Directory.SetAccessControl(String, DirectorySecurity) Método

Definición

Aplica al directorio especificado las entradas de la lista de control de acceso (ACL) descritas por un objeto DirectorySecurity.Applies access control list (ACL) entries described by a DirectorySecurity object to the specified directory.

public:
 static void SetAccessControl(System::String ^ path, System::Security::AccessControl::DirectorySecurity ^ directorySecurity);
public static void SetAccessControl (string path, System.Security.AccessControl.DirectorySecurity directorySecurity);
static member SetAccessControl : string * System.Security.AccessControl.DirectorySecurity -> unit

Parámetros

path
String

Directorio al que se van a agregar o del que se van a quitar entradas de la lista de control de acceso (ACL).A directory to add or remove access control list (ACL) entries from.

directorySecurity
DirectorySecurity

Objeto DirectorySecurity que describe una entrada de ACL que se aplica al directorio descrito por el parámetro path.A DirectorySecurity object that describes an ACL entry to apply to the directory described by the path parameter.

Excepciones

El parámetro directorySecurity es null.The directorySecurity parameter is null.

No se ha encontrado el directorio.The directory could not be found.

path no fue válido.The path was invalid.

El proceso actual no tiene acceso al directorio especificado por path.The current process does not have access to the directory specified by path.

o bien-or- El proceso actual no tiene privilegios suficientes para establecer la entrada ACL.The current process does not have sufficient privilege to set the ACL entry.

El sistema operativo actual no es Windows 2000 o posterior.The current operating system is not Windows 2000 or later.

Ejemplos

En el ejemplo siguiente se utilizan los métodos GetAccessControl y SetAccessControl para agregar una entrada de la lista de control de acceso (ACL) y, a continuación, quitar una entrada de la ACL de un directorio.The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. Para ejecutar este ejemplo, debe proporcionar una cuenta de usuario o grupo válida.You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }
    }
}

Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

Comentarios

El método SetAccessControl aplica las entradas de la lista de control de acceso (ACL) a un archivo que representa la lista ACL no heredada.The SetAccessControl method applies access control list (ACL) entries to a file that represents the noninherited ACL list.

Precaución

La ACL especificada para el parámetro directorySecurity reemplaza a la ACL existente para el directorio.The ACL specified for the directorySecurity parameter replaces the existing ACL for the directory. Para agregar permisos para un nuevo usuario, use el método GetAccessControl para obtener la ACL existente y modificarla.To add permissions for a new user, use the GetAccessControl method to obtain the existing ACL and modify it.

Una ACL describe los usuarios o grupos que tienen o no tienen derechos sobre acciones específicas en el archivo o directorio especificado.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Para más información, consulte How to: Add or Remove Access Control List Entries (Cómo: Agregar o quitar entradas de la lista de control de acceso).For more information, see How to: Add or Remove Access Control List Entries.

El método SetAccessControl conserva solo DirectorySecurity objetos que se han modificado después de la creación del objeto.The SetAccessControl method persists only DirectorySecurity objects that have been modified after object creation. Si no se ha modificado un objeto de DirectorySecurity, no se conservará en un archivo.If a DirectorySecurity object has not been modified, it will not be persisted to a file. Por lo tanto, no es posible recuperar un objeto de DirectorySecurity de un archivo y volver a aplicar el mismo objeto a otro archivo.Therefore, it is not possible to retrieve a DirectorySecurity object from one file and reapply the same object to another file.

Para copiar la información de la ACL de un archivo a otro:To copy ACL information from one file to another:

  1. Utilice el método GetAccessControl para recuperar el objeto de DirectorySecurity del archivo de código fuente.Use the GetAccessControl method to retrieve the DirectorySecurity object from the source file.

  2. Cree un nuevo objeto de DirectorySecurity para el archivo de destino.Create a new DirectorySecurity object for the destination file.

  3. Use el método GetSecurityDescriptorBinaryForm o GetSecurityDescriptorSddlForm del objeto de DirectorySecurity de origen para recuperar la información de la ACL.Use the GetSecurityDescriptorBinaryForm or GetSecurityDescriptorSddlForm method of the source DirectorySecurity object to retrieve the ACL information.

  4. Use el método SetSecurityDescriptorBinaryForm o SetSecurityDescriptorSddlForm para copiar la información recuperada en el paso 3 en el objeto de DirectorySecurity de destino.Use the SetSecurityDescriptorBinaryForm or SetSecurityDescriptorSddlForm method to copy the information retrieved in step 3 to the destination DirectorySecurity object.

  5. Establezca el objeto de DirectorySecurity de destino en el archivo de destino mediante el método SetAccessControl.Set the destination DirectorySecurity object to the destination file using the SetAccessControl method.

En entornos NTFS, ReadAttributes y ReadExtendedAttributes se conceden al usuario si el usuario tiene derechos ListDirectory en la carpeta principal.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. Para denegar ReadAttributes y ReadExtendedAttributes, deniegue ListDirectory en el directorio principal.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Seguridad

FileIOPermission
para obtener permiso para enumerar la lista de control de acceso (ACL) para un directorio.for permission to enumerate access control list (ACL) for a directory. Enumeraciones asociadas: NoAccess, ViewAssociated enumerations: NoAccess , View Acción de seguridad: demanda.Security action: Demand.

Se aplica a

Consulte también: