Access Control

本文详细介绍了如何使用Windows ACL API创建文件并修改其访问控制列表,包括设置文件标志、获取旧DACL、创建新ACE、组合旧和新ACE以及设置新的DACL等步骤。
#include <Aclapi.h>

int
main() { // Create file with multiple flags. HANDLE file = CreateFile("d:\\", STANDARD_RIGHTS_WRITE | WRITE_DAC, FILE_SHARE_READ | FILE_SHARE_WRITE, NULL, OPEN_EXISTING, FILE_FLAG_BACKUP_SEMANTICS, // This flag must be set. NULL); // Save old DACL. PSECURITY_DESCRIPTOR pSd = NULL; PACL pOldDacl = NULL, pNewDacl = NULL; GetSecurityInfo(file, SE_FILE_OBJECT, DACL_SECURITY_INFORMATION, NULL, NULL, &pOldDacl, NULL, &pSd); // Create new ACE. EXPLICIT_ACCESS ea = {}; ea.grfAccessMode = SET_ACCESS; // Reset or grant or deny, etc. ea.grfAccessPermissions = GENERIC_ALL; // GENERIC_READ | GENERIC_WRITE | GENERIC_EXECUTE. ea.grfInheritance = SUB_CONTAINERS_AND_OBJECTS_INHERIT; // Whether take effect on sub containers. ea.Trustee.TrusteeForm = TRUSTEE_IS_NAME; // 'ptstrName' is a name field. ea.Trustee.TrusteeType = TRUSTEE_IS_USER; // 'ptstrName' is a user name field. ea.Trustee.ptstrName = "EveryOne"; // User name. SetEntriesInAcl(1, &ea, pOldDacl, &pNewDacl); // Combine old ACEs and new ACE. // Set new DACL.(containing old ACEs) SetSecurityInfo(file, SE_FILE_OBJECT, DACL_SECURITY_INFORMATION, NULL, NULL, pNewDacl, NULL); // Release resource. LocalFree(pNewDacl); LocalFree(pSd); CloseHandle(file); return 0; }

转载于:https://www.cnblogs.com/walfud/archive/2012/11/13/2768274.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值