03-oct: superguardado automático
This commit is contained in:
59
scripts/bootstrap_autologon_juanjo.ps1
Normal file
59
scripts/bootstrap_autologon_juanjo.ps1
Normal file
@@ -0,0 +1,59 @@
|
||||
# bootstrap_autologon_juanjo.ps1
|
||||
# Migra la infraestructura a la cuenta local de autologon (juanjo).
|
||||
# Se ejecuta UNA sola vez, en el primer inicio de sesion de juanjo (via RunOnce HKLM).
|
||||
# No requiere administrador (registra tareas del usuario actual + config git de usuario).
|
||||
|
||||
$ErrorActionPreference = 'Continue'
|
||||
$log = Join-Path $env:USERPROFILE 'bootstrap_autologon.log'
|
||||
Start-Transcript -Path $log -Force | Out-Null
|
||||
Write-Output "=== BOOTSTRAP AUTOLOGON $(Get-Date -Format s) ==="
|
||||
Write-Output "Usuario: $env:USERDOMAIN\$env:USERNAME"
|
||||
|
||||
$infra = 'C:\Users\juanm\Documents\Github\INFRAESTRUCTURA'
|
||||
$bib = 'C:\Users\juanm\Documents\Github\biblioteca_negocio_prolongo'
|
||||
$pwsh = Join-Path $env:SystemRoot 'System32\WindowsPowerShell\v1.0\powershell.exe'
|
||||
|
||||
# 1) Git: identidad + safe.directory (los repos son de otro usuario) + helper
|
||||
git config --global user.name "juanminsanz"
|
||||
git config --global user.email "desarrollo@faccsa.es"
|
||||
git config --global --add safe.directory '*'
|
||||
git config --global credential.helper manager
|
||||
|
||||
# 2) Credenciales de Gitea reutilizando el token del remote de INFRAESTRUCTURA (sin mostrarlo)
|
||||
try {
|
||||
$remote = git -C $infra remote get-url origin 2>$null
|
||||
if ($remote -match 'https://([^:]+):([^@]+)@([^/]+)/') {
|
||||
$u = $matches[1]; $tok = $matches[2]; $hostname = $matches[3]
|
||||
$credPath = Join-Path $env:USERPROFILE '.git-credentials'
|
||||
"https://${u}:${tok}@${hostname}" | Set-Content -Path $credPath -Encoding ascii
|
||||
git config --global credential.helper store
|
||||
Write-Output "[OK] Credenciales git (store) configuradas."
|
||||
} else {
|
||||
Write-Output "[WARN] No se pudo extraer token del remote; se usara Git Credential Manager."
|
||||
}
|
||||
} catch { Write-Output "[WARN] credenciales git: $_" }
|
||||
|
||||
# 3) Instalar/registrar OmniRoute Watchdog + Monitor Estado + watchers para este usuario
|
||||
try {
|
||||
& (Join-Path $infra 'scripts\instalar_global.ps1')
|
||||
Write-Output "[OK] instalar_global.ps1 ejecutado."
|
||||
} catch { Write-Output "[ERROR] instalar_global.ps1: $_" }
|
||||
|
||||
# 4) MorningRoutine Prolongo para este usuario (abre apps al iniciar sesion)
|
||||
try {
|
||||
if (Get-ScheduledTask -TaskName 'MorningRoutine Prolongo' -ErrorAction SilentlyContinue) {
|
||||
Unregister-ScheduledTask -TaskName 'MorningRoutine Prolongo' -Confirm:$false
|
||||
}
|
||||
$action = New-ScheduledTaskAction -Execute $pwsh -Argument "-WindowStyle Hidden -ExecutionPolicy Bypass -File `"$infra\scripts\morning_routine\arranque_apps.ps1`""
|
||||
$trigger = New-ScheduledTaskTrigger -AtLogOn -User $env:USERNAME
|
||||
$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries -StartWhenAvailable -MultipleInstances IgnoreNew
|
||||
$principal = New-ScheduledTaskPrincipal -UserId "$env:USERDOMAIN\$env:USERNAME" -LogonType Interactive -RunLevel Limited
|
||||
Register-ScheduledTask -TaskName 'MorningRoutine Prolongo' -Action $action -Trigger $trigger -Settings $settings -Principal $principal -Description 'Abre apps al iniciar sesion (migrado a cuenta autologon).' -Force | Out-Null
|
||||
Write-Output "[OK] MorningRoutine Prolongo registrada."
|
||||
} catch { Write-Output "[ERROR] MorningRoutine: $_" }
|
||||
|
||||
Write-Output "--- TAREAS REGISTRADAS ---"
|
||||
Get-ScheduledTask | Where-Object { $_.TaskName -match 'OmniRoute|Monitor Estado|Telegram Watcher|Recordatorios|Shutdown Listener|MorningRoutine' } | Select-Object TaskName,State | Format-Table -AutoSize
|
||||
|
||||
Write-Output "=== FIN BOOTSTRAP $(Get-Date -Format s) ==="
|
||||
Stop-Transcript | Out-Null
|
||||
@@ -31,6 +31,30 @@ if (-not $Password) {
|
||||
[System.Runtime.InteropServices.Marshal]::ZeroFreeBSTR($BSTR)
|
||||
}
|
||||
|
||||
# Verificar la contraseña ANTES de escribir (evita guardar una credencial incorrecta,
|
||||
# que es lo que dejaba el arranque colgado en la pantalla de login)
|
||||
Write-Host "`nVerificando credenciales..." -ForegroundColor Cyan
|
||||
$credencialOk = $false
|
||||
$tmpVerify = Join-Path $env:TEMP "autologon_verify_$PID.txt"
|
||||
Remove-Item $tmpVerify -ErrorAction SilentlyContinue
|
||||
try {
|
||||
$sec = ConvertTo-SecureString $Password -AsPlainText -Force
|
||||
$cred = New-Object System.Management.Automation.PSCredential("$computername\$username", $sec)
|
||||
Start-Process cmd -ArgumentList "/c whoami > `"$tmpVerify`"" -Credential $cred -Wait -WindowStyle Hidden -ErrorAction Stop
|
||||
Start-Sleep -Milliseconds 500
|
||||
$credencialOk = (Test-Path $tmpVerify)
|
||||
} catch {
|
||||
$credencialOk = $false
|
||||
} finally {
|
||||
Remove-Item $tmpVerify -ErrorAction SilentlyContinue
|
||||
}
|
||||
if (-not $credencialOk) {
|
||||
Write-Host "[ERROR] La contraseña NO es correcta para $computername\$username." -ForegroundColor Red
|
||||
Write-Host " No se ha modificado el registro. Comprueba la contraseña e inténtalo de nuevo." -ForegroundColor Red
|
||||
exit 1
|
||||
}
|
||||
Write-Host "[OK] Contraseña verificada." -ForegroundColor Green
|
||||
|
||||
# Mostrar lo que se va a configurar (SIN mostrar la contraseña)
|
||||
Write-Host "`nSe configurará autologon con:" -ForegroundColor Cyan
|
||||
Write-Host " AutoAdminLogon: 1" -ForegroundColor White
|
||||
|
||||
Reference in New Issue
Block a user