【发布时间】:2021-04-20 17:34:25
【问题描述】:
我有一个旨在为用户添加读取/执行权限的应用程序。它似乎有效,但实际上无效。
我有以下代码:
string folderName = @"\\ShareDrive\MyDepartment\someFolder";
DirectorySecurity ds = new DirectoryInfo(folderName).GetAccessControl(AccessControlSections.Access);
AuthorizationRuleCollection rules = ds.GetAccessRules(true, true, typeof(NTAccount));
ds.AddAccessRule(
new FileSystemAccessRule(
"SomeValidUser@myCompany.com",
FileSystemRights.ReadAndExecute,
InheritanceFlags.ContainerInherit | InheritanceFlags.ObjectInherit,
PropagationFlags.None,
AccessControlType.Allow));
rules = ds.GetAccessRules(true, true, typeof(NTAccount));
//when I examine the value of 'rules' after executing the above statement, it appears the person has been added with
//the correct identity reference (successfully translated the email address)
执行此代码后,如果我在 Windows 文件资源管理器中检查权限,则此人尚未添加。这实际上是意料之中的,因为如果我尝试在文件资源管理器中添加此人,我会收到拒绝访问错误。我期待 AddAccessRule 抛出异常。
我的问题是:如何在 C# 中检查操作是否实际成功?
【问题讨论】: