You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell脚本排查:通过GPO部署Java exception.sites失败

问题排查与修复建议

问题描述

我正尝试通过GPO将exception.sites文件添加到用户的Java文件夹中,让Edge兼容模式无需用户干预即可运行(我们有大量遗留应用和用户,自动化此操作十分必要)。脚本看似运行无报错,但只有最后一行控制代码(复制文件到c:\Temp\Running\)能可靠执行,所有if-else分支均未触发,用于跟踪的复制操作都未生效。

原脚本

$Source = '\\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites'
$users = (Get-ChildItem 'c:\Users\').name
$JavaFolder = \"C:\Program Files\Java\"
$isJava = $false
$SEL = \"Select string\"
$DAFMComputer = \"ControlPC\"

#Do PC check to apply to only one PC 
if ($DAFMComputer -like \"ControlPC\")
{
if (JavaPath -Path $JavaFolder) #if Java is installed
  {
    Foreach ($user in $users)
    {
        if (FileExists -Path \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\") #check for the file
        {
            $SEL = Select-String -Path \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\" -Pattern https://agapps.agriculture.gov.ie #Check for the string pattern

            if ($SEL -ne $null)
            {
                #do nothing as the exception file exists with the URL we need do nothing
                Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\AlreadyThere\"
            }
            else
            {
                #add the following lines.
                Add-Content \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\" \"`nhttps://app.company.com/\"
                Add-Content \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\" \"`nhttps://app.company.com/\"
                Add-Content \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\" \"`We are adding lines\"                
                Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\FileExistsAddlines\"
            }

        }
        else #file does not exist
        {

             Copy-Item -Path $Source -Destination \"c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites\" -force
             Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\Filecopy\"          
        }            

    }
    } # end file copy.
    else
    {
      #No Java Do nothing    
      Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\NoJavaDoNothing\"
    }
  else
  {
  Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\NoComputerMatch\"
  #do nothing as the PC name does not match
  }
}
#Control line showing the script runs.
Copy-Item -Path \\thepath\Policies\{1FA921CE-231E-4982-8EBA-29E3AD4A44EF}\Machine\Scripts\Startup\exception.sites -Destination \"c:\Temp\Running\"

核心问题与修复步骤

  • 错误1:使用了不存在的PowerShell命令
    脚本中JavaPath和FileExists并非PowerShell内置命令,判断路径/文件存在必须用Test-Path:

    • 判断Java是否安装:替换if (JavaPath -Path $JavaFolder)为if (Test-Path $JavaFolder)
    • 判断文件是否存在:替换if (FileExists -Path "...")为if (Test-Path -Path "c:\Users\$user\AppData\LocalLow\Sun\Java\Deployment\security\exception.sites" -PathType Leaf)(-PathType Leaf确保是文件而非文件夹)
  • 错误2:多余的引号转义
    脚本中所有\"都是无效转义,会导致路径解析错误,直接删除转义符,比如:

    • $JavaFolder = "C:\Program Files\Java"
    • if ($DAFMComputer -like "ControlPC")
  • 错误3:计算机名判断逻辑无效
    当前写法$DAFMComputer = "ControlPC"然后判断是否等于自身,永远为真。若要判断当前机器是否为目标PC,应获取实际计算机名:

    $currentPC = $env:COMPUTERNAME
    if ($currentPC -eq "ControlPC")
    
  • 错误4:重复路径维护困难
    多次重复写源文件路径,直接用已定义的$Source变量替换,比如:

    Copy-Item -Path $Source -Destination "c:\Temp\AlreadyThere"
    
  • 权限与执行时机问题
    GPO启动脚本以系统账户运行,访问用户AppData文件夹可能有权限限制。建议改用用户登录脚本(以用户权限执行),避免权限问题;若必须用启动脚本,需确保系统账户对所有用户LocalLow\Sun\Java目录有读写权限。

  • 调试优化
    添加日志输出定位问题,比如在关键节点写入日志文件:

    $logPath = "c:\Temp\java_exception_script.log"
    Write-Output "[$(Get-Date)] 脚本开始执行" | Out-File -Path $logPath -Append
    Write-Output "[$(Get-Date)] 当前计算机名: $currentPC" | Out-File -Path $logPath -Append
    Write-Output "[$(Get-Date)] Java文件夹存在性: $(Test-Path $JavaFolder)" | Out-File -Path $logPath -Append
    

    同时设置错误停止:$ErrorActionPreference = "Stop",让脚本遇到错误立即终止,便于定位问题点。

内容的提问来源于stack exchange,提问作者user19951896

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 06:10:50