FileAuthorizationModule.CheckFileAccessForUser Method (String, IntPtr, String)

 

Determines whether the user has access to the requested file.

Namespace:   System.Web.Security
Assembly:  System.Web (in System.Web.dll)

<SecurityPermissionAttribute(SecurityAction.Demand, UnmanagedCode := True)>
Public Shared Function CheckFileAccessForUser (
	virtualPath As String,
	token As IntPtr,
	verb As String
) As Boolean

Parameters

virtualPath
Type: System.String

The virtual path to the file.

token
Type: System.IntPtr

A Windows access token representing the user.

verb
Type: System.String

The HTTP verb used to make the request.

Return Value

Type: System.Boolean

true if the current Windows user represented by token has access to the file using the specified HTTP verb or if the FileAuthorizationModule module is not defined in the application's configuration file; otherwise, false.

Exception Condition
ArgumentNullException

virtualPath is null.

-or-

token is Zero.

-or-

verb is null.

ArgumentException

virtualPath is not in the application directory structure of the Web application.

FileNotFoundException

The file specified by virtualPath does not exist.

The CheckFileAccessForUser method checks to see whether the current user, represented by a Windows access token, is granted access to the requested file in the file-system access-control lists (ACLs). The virtual path is mapped to the physical file-system path before the check is made.

If the HTTP verb used to make the request is GET, POST, or HEAD, the CheckFileAccessForUser method checks for read access to the file. If any other verb is used, the CheckFileAccessForUser method checks for read/write permission to the file.

Security Note   If the FileAuthorizationModule module is not defined in the httpModules configuration section for the application, the FileAuthorizationModule module always returns true.

.NET Framework
Available since 2.0
Return to top
Show: