Set-DbaLogin - Stop eating the caller loop on an invalid parameter combination - #10737
Merged
Merged
Conversation
…mbination Six parameter checks in the begin block used Stop-Function -Continue with no enclosing loop, so the continue escaped the command and consumed an iteration of the caller's loop. Every failed check now stops and returns. (do Set-DbaLogin) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
andreasjordan
marked this pull request as ready for review
September 24, 2026 12:48
potatoqualitee
approved these changes
Sep 25, 2026
potatoqualitee
left a comment
Member
There was a problem hiding this comment.
Reviewed the exact head, full patch, intended caller-loop behavior, surrounding validation/interrupt flow, tests, discussions, and CI. The begin-block validation now terminates this invocation without escaping the caller loop, preserves exception behavior, and acquires no resources before returning. The focused regressions cover all three iterations and existing real-SQL tests cover valid operations and multi-input paths. All current checks are successful except the intentionally skipped cross-platform Windows job. No material defect found.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #10638, and its last open entry: once this merges, all 91 sites of the inventory are fixed or triaged, and the issue can be closed.
The bug
Six parameter checks in the
beginblock ofSet-DbaLogincalledStop-Function -Continue:-NewNameequal to-Login-Enablewith-Disable-GrantLoginwith-DenyLogin-SecurePasswordwith-PasswordHash-PasswordHashwith-PasswordMustChange-PasswordHashthat is not hexadecimalThe
beginblock has no loop around these checks, so without-EnableExceptionthecontinueescaped the command and consumed an iteration of whatever loop the caller was running. Aforeachover three elements that callsSet-DbaLoginwith one of these combinations completes zero iterations.These sites waited for #10537, which touched the same file and merged on 2026-09-22.
What changed
The
-Continueis dropped and every failed check in thebeginblock ends withreturn, as in #10637. Theprocessblock is already guarded byTest-FunctionInterrupt. The four checks that had no-Continuealso return now, so only the first failed check warns instead of every one after it.Tests
One new test per check (
-ForEachover the six combinations): three calls in a loop, asserting the loop count and the warning. The calls never connect to the instance, because the command stops in thebeginblock.Through the testing-dbatools harness: 51/51 on pwsh 7 and on Windows PowerShell 5.1. With the command change reverted, exactly the six new tests fail with
Expected 3, but got 0.created by Claude and reviewed by Andreas Jordan
🤖 Generated with Claude Code