Repository navigation
fix(windows): survive wrong-identity installs — de-elevated MSI launch + access-denied Explorer fallback - #5
Merged
Conversation
…h + access-denied Explorer fallback Two users hit "CreateFile \\storage\...: Access is denied." on folders they could open manually in Explorer just fine. Root cause: the MSI's LaunchApp custom action runs in the elevated execute sequence, so after an install/upgrade the server keeps the installer's identity (the admin account typed at the UAC prompt, or an IT remote-assist session) — and SMB auth to the file server happens as THAT account, whose per-share permissions differ from the signed-in user's. - MSI: launch via explorer.exe, which hands the launch to the session shell so the server always starts as the actual desktop user. - Windows: when stat is denied, hand the path to Explorer anyway — Explorer runs as the desktop user, so the folder opens with THEIR permissions. FindFirstFile (parent-list rights only) picks open vs reveal; an unknown type is revealed with /select, never executed. - New 403 "access_denied" error code on /open + npm client type, so web clients can show actionable help instead of the raw Go error. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bug
Two IAP users hit
stat "\\\\storage\\...": CreateFile \\storage\...: Access is denied.on storage folders they could open manually in Explorer without issue — and only on some shares (AACC / U.S. DOD Coins / CCN failed, Plus worked).Root cause
The per-machine MSI's
LaunchAppcustom action runs in the elevated execute sequence, so after an install/upgrade the server keeps the installer's identity — the admin account typed at the UAC prompt, or an IT remote-assist session. SMB auth to\\storagethen happens as that account, whose per-share permissions differ from the signed-in user's. Broadly-permissioned shares kept working; restricted ones denied. Manual Explorer navigation (as the real user) worked, which is exactly the reported symptom.Fixes
LaunchAppnow launches via[WindowsFolder]explorer.exe "...folder-opener.exe". Explorer hands the launch to the session shell, so the server always starts as the actual desktop user. Session-less contexts (GPO machine install at boot) remain a no-op with the HKLM Run value picking it up at first login, as before.os.Statfails with ERROR_ACCESS_DENIED, hand the path to Explorer anyway — Explorer runs as the desktop user, so the folder still opens with their permissions (and if even they lack access, Explorer shows its native permission dialog).FindFirstFile(which needs only parent-list rights) distinguishes dir vs file; an unknown type is revealed with/selectrather than opened, so a localhost caller can never make the server execute a file it can't even stat.access_deniederror code (HTTP 403) onPOST /open+ the npm client'sErrorCodeunion, so web clients can show actionable help instead of the raw Go error.Verification
go build ./... && go vet ./... && go test ./...green, plusGOOS=windowsandGOOS=linux CGO_ENABLED=0cross-buildsaccess_deniedmapping without invoking a real file browsernpm run build)🤖 Generated with Claude Code