Модераторы: Daevaorn
  

Поиск:

Ответ в темуСоздание новой темы Создание опроса
> Права в NT, Распознавание прав 
:(
    Опции темы
AlexS
Дата 28.3.2002, 15:24 (ссылка)    |    (голосов: 0) Загрузка ... Загрузка ... Быстрая цитата Цитата


Unregistered











Как в NT программно узнать права пользователя на данный файл или каталог?
  Вверх
Dicobraz
Дата 29.3.2002, 11:17 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Шустрый
*


Профиль
Группа: Участник
Сообщений: 79
Регистрация: 26.3.2002
Где: Пермь

Репутация: нет
Всего: нет



Сам еще не писал, но вот статья из MSDN. Надеюсь, поможет.

GetNamedSecurityInfo
The GetNamedSecurityInfo function retrieves a copy of the security descriptor for an object specified by name.

DWORD GetNamedSecurityInfo(
LPTSTR pObjectName,                      // object name
SE_OBJECT_TYPE ObjectType,             // object type
SECURITY_INFORMATION SecurityInfo,  // information type
PSID *ppsidOwner,                         // owner SID
PSID *ppsidGroup,                         // primary group SID
PACL *ppDacl,                             // DACL
PACL *ppSacl,                             // SACL
PSECURITY_DESCRIPTOR *ppSecurityDescriptor // SD
);
Parameters:
pObjectName
[in] Pointer to a null-terminated string that specifies the name of the object from which to retrieve security information. For descriptions of the string formats for the different object types, see SE_OBJECT_TYPE.
ObjectType
[in] Specifies a value from the SE_OBJECT_TYPE enumeration that indicates the type of object named by the pObjectName parameter.
SecurityInfo
[in] A set of SECURITY_INFORMATION bit flags that indicate the type of security information to retrieve. This parameter can be a combination of the following values. Value Meaning
DACL_SECURITY_INFORMATION If this flag is set, the ppDacl parameter receives the object's discretionary access-control list (DACL).
GROUP_SECURITY_INFORMATION If this flag is set, the ppsidGroup parameter receives the SID of the object's primary group.  
OWNER_SECURITY_INFORMATION If this flag is set, the ppsidOwner parameter receives the security identifier (SID) of the object's owner.
SACL_SECURITY_INFORMATION If this flag is set, the ppSacl parameter receives the object's system access-control list (SACL).
ppsidOwner
[out] Pointer to a variable that receives a pointer to the owner SID in the security descriptor returned in ppSecurityDescriptor. The returned pointer is valid only if you set the OWNER_SECURITY_INFORMATION flag. This parameter can be NULL if you do not need the owner SID.
ppsidGroup
[out] Pointer to a variable that receives a pointer to the primary group SID in the returned security descriptor. The returned pointer is valid only if you set the GROUP_SECURITY_INFORMATION flag. This parameter can be NULL if you do not need the group SID.
ppDacl
[out] Pointer to a variable that receives a pointer to the DACL in the returned security descriptor. The returned pointer is valid only if you set the DACL_SECURITY_INFORMATION flag. This parameter can be NULL if you do not need the DACL.
ppSacl
[out] Pointer to a variable that receives a pointer to the SACL in the returned security descriptor. The returned pointer is valid only if you set the SACL_SECURITY_INFORMATION flag. This parameter can be NULL if you do not need the SACL.
ppSecurityDescriptor
[out] Pointer to a variable that receives a pointer to the security descriptor of the object. You must call the LocalFree function to free the returned buffer.
Return Values
If the function succeeds, the return value is ERROR_SUCCESS.

If the function fails, the return value is a nonzero error code defined in WINERROR.H.

Remarks
If the ppsidOwner, ppsidGroup, ppDacl, ppSacl parameters are non-NULL, and the SecurityInfo parameter specifies that they be retrieved from the object, those parameters will point to the corresponding parameters in the security descriptor returned in ppSecurityDescriptor.

To read the owner, group, or DACL from the object's security descriptor, the object's DACL must grant READ_CONTROL access to the caller or the caller must be the owner of the object.

To read the system access-control list (SACL) of the object, the SE_SECURITY_NAME privilege must be enabled for the calling process.

