Table of Contents

Class AccessControlEntry

Namespace
ArcanaDevelopment.adTempus.Client
Assembly
ArcanaDevelopment.adTempus.Client.dll

Represents a set of permissions that share the same secured object, security entity, and inheritance rules.

[ComVisible(true)]
[Guid("2BA76717-5209-430C-A7A0-621B2E4C6EFF")]
public sealed class AccessControlEntry : ADTObject
Inheritance
object
AccessControlEntry

Remarks

Each secured object has a SecurityDescriptor that contains the Access Control Entries defining the permissions for the object.

An AccessControlEntry contains a list of granted permissions and a list of denied permissions. Any permission not included in either list is granted or denied based on permissions inherited from the object's security container, if any. Any permission not explicitly granted or denied anywhere in the security inheritance hierarchy is implicitly denied.

To create a new AccessControlEntry, call GetOrCreateAccessControlEntry(SecurityEntity, SecurityInheritanceOptions), AddPermissions(SecurityEntity, IList<int>, IList<int>, SecurityInheritanceOptions), or ReplacePermissions(SecurityEntity, IList<int>, IList<int>, SecurityInheritanceOptions).

Security permission constants are defined in SecurityPermission.

Properties

ClassID

The Class ID for the object

[IgnoreDataMember]
public override ClassID ClassID { get; }

Property Value

ClassID

ClassKeyName

The key name for the class.

public override string ClassKeyName { get; }

Property Value

string

Remarks

This name the name used by adTempus to identify the class and is intended for programmatic use only. Use the ClassName for a user-friendly name.

DeniedPermissionList

Gets a comma-delimited list of the names of the permissions denied by this permission set.

public string DeniedPermissionList { get; }

Property Value

string

Remarks

This property returns a comma-delimited list of all denied permissions, using GetSecurityPermissionName(SecurityPermission, string) to get the name for each permission. For example, the list could return "Modify, Delete".

GrantedPermissionList

Gets a comma-delimited list of the names of the permissions granted by this permission set.

public string GrantedPermissionList { get; }

Property Value

string

Remarks

This property returns a comma-delimited list of all granted permissions, using GetSecurityPermissionName(SecurityPermission, string) to get the name for each permission. For example, the list could return "View, Modify".

InheritanceOptions

Gets the inheritance options for this permission set.

public SecurityInheritanceOptions InheritanceOptions { get; set; }

Property Value

SecurityInheritanceOptions

Remarks

Inheritance options cannot be changed once a AccessControlEntry has been created. To set permissions with different inheritance options, create a new AccessControlEntry.

IsDependent

Indicates whether the object is a dependent of (owned by) another object

[IgnoreDataMember]
public override bool IsDependent { get; }

Property Value

bool

Remarks

An independent object (IsDependent is false) is an object that can exist on its own without being part of another object. For example, Jobs, Job Groups, etc.

A dependent object (IsDependent is true) is a part of another object. For example, a JobStep cannot exist independently of a Job, so the JobStep is dependent.

Dependent objects cannot be directly fetched from the server: they are only fetched as part of the object they belong to. They also cannot be saved or deleted independently: they are automatically saved or deleted when the owning object is saved or deleted.

IsSystem

Indicates whether this is a system-managed entry.

public bool IsSystem { get; }

Property Value

bool

Remarks

If IsSystem is true, this item cannot be modified or deleted.

SecuredObject

The object this entry applies to.

public ADTObject SecuredObject { get; }

Property Value

ADTObject

SecurityEntity

The SecurityEntity this entry belongs to.

public SecurityEntity SecurityEntity { get; }

Property Value

SecurityEntity

Methods

DenyPermission(int)

Denies a permission.

public void DenyPermission(int permission)

Parameters

NameTypeDescription
permission int

The permission to deny. Security permission constants are defined in SecurityPermission.

Remarks

The specified permission is added to the Denies for the AccessControlEntry and removed from the Grants (if present).

DenyPermissions(IEnumerable<int>)

Denies a set of permissions.

public void DenyPermissions(IEnumerable<int> permissions)

Parameters

NameTypeDescription
permissions IEnumerable<int>

The permission to grant. Security permission constants are defined in SecurityPermission.

Remarks

The specified permissions are added to the Denies for the AccessControlEntry and removed from the Grants (if present).

FindOwningObject()

Get the owner of this object based on relationships.

protected override ADTObject FindOwningObject()

Returns

ADTObject

The owning object, or null if the object is not owned by another object or the owner has not been set.

GetDeniedPermissions()

Gets a list of all permissions denied by this permission set.

public ReadOnlyCollection<int> GetDeniedPermissions()

Returns

ReadOnlyCollection<int>

A list of permissions denied in this entry. Security permission constants are defined in SecurityPermission.

GetGrantedPermissions()

Gets a list of all permissions granted by this permission set.

public ReadOnlyCollection<int> GetGrantedPermissions()

Returns

ReadOnlyCollection<int>

A list of permissions granted in this entry. Security permission constants are defined in SecurityPermission.

GetObjectDescription()

Gets a description of the object's key settings.

protected override string GetObjectDescription()

Returns

string

Remarks

This method is called by GetDescription() to get a user-friendly description of the object (such as its key settings) for display to the user. The description should contain enough information to distinguish this object from others of the same class.

GrantPermission(int)

Grants a permission.

public void GrantPermission(int permission)

Parameters

NameTypeDescription
permission int

The permission to grant. Security permission constants are defined in SecurityPermission.

Remarks

The specified permission is added to the Grants for the AccessControlEntry and removed from the Denies (if present).

GrantPermissions(IEnumerable<int>)

Grants a set of permissions.

public void GrantPermissions(IEnumerable<int> permissions)

Parameters

NameTypeDescription
permissions IEnumerable<int>

The permission to grant. Security permission constants are defined in SecurityPermission.

Remarks

The specified permissions are added to the Grants for the AccessControlEntry and removed from the Denies (if present).

RemovePermission(int)

Removes a permission (the permission is neither granted nor denied)

public void RemovePermission(int permission)

Parameters

NameTypeDescription
permission int

The permission to remove. Security permission constants are defined in SecurityPermission.

Remarks

The specified permission is removed from the Grants and Denies.

WriteToConfigurationReport(IADTObjectConfigurationReportWriter)

Writes the object and any contained objects to a configuration report

public override void WriteToConfigurationReport(IADTObjectConfigurationReportWriter reportBuilder)

Parameters

NameTypeDescription
reportBuilder IADTObjectConfigurationReportWriter

The report builder to write the object to.

Inherited Members