Skip to content

machine-health: approved_by persists a literal double backslash in Get-ApprovalState #3369

Description

@kyle-sexton

Context

plugins/machine-health/skills/audit/scripts/windows/lib/Get-ApprovalState.ps1:68 builds the approver identity as:

$approvedBy = "$env:COMPUTERNAME\\$env:USERNAME"

PowerShell double-quoted strings do not treat backslash as an escape character, so \\ is two literal backslashes and approved_by persists as HOST\\user instead of the conventional HOST\user. Cost of leaving it: every persisted approval record carries a malformed identity, and any later comparison against a correctly formed DOMAIN\user string (or display of the field) is off by one backslash.

Proposed work

  • Change the interpolation to a single backslash: "$env:COMPUTERNAME\$env:USERNAME".
  • Decide whether existing persisted records with \\ need a one-time normalization on read.

Acceptance criteria

  • Newly persisted approvals record approved_by as COMPUTERNAME\USERNAME with exactly one backslash.
  • Any consumer that matches on approved_by handles (or migrates) previously persisted double-backslash values, or the owner explicitly waives this.

References

  • plugins/machine-health/skills/audit/scripts/windows/lib/Get-ApprovalState.ps1:68
  • Found by the batch-simplify sweep on branch claude/code-tidying-batch-simplify-s7ljbi; deliberately not fixed there because the sweep was behavior-preserving.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority: highSignificant impact, or blocks an imminent release; staff this cycle.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions