Directory.SetAccessControl(String, DirectorySecurity) Método

Definição

Aplica entradas de ACL (lista de controle de acesso) descritas por um objeto DirectorySecurity ao diretório especificado.Applies access control list (ACL) entries described by a DirectorySecurity object to the specified directory.

public:
 static void SetAccessControl(System::String ^ path, System::Security::AccessControl::DirectorySecurity ^ directorySecurity);
public static void SetAccessControl (string path, System.Security.AccessControl.DirectorySecurity directorySecurity);
static member SetAccessControl : string * System.Security.AccessControl.DirectorySecurity -> unit
Public Shared Sub SetAccessControl (path As String, directorySecurity As DirectorySecurity)

Parâmetros

path
String

Um diretório ao qual adicionar ou remover entradas de ACL (lista de controle de acesso).A directory to add or remove access control list (ACL) entries from.

directorySecurity
DirectorySecurity

Um objeto DirectorySecurity que descreve uma entrada de ACL a ser aplicada ao diretório descrito pelo parâmetro path.A DirectorySecurity object that describes an ACL entry to apply to the directory described by the path parameter.

Exceções

O parâmetro directorySecurity é null.The directorySecurity parameter is null.

Não foi possível encontrar o diretório.The directory could not be found.

O path era inválido.The path was invalid.

O processo atual não tem acesso ao diretório especificado por path.The current process does not have access to the directory specified by path.

- ou --or- O processo atual não tem privilégios suficientes para configurar a entrada de ACL.The current process does not have sufficient privilege to set the ACL entry.

Exemplos

O exemplo a seguir usa os GetAccessControl SetAccessControl métodos e para adicionar uma entrada de ACL (lista de controle de acesso) e, em seguida, remover uma entrada de ACL de um diretório.The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. Você deve fornecer uma conta de grupo ou de usuário válida para executar este exemplo.You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings.
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);
        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings.
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);
        }
    }
}

Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

Comentários

O SetAccessControl método aplica entradas de ACL (lista de controle de acesso) a um arquivo que representa a lista ACL não herdada.The SetAccessControl method applies access control list (ACL) entries to a file that represents the noninherited ACL list.

Cuidado

A ACL especificada para o directorySecurity parâmetro substitui a ACL existente para o diretório.The ACL specified for the directorySecurity parameter replaces the existing ACL for the directory. Para adicionar permissões para um novo usuário, use o GetAccessControl método para obter a ACL existente e modificá-la.To add permissions for a new user, use the GetAccessControl method to obtain the existing ACL and modify it.

Uma ACL descreve indivíduos e/ou grupos que têm ou não têm direitos sobre ações específicas no arquivo ou diretório determinado.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Para saber mais, confira Como adicionar ou remover entradas da lista de controle de acesso.For more information, see How to: Add or Remove Access Control List Entries.

O SetAccessControl método persiste somente os DirectorySecurity objetos que foram modificados após a criação do objeto.The SetAccessControl method persists only DirectorySecurity objects that have been modified after object creation. Se um DirectorySecurity objeto não tiver sido modificado, ele não será persistido em um arquivo.If a DirectorySecurity object has not been modified, it will not be persisted to a file. Portanto, não é possível recuperar um DirectorySecurity objeto de um arquivo e reaplicar o mesmo objeto a outro arquivo.Therefore, it is not possible to retrieve a DirectorySecurity object from one file and reapply the same object to another file.

Para copiar informações de ACL de um arquivo para outro:To copy ACL information from one file to another:

  1. Use o GetAccessControl método para recuperar o DirectorySecurity objeto do arquivo de origem.Use the GetAccessControl method to retrieve the DirectorySecurity object from the source file.

  2. Crie um novo DirectorySecurity objeto para o arquivo de destino.Create a new DirectorySecurity object for the destination file.

  3. Use o GetSecurityDescriptorBinaryForm GetSecurityDescriptorSddlForm método ou do objeto de origem DirectorySecurity para recuperar as informações de ACL.Use the GetSecurityDescriptorBinaryForm or GetSecurityDescriptorSddlForm method of the source DirectorySecurity object to retrieve the ACL information.

  4. Use o SetSecurityDescriptorBinaryForm SetSecurityDescriptorSddlForm método ou para copiar as informações recuperadas na etapa 3 para o DirectorySecurity objeto de destino.Use the SetSecurityDescriptorBinaryForm or SetSecurityDescriptorSddlForm method to copy the information retrieved in step 3 to the destination DirectorySecurity object.

  5. Defina o objeto de destino DirectorySecurity para o arquivo de destino usando o SetAccessControl método.Set the destination DirectorySecurity object to the destination file using the SetAccessControl method.

Em ambientes NTFS, ReadAttributes e ReadExtendedAttributes são concedidos ao usuário se o usuário tiver ListDirectory direitos sobre a pasta pai.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. Para negar ReadAttributes e ReadExtendedAttributes , negar ListDirectory no diretório pai.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Aplica-se a

Confira também