys stay locked.

ConfigManager no longer reads or writes HKCU settings, and the CLI drops
--save-settings-file, so no settings come from a user-writable location.
@rodchristiansen
rodchristiansen merged commit cc82ebf into main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant