LotusScript复制Domino邮箱权限异常及批量归档问题求助
解决方案:批量复制Domino邮箱并确保可无权限访问
问题根源
你的CreateReplica方法会完整保留原邮箱数据库的ACL权限设置,原邮箱默认只有所有者和管理员有访问权限,所以本地打开时提示授权错误;而通过Domino Administrator手动复制时,因为你拥有完全管理权限,操作过程中会自动将你的账号加入本地库的ACL,同时隐式处理了加密和权限继承问题。CreateCopy为空则是因为未确保原数据库完全打开,且权限不足导致无法读取文档内容。
核心解决思路
- 使用拥有服务器完全管理权限的ID运行脚本,确保能访问所有目标邮箱。
- 复制完成后,手动修改本地数据库的ACL,添加匿名用户(Anonymous)的访问权限,确保任何人都能打开。
- 解除本地数据库的加密(如果原邮箱有加密设置)。
修改后的脚本
单邮箱处理示例
Sub Click(Source As Button) Dim session As New NotesSession Dim db As NotesDatabase Dim localDb As NotesDatabase Dim acl As NotesACL Dim entry As NotesACLEntry Dim sourcePath As String Dim targetPath As String Dim server As String Dim mailbox As String ' 替换为实际的服务器地址和邮箱文件名 mailbox = "<mailbox>" server = "<mailserver>" sourcePath = "mail/" + mailbox targetPath = "C:\Temp\mailbox_data\" + mailbox ' 打开源邮箱数据库(确保用管理员ID运行) Set db = session.GetDatabase(server, sourcePath) If Not db.IsOpen Then Call db.Open("", "") End If ' 创建本地副本 Set localDb = db.CreateReplica("", targetPath) ' 修改本地库ACL:添加匿名用户的读取权限 Set acl = localDb.ACL Set entry = acl.GetEntry("Anonymous") If entry Is Nothing Then Set entry = acl.CreateACLEntry("Anonymous", ACLLEVEL_READER) Else entry.Level = ACLLEVEL_READER End If acl.AllowAnonymousAccess = True Call acl.Save() ' 移除数据库加密(如果原邮箱加密) If localDb.IsEncrypted Then Call localDb.RemoveEncryption() End If ' 释放资源 Call db.Close() Call localDb.Close() End Sub
批量处理示例
从Domino地址簿读取所有用户的邮箱信息,循环处理:
Sub BatchArchiveMailboxes() Dim session As New NotesSession Dim dirDb As NotesDatabase Dim view As NotesView Dim doc As NotesDocument Dim db As NotesDatabase Dim localDb As NotesDatabase Dim acl As NotesACL Dim entry As NotesACLEntry Dim sourcePath As String Dim targetPath As String Dim server As String Dim mailbox As String server = "<mailserver>" Dim logFile As Integer logFile = Freefile() Open "C:\Temp\archive_log.txt" For Output As logFile ' 打开Domino地址簿 Set dirDb = session.GetDatabase(server, "names.nsf") If Not dirDb.IsOpen Then Print #logFile, "无法打开地址簿" Close logFile Exit Sub End If Set view = dirDb.GetView("People") ' 选择包含用户邮箱信息的视图 Set doc = view.GetFirstDocument() While Not doc Is Nothing mailbox = doc.MailFile(0) If mailbox <> "" Then sourcePath = "mail/" + mailbox targetPath = "C:\Temp\mailbox_data\" + mailbox On Error Resume Next Set db = session.GetDatabase(server, sourcePath) If Err.Number <> 0 Then Print #logFile, "无法访问邮箱:" + mailbox + ",错误:" + Err.Description Err.Clear() Set doc = view.GetNextDocument(doc) Continue End If If Not db.IsOpen Then Call db.Open("", "") End If Set localDb = db.CreateReplica("", targetPath) If localDb Is Nothing Then Print #logFile, "复制失败:" + mailbox Call db.Close() Set doc = view.GetNextDocument(doc) Continue End If ' 修改ACL和移除加密 Set acl = localDb.ACL Set entry = acl.GetEntry("Anonymous") If entry Is Nothing Then Set entry = acl.CreateACLEntry("Anonymous", ACLLEVEL_READER) Else entry.Level = ACLLEVEL_READER End If acl.AllowAnonymousAccess = True Call acl.Save() If localDb.IsEncrypted Then Call localDb.RemoveEncryption() End If Print #logFile, "成功归档:" + mailbox Call db.Close() Call localDb.Close() End If Set doc = view.GetNextDocument(doc) Wend Close logFile End Sub
关键注意事项
- 权限要求:必须使用拥有Domino服务器完全管理权限的ID执行脚本,否则无法访问其他用户的邮箱,也无法修改ACL和移除加密。
- 性能优化:2TB的总数据量较大,建议在服务器非高峰时段运行脚本,可添加分批次处理逻辑,避免服务器IO负载过高。
- 日志记录:批量处理时一定要记录日志,方便排查失败的邮箱。
内容的提问来源于stack exchange,提问作者Filip Kowalczyk
相关产品推荐
相关产品推荐

