Skip to content

Security_SetDirPermissions

Sets access right for a trustee on a directory.

sRight can be one of the following values:

  • F: Full Control
  • C: Change
  • R: Read
  • X: Execute
  • E: Read Execute
  • W: Write
  • D: Delete

The directory must exist. If it doesn’t, the function returns False.

If bIncludeSubDirs is True, the right is first set on sDir and then on sDir & "\*", for example first on C:\Temp and then on C:\Temp\*. This way the right also applies to the files and subdirectories in the directory.

If more than one access right needs to be applied the values must be added in the same sRight string e.g. “RW” to obtain Read and Write access on the Directory.

Security_SetDirPermissions(sDir, sTrustee, sRight, bIncludeSubDirs) As Boolean

Full path of the directory

A trustee is a user or group. The trustee can be a name in the format Domain\User or a well-known SID (security identifier). Some built-in group names, such as Power Users, are localized, so use the SID for those.

Access Right that should be set

Include subdirectories (True/False)

The function returns False if the directory doesn’t exist, if SubInACL.exe can’t be found, or if SubInACL reports an error. See Security functions for where the library looks for SubInACL.exe.

If bStatus Then bStatus = Security_SetDirPermissions(gsProgramFiles & "\CapaInstaller\Logs","S-1-5-4", "F", True)

Scripting Guidelines

Security functions Security_DenyDirAccess Security_RevokeDirPermissions Constants Package Property Variables