Directory.GetAccessControl Método

Definición

Devuelve la lista de control de acceso (ACL) de Windows para un directorio.Returns the Windows access control list (ACL) for a directory.

Sobrecargas

GetAccessControl(String)

Obtiene un objeto DirectorySecurity que encapsula las entradas de la lista de control de acceso (ACL) para un directorio especificado.Gets a DirectorySecurity object that encapsulates the access control list (ACL) entries for a specified directory.

GetAccessControl(String, AccessControlSections)

Obtiene un objeto DirectorySecurity que encapsula el tipo especificado de las entradas de la lista de control de acceso (ACL) para un directorio especificado.Gets a DirectorySecurity object that encapsulates the specified type of access control list (ACL) entries for a specified directory.

GetAccessControl(String)

Obtiene un objeto DirectorySecurity que encapsula las entradas de la lista de control de acceso (ACL) para un directorio especificado.Gets a DirectorySecurity object that encapsulates the access control list (ACL) entries for a specified directory.

public:
 static System::Security::AccessControl::DirectorySecurity ^ GetAccessControl(System::String ^ path);
public static System.Security.AccessControl.DirectorySecurity GetAccessControl (string path);
static member GetAccessControl : string -> System.Security.AccessControl.DirectorySecurity
Public Shared Function GetAccessControl (path As String) As DirectorySecurity

Parámetros

path
String

Ruta de acceso a un directorio que contiene un objeto DirectorySecurity que describe la información de la lista de control de acceso (ACL) del archivo.The path to a directory containing a DirectorySecurity object that describes the file's access control list (ACL) information.

Devoluciones

Objeto que encapsula las reglas de control de acceso correspondientes al archivo descrito por el parámetro path.An object that encapsulates the access control rules for the file described by the path parameter.

Excepciones

El parámetro path es null.The path parameter is null.

Se ha producido un error de E/S al abrir el directorio.An I/O error occurred while opening the directory.

El sistema operativo actual no es Windows 2000 o posterior.The current operating system is not Windows 2000 or later.

Se produjo un error en el nivel del sistema, como que no se encontró el directorio.A system-level error occurred, such as the directory could not be found. La excepción específica puede ser una subclase de SystemException.The specific exception may be a subclass of SystemException.

El parámetro path especificó un directorio que es de solo lectura.The path parameter specified a directory that is read-only.

o bien-or- Esta operación no es compatible con la plataforma actual.This operation is not supported on the current platform.

o bien-or- El llamador no dispone del permiso requerido.The caller does not have the required permission.

Ejemplos

En el ejemplo siguiente se utilizan los métodos GetAccessControl y SetAccessControl para agregar una entrada de la lista de control de acceso (ACL) y, a continuación, quitar una entrada de la ACL de un directorio.The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. Para ejecutar este ejemplo, debe proporcionar una cuenta de usuario o grupo válida.You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }
    }
}

Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

Comentarios

Use el método GetAccessControl para recuperar las entradas de la lista de control de acceso (ACL) para un directorio.Use the GetAccessControl method to retrieve the access control list (ACL) entries for a directory.

Una ACL describe los usuarios o grupos que tienen o no tienen derechos sobre acciones específicas en el archivo o directorio especificado.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Para más información, consulte How to: Add or Remove Access Control List Entries (Cómo: Agregar o quitar entradas de la lista de control de acceso).For more information, see How to: Add or Remove Access Control List Entries.

En entornos NTFS, ReadAttributes y ReadExtendedAttributes se conceden al usuario si el usuario tiene derechos ListDirectory en la carpeta principal.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. Para denegar ReadAttributes y ReadExtendedAttributes, deniegue ListDirectory en el directorio principal.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Seguridad

FileIOPermission
para obtener permiso para enumerar la lista de control de acceso (ACL) para un directorio.for permission to enumerate access control list (ACL) for a directory. Enumeraciones asociadas: NoAccess, ViewAssociated enumerations: NoAccess , View Acción de seguridad: demanda.Security action: Demand.

GetAccessControl(String, AccessControlSections)

Obtiene un objeto DirectorySecurity que encapsula el tipo especificado de las entradas de la lista de control de acceso (ACL) para un directorio especificado.Gets a DirectorySecurity object that encapsulates the specified type of access control list (ACL) entries for a specified directory.

public:
 static System::Security::AccessControl::DirectorySecurity ^ GetAccessControl(System::String ^ path, System::Security::AccessControl::AccessControlSections includeSections);
public static System.Security.AccessControl.DirectorySecurity GetAccessControl (string path, System.Security.AccessControl.AccessControlSections includeSections);
static member GetAccessControl : string * System.Security.AccessControl.AccessControlSections -> System.Security.AccessControl.DirectorySecurity
Public Shared Function GetAccessControl (path As String, includeSections As AccessControlSections) As DirectorySecurity

Parámetros

path
String

Ruta de acceso a un directorio que contiene un objeto DirectorySecurity que describe la información de la lista de control de acceso (ACL) del archivo.The path to a directory containing a DirectorySecurity object that describes the file's access control list (ACL) information.

includeSections
AccessControlSections

Uno de los valores AccessControlSections que especifica el tipo de información de la lista de control de acceso (ACL) que se recibe.One of the AccessControlSections values that specifies the type of access control list (ACL) information to receive.

Devoluciones

Objeto que encapsula las reglas de control de acceso correspondientes al archivo descrito por el parámetro path.An object that encapsulates the access control rules for the file described by the path parameter.

Excepciones

El parámetro path es null.The path parameter is null.

Se ha producido un error de E/S al abrir el directorio.An I/O error occurred while opening the directory.

El sistema operativo actual no es Windows 2000 o posterior.The current operating system is not Windows 2000 or later.

Se produjo un error en el nivel del sistema, como que no se encontró el directorio.A system-level error occurred, such as the directory could not be found. La excepción específica puede ser una subclase de SystemException.The specific exception may be a subclass of SystemException.

El parámetro path especificó un directorio que es de solo lectura.The path parameter specified a directory that is read-only.

o bien-or- Esta operación no es compatible con la plataforma actual.This operation is not supported on the current platform.

o bien-or- El llamador no dispone del permiso requerido.The caller does not have the required permission.

Comentarios

Use el método GetAccessControl para recuperar las entradas de la lista de control de acceso (ACL) para un directorio.Use the GetAccessControl method to retrieve the access control list (ACL) entries for a directory.

Una ACL describe los usuarios o grupos que tienen o no tienen derechos sobre acciones específicas en el archivo o directorio especificado.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Para más información, consulte How to: Add or Remove Access Control List Entries (Cómo: Agregar o quitar entradas de la lista de control de acceso).For more information, see How to: Add or Remove Access Control List Entries.

En entornos NTFS, ReadAttributes y ReadExtendedAttributes se conceden al usuario si el usuario tiene derechos ListDirectory en la carpeta principal.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. Para denegar ReadAttributes y ReadExtendedAttributes, deniegue ListDirectory en el directorio principal.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Seguridad

FileIOPermission
para obtener permiso para enumerar la lista de control de acceso (ACL) para un directorio.for permission to enumerate access control list (ACL) for a directory. Enumeraciones asociadas: NoAccess, ViewAssociated enumerations: NoAccess , View Acción de seguridad: demanda.Security action: Demand.

Se aplica a