Directory.SetAccessControl(String, DirectorySecurity) Metodo

Definizione

Applica le voci dell'elenco di controllo di accesso (ACL) descritte da un oggetto DirectorySecurity nella directory specificata.Applies access control list (ACL) entries described by a DirectorySecurity object to the specified directory.

public:
 static void SetAccessControl(System::String ^ path, System::Security::AccessControl::DirectorySecurity ^ directorySecurity);
public static void SetAccessControl (string path, System.Security.AccessControl.DirectorySecurity directorySecurity);
static member SetAccessControl : string * System.Security.AccessControl.DirectorySecurity -> unit
Public Shared Sub SetAccessControl (path As String, directorySecurity As DirectorySecurity)

Parametri

path
String

Directory cui aggiungere o rimuovere le voci dell'elenco di controllo di accesso (ACL).A directory to add or remove access control list (ACL) entries from.

directorySecurity
DirectorySecurity

Oggetto DirectorySecurity che descrive una voce ACL da applicare alla directory descritta dal parametro path.A DirectorySecurity object that describes an ACL entry to apply to the directory described by the path parameter.

Eccezioni

Il valore del parametro directorySecurity è null.The directorySecurity parameter is null.

Non è possibile trovare la directory.The directory could not be found.

path non valido.The path was invalid.

Il processo corrente non ha accesso alla directory specificata da path.The current process does not have access to the directory specified by path.

-oppure--or- Privilegi non sufficienti per impostare la voce ACL del processo corrente.The current process does not have sufficient privilege to set the ACL entry.

Esempio

Nell'esempio seguente vengono usati i GetAccessControl SetAccessControl metodi e per aggiungere una voce dell'elenco di controllo di accesso (ACL) e quindi rimuovere una voce ACL da una directory.The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. È necessario specificare un utente valido o un account di gruppo per eseguire questo esempio.You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings.
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);
        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings.
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);
        }
    }
}

Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

Commenti

Il SetAccessControl metodo applica le voci dell'elenco di controllo di accesso (ACL) a un file che rappresenta l'elenco ACL non ereditato.The SetAccessControl method applies access control list (ACL) entries to a file that represents the noninherited ACL list.

Attenzione

L'ACL specificato per il directorySecurity parametro sostituisce l'ACL esistente per la directory.The ACL specified for the directorySecurity parameter replaces the existing ACL for the directory. Per aggiungere autorizzazioni per un nuovo utente, utilizzare il GetAccessControl metodo per ottenere l'ACL esistente e modificarlo.To add permissions for a new user, use the GetAccessControl method to obtain the existing ACL and modify it.

Un ACL descrive i singoli utenti e/o i gruppi che dispongono o non dispongono di diritti per azioni specifiche sul file o sulla directory specificata.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Per altre informazioni, vedere Procedura: aggiungere o rimuovere voci dell'elenco di controllo di accesso (ACL).For more information, see How to: Add or Remove Access Control List Entries.

Il SetAccessControl metodo rende permanente solo DirectorySecurity gli oggetti che sono stati modificati dopo la creazione dell'oggetto.The SetAccessControl method persists only DirectorySecurity objects that have been modified after object creation. Se un DirectorySecurity oggetto non è stato modificato, non verrà salvato in modo permanente in un file.If a DirectorySecurity object has not been modified, it will not be persisted to a file. Non è quindi possibile recuperare un DirectorySecurity oggetto da un file e riapplicare lo stesso oggetto a un altro file.Therefore, it is not possible to retrieve a DirectorySecurity object from one file and reapply the same object to another file.

Per copiare le informazioni ACL da un file a un altro:To copy ACL information from one file to another:

  1. Utilizzare il GetAccessControl metodo per recuperare l' DirectorySecurity oggetto dal file di origine.Use the GetAccessControl method to retrieve the DirectorySecurity object from the source file.

  2. Creare un nuovo DirectorySecurity oggetto per il file di destinazione.Create a new DirectorySecurity object for the destination file.

  3. Utilizzare il GetSecurityDescriptorBinaryForm GetSecurityDescriptorSddlForm metodo o dell'oggetto di origine DirectorySecurity per recuperare le informazioni ACL.Use the GetSecurityDescriptorBinaryForm or GetSecurityDescriptorSddlForm method of the source DirectorySecurity object to retrieve the ACL information.

  4. Usare il SetSecurityDescriptorBinaryForm SetSecurityDescriptorSddlForm metodo o per copiare le informazioni recuperate nel passaggio 3 nell'oggetto di destinazione DirectorySecurity .Use the SetSecurityDescriptorBinaryForm or SetSecurityDescriptorSddlForm method to copy the information retrieved in step 3 to the destination DirectorySecurity object.

  5. Impostare l' DirectorySecurity oggetto di destinazione sul file di destinazione utilizzando il SetAccessControl metodo.Set the destination DirectorySecurity object to the destination file using the SetAccessControl method.

Negli ambienti NTFS ReadAttributes e ReadExtendedAttributes vengono concesse all'utente se l'utente dispone ListDirectory dei diritti per la cartella padre.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. Per negare ReadAttributes e ReadExtendedAttributes , negare ListDirectory nella directory padre.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Si applica a

Vedi anche