You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Standard 2.1下管理员服务器与普通用户客户端管道访问拒绝问题

管理员权限服务器与普通用户客户端的命名管道权限问题解决方法

当服务器以管理员权限启动,客户端以普通用户身份运行时,NamedPipeClientStream抛出“Access to the path is denied”错误,核心原因是默认创建的命名管道仅授予管理员访问权限,普通用户无连接权限。解决的关键是在服务器端创建管道时显式配置管道安全规则,开放权限给普通用户。

具体解决步骤

1. 构建管道安全配置

使用PipeSecurity类创建权限规则,允许普通用户组(如Everyone)对管道拥有读写权限:

var pipeSecurity = new PipeSecurity();
// 允许Everyone组读写管道
var accessRule = new PipeAccessRule(
    new SecurityIdentifier(WellKnownSidType.WorldSid, null),
    PipeAccessRights.ReadWrite,
    AccessControlType.Allow);
pipeSecurity.AddAccessRule(accessRule);

2. 修改服务器端管道创建代码

在NamedPipeServerStream的构造函数中,传入配置好的PipeSecurity对象:

修改后的完整创建逻辑:

void CreatePipe()
{
    if (m_bIsServer)
    {
        try
        {
            // 构建管道安全规则
            var pipeSecurity = new PipeSecurity();
            var accessRule = new PipeAccessRule(
                new SecurityIdentifier(WellKnownSidType.WorldSid, null),
                PipeAccessRights.ReadWrite,
                AccessControlType.Allow);
            pipeSecurity.AddAccessRule(accessRule);

            m_Pipe = new NamedPipeServerStream(
                m_szPipeName,
                PipeDirection.InOut,
                2, // max incoming instances
                PipeTransmissionMode.Byte,
                PipeOptions.Asynchronous,
                0, // 使用默认输入缓冲区大小
                0, // 使用默认输出缓冲区大小
                pipeSecurity); // 传入管道安全配置
            Console.WriteLine("done creating pipe");
            m_szDebugName = "S:";
            m_bIsServer = true;
        }
        catch (Exception e)
        {
            Debug.WriteLine("Exception: " + e.Message);
        }
    }
    else
    {
        m_Pipe = new NamedPipeClientStream(
            ".",
            m_szPipeName,
            PipeDirection.InOut,
            PipeOptions.Asynchronous,
            System.Security.Principal.TokenImpersonationLevel.Impersonation); // 无需委派时用Impersonation更合适
        m_szDebugName = "C:";
        m_bIsServer = false;
    }
}

补充说明

  • 若不需要开放给所有用户,可替换WellKnownSidType.WorldSid为特定用户组的SID(如AuthenticatedUsersSid),实现更精准的权限控制。
  • 客户端的TokenImpersonationLevel:如果不需要服务器模拟客户端执行操作,使用TokenImpersonationLevel.Impersonation或Identification即可,Delegation权限过高且通常不必要。

内容的提问来源于stack exchange,提问作者eric frazer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 03:12:17