You can use the GetNamedSecurityInfo function with the following types of objects:

Local or remote files or directories on an NTFS file system
Local or remote printers
Local or remote Win32 services
Network shares
Registry keys
Semaphores, events, mutexes, and waitable timers
File-mapping objects
Directory service objects
Requirements
 Windows NT/2000: Requires Windows NT 4.0 or later.
 Header: Declared in Aclapi.h.
 Library: Use Advapi32.lib.
 Unicode: Implemented as Unicode and ANSI versions on Windows NT/2000.

See Also
Access Control Overview, Access Control Functions, ACL, GetSecurityInfo, LocalFree, SE_OBJECT_TYPE, SECURITY_DESCRIPTOR, SECURITY_INFORMATION, SetNamedSecurityInfo, SetSecurityInfo, SID

P.S. Не поленись скинуть мне на мыло, если получится (или не получится :)).
PM MAIL ICQ   Вверх
Vit
Дата 29.3.2002, 11:21 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Vitaly Nevzorov
****


Профиль
Группа: Экс. модератор
Сообщений: 10964
Регистрация: 25.3.2002
Где: Chicago

Репутация: нет
Всего: 207



Цитата
P.S. Не поленись скинуть мне на мыло, если получится (или не получится ).


Зачем, лучше в форум :)


--------------------
With the best wishes, Vit
I have done so much with so little for so long that I am now qualified to do anything with nothing
Самый большой Delphi FAQ на русском языке здесь: www.drkb.ru
PM MAIL WWW ICQ   Вверх
Dicobraz
Дата 29.3.2002, 13:52 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Шустрый
*


Профиль
Группа: Участник
Сообщений: 79
Регистрация: 26.3.2002
Где: Пермь

Репутация: нет
Всего: нет



ну, тогда и я попробую...;) все равно пара часиков свободных есть.
PM MAIL ICQ   Вверх
Dicobraz
Дата 29.3.2002, 16:30 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Шустрый
*


Профиль
Группа: Участник
Сообщений: 79
Регистрация: 26.3.2002
Где: Пермь

Репутация: нет
Всего: нет



Сегодня не успел. В понедельник допишу.
Добился вывода списка ACE файла (ну типа user такой-то может то-то), но вот с масками не разобрался еще (перевод из DWORD в список прав) - муть какая-то... :(
Так что скоро (надеюсь) грянет Исходник (надеюсь) :).

Удачи!
PM MAIL ICQ   Вверх
Dicobraz
Дата 1.4.2002, 11:42 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Шустрый
*


Профиль
Группа: Участник
Сообщений: 79
Регистрация: 26.3.2002
Где: Пермь

Репутация: нет
Всего: нет



Вобщем вот. Сильно кпрощенный пример того, как писать не надо ( попытка нарваться на комплимент :)).
Итак. Создаем Dialog-проект в Visual C++. Вставляем туды CListBox (m_List) и кнопку "Выбор файла". Делаем процедуру обработки нажатия и пишем там следующее:
Код

void CNT_FileSecurityAttrDlg::OnSelectFile()
{
CFileDialog fdDlg(true, NULL, NULL, OFN_HIDEREADONLY | OFN_OVERWRITEPROMPT | OFN_ENABLESIZING, NULL, this);
if (fdDlg.DoModal() != IDOK)
return;

PACL paclDACL;
PSECURITY_DESCRIPTOR psdSecurity;
if (GetNamedSecurityInfo( fdDlg.GetPathName().GetBuffer(0),
SE_FILE_OBJECT, //SE_LMSHARE,
DACL_SECURITY_INFORMATION,
NULL,
NULL,
&paclDACL,
NULL,
&psdSecurity
) != ERROR_SUCCESS)
{
LPVOID lpMsgBuf;
FormatMessage(
FORMAT_MESSAGE_ALLOCATE_BUFFER |
FORMAT_MESSAGE_FROM_SYSTEM |
FORMAT_MESSAGE_IGNORE_INSERTS,
NULL,
GetLastError(),
0,
(LPTSTR) &lpMsgBuf,
0,
NULL);
AfxMessageBox((LPTSTR)lpMsgBuf);
return;
}

