$ErrorActionPreference = 'Stop' $path = 'C:\yutongda\secure\application-database-credentials.json' if (-not (Test-Path -LiteralPath $path)) { throw 'Application database credential file missing' } $acl = New-Object System.Security.AccessControl.FileSecurity $acl.SetAccessRuleProtection($true, $false) foreach ($identity in @('BUILTIN\Administrators', 'NT AUTHORITY\SYSTEM')) { $rule = New-Object System.Security.AccessControl.FileSystemAccessRule($identity, 'FullControl', 'Allow') $acl.AddAccessRule($rule) } Set-Acl -LiteralPath $path -AclObject $acl $json = Get-Content -Raw -LiteralPath $path | ConvertFrom-Json [ordered]@{ status = 'PASS' path = $path sha256 = (Get-FileHash -LiteralPath $path -Algorithm SHA256).Hash keys = @($json.PSObject.Properties.Name) contains_admin_credentials = ($json.PSObject.Properties.Name -contains 'mysql_root' -or $json.PSObject.Properties.Name -contains 'postgres_admin') secrets_in_output = $false } | ConvertTo-Json -Compress