dsp74118の補完庫: Windows のオブジェクトのアクセス権を操作するコマンド subinacl が便利だった で触れたSubInACLのFlag、AccessMaskの早見表を作った。
俺の中ではアクセス権変更ツールとしてのSubInACLはオワコンだが、現在のACLを確認するツールとしてはまだまだ便利に使えると思う。
俺の中ではアクセス権変更ツールとしてのSubInACLはオワコンだが、現在のACLを確認するツールとしてはまだまだ便利に使えると思う。
' Open with Afxw.vbs
' ver.1.1 dsp74118
' Description: Open path(Local path/UNC path/URI) with Afxw
' Requirement: あふこまんど(AFXWCMD.EXE) is installed in %APP%\afxw\
' args:
' path string
Option Explicit
'Function UrlDecode
' Description: Decode UTF8-Encoded-URI
' args:
' strSource: Encoded URI string
' return:
' Decoded URI String
Function URLDecode(strSource)
Dim objSC
Set objSC = CreateObject("ScriptControl")
objSC.Language = "Jscript"
URLDecode = objSC.CodeObject.decodeURIComponent(strSource)
Set objSC = Nothing
End Function
' main
On Error Resume Next
Dim wshShell
Dim app, afx, opt, quoteChar, SPC, YEN
Set wshShell = WScript.CreateObject("WScript.Shell")
app = wshShell.ExpandEnvironmentStrings("%APP%")
afx = app & "\afxw\AFXWCMD.EXE"
opt = "-p"
quoteChar = """"
Dim path, arg, runCmd
Set arg = WScript.Arguments
If arg.Count = 0 Then
WScript.Quit
End If
path = arg(0)
' convert URI(file scheme) to UNC
If Left(path, 8) = "file:///" then
path = Right(path, Len(path) - 8)
path = URLDecode(path)
End If
runCmd = quoteChar & afx & quoteChar & " " & opt & quoteChar & path & quoteChar
wshShell.Run(runCmd)
$Path = $args[0]
$acl = Get-Acl $Path
$groupAccess = $acl.access | where {$_.IdentityReference -like "domainname\groupprefix*"}
if ($groupAccess){
$Access = $groupAccess.IdentityReference
"Modifying Permissions For $Access"
$Permission = $groupAccess.FileSystemRights
"Before: $Permission"
$Permission = ($Permission -replace "DeleteSubdirectoriesAndFiles(, )*","") -replace ", $", ""
"After: $Permission"
$inherit = $groupAccess.InheritanceFlags
$propagation = $groupAccess.PropagationFlags
$AccessRule = New-Object system.security.AccessControl.FileSystemAccessRule($Access, $Permission, $inherit, $propagation, "Allow")
$AccessModification = New-Object system.security.AccessControl.AccessControlModification
$AccessModification.value__ = 2
$Modification = $False
$acl.ModifyAccessRule($AccessModification, $AccessRule, [ref]$Modification) | out-null
}
Set-Acl -aclobject $acl -Path $Path
![]() |
| Figure.1 A列とC列を比較したい |
![]() | |
| Figure.2 こういう風に同じデータが同一行に揃うと嬉しいよね |