LPVOID pACE;
BYTE bACEType;
ACCESS_ALLOWED_ACE *ACE;
CString Mask, Tmp;
m_List.ResetContent();
for (int i = 0; i < paclDACL->AceCount; i++)
{
if (!GetAce(paclDACL, i, &pACE))
AfxMessageBox("Ошибка GetAce()!");
bACEType = ((ACE_HEADER*)pACE)->AceType;
if (bACEType!= ACCESS_ALLOWED_ACE_TYPE &&
bACEType!= ACCESS_DENIED_ACE_TYPE)
AfxMessageBox(_T("ActiveDirectory доделывайте сами :)."));
else
{
ACE = (ACCESS_ALLOWED_ACE*)pACE;
for (int j = 0; j < 32; j++)
{
Tmp.Format(_T("%u"), ((ACE->Mask >> j) & 1) );
Mask += Tmp;
}
m_List.AddString(Mask);
Mask.Empty();
Tmp.Empty();

char Name[100], Domain[100];
DWORD NameSize = 100, DomainSize = 100;
SID_NAME_USE SidType;
PSID pSID = (PSID)&(((ACCESS_ALLOWED_ACE*)pACE)->SidStart);
if (!LookupAccountSid(NULL,
 pSID,
 Name, &NameSize,
 Domain, &DomainSize,
 &SidType))
{
LPVOID lpMsgBuf;
FormatMessage(
FORMAT_MESSAGE_ALLOCATE_BUFFER |
FORMAT_MESSAGE_FROM_SYSTEM |
FORMAT_MESSAGE_IGNORE_INSERTS,
NULL,
GetLastError(),
0,
(LPTSTR) &lpMsgBuf,
0,
NULL);
AfxMessageBox((LPTSTR)lpMsgBuf);
}//if
else m_List.AddString(Name);
}//else
} //for
}

Глюки возможны, но не приветствуются :)
Инструкция по применению.
Выбрать файл в диалоге, получить список попарно, строка - права доступа (в бинарном виде, лень парсинг делать), строка - имя владельца этих прав.
Для каталогов тоже работает, но в стандартном диалоге их выбор не предусмотрен.
Одна тонкость - если хочешь получить ACL для файла, не забудь иметь на это право - иначе security тебя пошлет.
Удачи.
PM MAIL ICQ   Вверх
Кащей
Дата 26.4.2006, 14:35 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Новичок



Профиль
Группа: Участник
Сообщений: 48
Регистрация: 2.8.2005

Репутация: нет
Всего: нет



Dicobraz, а есть ли возможность переложить этот код на Delphi? Мне достаточно просто получить файл или массив со значением ACL 
PM MAIL   Вверх
likehood
Дата 26.4.2006, 14:43 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


666
**


Профиль
Группа: Участник
Сообщений: 536
Регистрация: 21.12.2005

Репутация: 8
Всего: 24



Вряд ли он тебе ответит - посмотри дату последнего сообщения в его профиле. 
PM MAIL   Вверх
Кащей
Дата 26.4.2006, 14:50 (ссылка) | (нет голосов) Загрузка ... Загрузка ... Быстрая цитата Цитата


Новичок



Профиль
Группа: Участник
Сообщений: 48
Регистрация: 2.8.2005

Репутация: нет
Всего: нет



ну кто-нибудь другой, кто знает оба языка 
PM MAIL   Вверх
  
Ответ в темуСоздание новой темы Создание опроса
Правила форума "С++:Общие вопросы"
Earnest Daevaorn

Добро пожаловать!

  • Черновик стандарта C++ (за октябрь 2005) можно скачать с этого сайта. Прямая ссылка на файл черновика(4.4мб).
  • Черновик стандарта C (за сентябрь 2005) можно скачать с этого сайта. Прямая ссылка на файл черновика (3.4мб).
  • Прежде чем задать вопрос, прочтите это и/или это!
  • Здесь хранится весь мировой запас ссылок на документы, связанные с C++ :)
  • Не брезгуйте пользоваться тегами [code=cpp][/code].
  • Пожалуйста, не просите написать за вас программы в этом разделе - для этого существует "Центр Помощи".
  • C++ FAQ

Если Вам понравилась атмосфера форума, заходите к нам чаще! С уважением, Earnest Daevaorn

 
0 Пользователей читают эту тему (0 Гостей и 0 Скрытых Пользователей)
0 Пользователей:
« Предыдущая тема | C/C++: Общие вопросы | Следующая тема »


 




[ Время генерации скрипта: 0.0514 ]   [ Использовано запросов: 22 ]   [ GZIP включён ]


Реклама на сайте     Информационное спонсорство

 
По вопросам размещения рекламы пишите на vladimir(sobaka)vingrad.ru
Отказ от ответственности     Powered by Invision Power Board(R) 1.3 © 2003  IPS, Inc.