Skip to content

PoshUI v1.3.1

Choose a tag to compare

@Kanders-II Kanders-II released this 19 Jun 16:53
· 16 commits to main since this release

πŸ”’ PoshUI v1.3.1 β€” Security Hardening & Bug Fixes

Drop-in upgrade. No changes to the public cmdlet API β€” all existing scripts work without modification.


πŸ›‘οΈ Security Fixes

Script Injection Prevention in ConvertTo-UIScript

ConvertTo-UIScript (PoshUI.Wizard and PoshUI.Workflow) now escapes every interpolated value β€” titles, labels, choices, defaults, branding keys/values, step metadata, and card/banner properties β€” for safe embedding in single-quoted PowerShell literals, and validates control/step names as safe identifiers.

Previously, a value containing a single quote (or one sourced from dynamic/external data) could break out of the generated string and execute arbitrary code when the wizard ran.

Repaired Value Escaper

ConvertTo-SafeScriptValue's boolean branch used return if (...), which threw a runtime error. Fixed across all three modules.

Removed Predictable Script Disclosure

Show-PoshUIWizard / Show-PoshUIWorkflow no longer write the generated script to a predictable %TEMP%\PoshUI_*.ps1 path on every run. The debug dump is now gated behind -AppDebug and written via a hardened secure-temp helper (cryptographically random filename + restrictive ACL).

Stronger Workflow-State Integrity

Protect-WorkflowState now uses DPAPI authenticated encryption instead of an HMAC keyed on guessable values (username + computer name). State files are written in the new POSHUI_STATE_V2 format; legacy V1 files are still read.

Signature Policy No Longer Downgraded

Calling Show-* without -RequireSignedScripts no longer forces POSHUI_SIGNATURE_MODE=Disabled over a stricter environment or organization policy setting β€” the prior value is respected and restored.

Temp-Directory Hardening

New-SecureTempFile / New-SecureTempScript now re-assert the restrictive directory ACL on every run, not only when the directory is first created.

Secret Redaction in Persisted State

Set-UIState now redacts fields with secret-sounding names (password, token, credential, etc.) and any SecureString / PSCredential values before writing form data to the registry.


πŸ› Bug Fixes

  • Fixed OptionGroup attribute being dropped β€” a stray } else { in ConvertTo-UIScript made the [WizardOptionGroup(...)] attribute (choices + orientation) unreachable; OptionGroup controls now render correctly in generated scripts
  • Fixed Date default double-append β€” a DateTime default value was emitted twice, producing a malformed parameter default; date defaults now render exactly once (DateTime formatted as yyyy-MM-dd, string values passed through unchanged)
  • Fixed verbose logging β€” corrected ${var.Length} string interpolation in workflow state encryption log messages

πŸ“¦ What's Included

PoshUI/
β”œβ”€β”€ PoshUI.Wizard/          # Wizard module (hardened script generator)
β”œβ”€β”€ PoshUI.Dashboard/       # Dashboard module
β”œβ”€β”€ PoshUI.Workflow/        # Workflow module (DPAPI state, hardened generator)
β”œβ”€β”€ Examples/               # All v1.3.0 examples (unchanged)
β”œβ”€β”€ Docs/                   # Documentation site
β”œβ”€β”€ bin/                    # Signed PoshUI.exe v1.3.1
└── README.md

⚠️ Upgrade Note

Workflow state files saved by v1.3.1 use the new POSHUI_STATE_V2 format and cannot be read by v1.3.0 or earlier. Any in-progress workflows should be completed before upgrading. State files written by older versions continue to work normally.


πŸš€ Installation

  1. Download the release package
  2. Extract to your preferred location
  3. Import the module you need:
# For Wizards
Import-Module .\PoshUI\PoshUI.Wizard\PoshUI.Wizard.psd1

# For Dashboards
Import-Module .\PoshUI\PoshUI.Dashboard\PoshUI.Dashboard.psd1

# For Workflows
Import-Module .\PoshUI\PoshUI.Workflow\PoshUI.Workflow.psd1

πŸ› οΈ System Requirements

Requirement Version
Operating System Windows 10/11 (64-bit)
PowerShell Windows PowerShell 5.1
.NET Framework 4.8 (included with Windows 10/11)
Permissions User-level (no admin required for most features)

πŸ“– Documentation

Full documentation: https://kanders-ii.github.io/PoshUI/


🀝 Getting Help


Made with ❀️ for the PowerShell Community

Documentation β€’ GitHub β€’ Report Issue