@echo off rem ================================================================== rem Locks the application folder down so ONLY Administrators and the rem SYSTEM account (which runs the portal's scheduled task) can read rem it. Normal / standard Windows users on this machine will get rem "Access denied" when trying to open the folder - protecting the rem source code and, far more importantly, the passwords in .env. rem rem >> RUN AS ADMINISTRATOR rem >> To undo: icacls "" /reset /T rem ================================================================== net session >nul 2>&1 if %ERRORLEVEL% NEQ 0 ( echo This script must be run as Administrator. pause exit /b 1 ) set "APPDIR=%~dp0.." for %%I in ("%APPDIR%") do set "APPDIR=%%~fI" echo Locking down: %APPDIR% echo Only SYSTEM and Administrators will keep access. Continue? (Ctrl+C to abort) pause icacls "%APPDIR%" /inheritance:r /grant:r "SYSTEM:(OI)(CI)F" "*S-1-5-32-544:(OI)(CI)F" if %ERRORLEVEL% NEQ 0 ( echo Failed - no changes may have been applied. pause exit /b 1 ) echo. echo Done. Standard users on this machine can no longer open the folder. echo The portal keeps working (its task runs as SYSTEM). echo To undo later: icacls "%APPDIR%" /reset /T pause