【问题标题】:DirectorySecurity.AddAccessRule Appears to work, but really doesn'tDirectorySecurity.AddAccessRule 看起来有效,但实际上没有
【发布时间】:2021-04-20 17:34:25
【问题描述】:

我有一个旨在为用户添加读取/执行权限的应用程序。它似乎有效,但实际上无效。

我有以下代码:

string folderName = @"\\ShareDrive\MyDepartment\someFolder";
        DirectorySecurity ds = new DirectoryInfo(folderName).GetAccessControl(AccessControlSections.Access);
            AuthorizationRuleCollection rules = ds.GetAccessRules(true, true, typeof(NTAccount));

        ds.AddAccessRule(
            new FileSystemAccessRule(
                "SomeValidUser@myCompany.com",
                FileSystemRights.ReadAndExecute,
                InheritanceFlags.ContainerInherit | InheritanceFlags.ObjectInherit,
                PropagationFlags.None,
                AccessControlType.Allow));

        
        rules = ds.GetAccessRules(true, true, typeof(NTAccount));
        //when I examine the value of 'rules' after executing the above statement, it appears the person has been added with
        //the correct identity reference (successfully translated the email address)

执行此代码后,如果我在 Windows 文件资源管理器中检查权限,则此人尚未添加。这实际上是意料之中的,因为如果我尝试在文件资源管理器中添加此人,我会收到拒绝访问错误。我期待 AddAccessRule 抛出异常。

我的问题是:如何在 C# 中检查操作是否实际成功?

【问题讨论】:

    标签: c# file security


    【解决方案1】:

    您需要调用 SetAccessControl() 并传入修改后的 DirectorySecurity 对象才能实际应用您的更改。

    【讨论】:

    • SetAccessControl() 抛出预期的异常。它是 System.IO.FileSystemAclExtensions 的一个功能,仅在 .net 5 中可用,所以我必须将我的应用程序转换为 .net(而不是 .net 框架)
    • @MarkAinsworth 在 .NET Framework 中还有 DirectoryInfo.SetAccessControl()。
    猜你喜欢
    • 1970-01-01
    • 2011-11-01
    • 1970-01-01
    • 1970-01-01
    • 2020-03-27
    • 1970-01-01
    • 1970-01-01
    • 2015-01-02
    • 1970-01-01
    相关资源
    最近更新 更多