关于Kentico CMS文档管理系统集成及细粒度权限配置的技术问询
Great question! Let’s break this down step by step since you’re evaluating Kentico for your ASP.NET MVC project— I’ve worked with this setup a few times, so I’ll walk you through exactly what you need to know.
1. Does Kentico CMS include a Document Management System (DMS)?
Absolutely. Kentico comes with a built-in Document Management module that’s fully integrated with its core platform. It supports:
- Uploading and storing all common file types (docs, PDFs, images, videos, etc.)
- Version control for tracked changes
- Folder-based organization
- Metadata tagging and search
- Integration with Kentico’s user/role system for permissions
It’s not a separate tool— it’s baked right into Kentico’s admin interface and API.
2. Integrating Kentico Document Management into Your ASP.NET MVC Project
There are two main approaches, depending on how much customization you need:
Option 1: Use Kentico’s Built-in MVC Helpers (Quickest Setup)
Kentico provides ready-to-use HTML helpers that handle the heavy lifting for uploads and document lists. Here’s a quick example:
Step 1: Add the Uploader to Your View
In your MVC view, add the Kentico document uploader helper (make sure you’ve referenced the Kentico MVC NuGet packages first):
@using CMS.DocumentEngine.Mvc @using CMS.Helpers @using (Html.BeginForm("UploadDocument", "Documents", FormMethod.Post, new { enctype = "multipart/form-data" })) { @Html.Kentico().DocumentUploader() <button type="submit">Upload Document</button> }
Step 2: Handle Upload in Your Controller
Create an action method to process the upload and save the document to Kentico’s storage:
using CMS.DocumentEngine; using CMS.Membership; using CMS.SiteProvider; using System.IO; using System.Web.Mvc; public class DocumentsController : Controller { [HttpPost] public ActionResult UploadDocument(HttpPostedFileBase file) { if (file == null || file.ContentLength == 0) { ModelState.AddModelError("", "Please select a file to upload."); return View(); } // Get the authenticated user and target folder (create the folder in Kentico Admin first!) var currentUser = MembershipContext.AuthenticatedUser; var targetFolder = DocumentHelper.GetDocumentFolder("/Documents/ProjectFiles", SiteContext.CurrentSiteName); // Create document metadata var newDocument = new DocumentInfo { DocumentName = Path.GetFileName(file.FileName), DocumentFilePath = file.FileName, DocumentFolderID = targetFolder.FolderID, DocumentCreatedByUserID = currentUser.UserID }; // Save the file to Kentico's storage using (var fileStream = file.InputStream) { DocumentHelper.AddDocument(newDocument, fileStream); } return RedirectToAction("DocumentList"); } // Action to display all documents in the folder public ActionResult DocumentList() { var targetFolder = DocumentHelper.GetDocumentFolder("/Documents/ProjectFiles", SiteContext.CurrentSiteName); var documents = DocumentHelper.GetDocuments() .WhereEquals("DocumentFolderID", targetFolder.FolderID) .OrderByDescending("DocumentCreatedWhen") .ToList(); return View(documents); } }
Option 2: Build a Custom UI with Kentico’s API (Full Control)
If you need a fully custom interface, use Kentico’s Document Management API directly. This lets you build upload forms, document previews, and download links exactly how you want— just call the Kentico backend services from your MVC controllers.
3. Configuring Granular Permissions for Documents
Kentico’s permission system is highly flexible— you can lock down access at the folder, document, or even role/user level. Here’s how to set it up:
Step 1: Set Folder-Level Permissions (Base Rule)
- Log into the Kentico Admin interface
- Go to Content > Document Management
- Navigate to the folder where you’ll store project documents
- Right-click the folder > Permissions
- Assign permissions to roles/users:
- Read: View and download documents
- Write: Upload and edit documents
- Delete: Remove documents
- Modify permissions: Change access rules for the folder
Step 2: Document-Level Permissions (Override for Specific Files)
If you need to restrict access to a single document (not the whole folder):
- In Document Management, open the document’s details
- Go to the Permissions tab
- Toggle off "Inherit permissions from parent folder"
- Assign custom permissions to specific roles/users
Step 3: Check Permissions in Your MVC Project
Always validate user permissions in your MVC code before allowing access to documents. Use Kentico’s security helper:
public ActionResult DownloadDocument(int documentId) { var document = DocumentHelper.GetDocument(documentId); var currentUser = MembershipContext.AuthenticatedUser; // Check if the user has permission to read the document if (!DocumentSecurityHelper.IsAuthorizedPerDocument(document, "Read", currentUser)) { return new HttpUnauthorizedResult("You don't have permission to access this document."); } // Get the file stream from Kentico and return it as a download using (var fileStream = DocumentHelper.GetDocumentStream(document)) { return File(fileStream, document.DocumentMimeType, document.DocumentName); } }
Bonus: Custom Permissions
If the default permission set isn’t enough, you can create custom permissions in Kentico Admin (System > Permissions > Custom permissions) and check them in your code using PermissionHelper.IsAuthorized().
Let me know if you need more details on any specific part— whether it’s tweaking the UI, setting up complex permission rules, or troubleshooting integration issues!
内容的提问来源于stack exchange,提问作者Bhaskar Sharma

