You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过C#在未知密码时检查TFS 2010项目的用户权限?

Check TFS 2010 Project Access Without User Password (C#)

Got it, let's work through this. You need a C# solution to verify if a specific user has read/write access to a TFS 2010 project—no user password required, unlike your existing VB code that relies on knowing credentials. Here's a solid approach using TFS's built-in security API, which lets you query permissions as a user with permission-view access to the TFS server.

Prerequisites

First, add references to these TFS 2010 client assemblies in your project:

  • Microsoft.TeamFoundation.Client.dll
  • Microsoft.TeamFoundation.WorkItemTracking.Client.dll
  • Microsoft.TeamFoundation.Framework.Client.dll

C# Implementation

This method returns a bool indicating if the user has either read or write rights to the target project:

using System;
using Microsoft.TeamFoundation.Client;
using Microsoft.TeamFoundation.Framework.Client;
using Microsoft.TeamFoundation.Framework.Common;
using Microsoft.TeamFoundation.WorkItemTracking.Client;

public static bool HasProjectAccess(string tfsServerUrl, string projectName, string targetUsername)
{
    try
    {
        // Connect to TFS using the current executing user's credentials (needs permission to query security)
        TfsTeamProjectCollection tfsCollection = new TfsTeamProjectCollection(new Uri(tfsServerUrl));
        tfsCollection.EnsureAuthenticated();

        // Locate the target project in the Work Item Store
        WorkItemStore workItemStore = tfsCollection.GetService<WorkItemStore>();
        Project targetProject = workItemStore.Projects[projectName];
        if (targetProject == null)
            throw new ArgumentException($"Project '{projectName}' not found on the server.");

        // Get the security namespace for work item permissions
        ISecurityService securityService = tfsCollection.GetService<ISecurityService>();
        SecurityNamespace workItemSecurity = securityService.GetSecurityNamespace(SecurityNamespaceConstants.WorkItem);

        // Generate the unique security token for the target project
        string projectSecurityToken = $"vstfs:///Classification/TeamProject/{targetProject.Id}";

        // Define the permissions we care about: Read and Write work items
        int readPermission = (int)WorkItemPermissions.Read;
        int writePermission = (int)WorkItemPermissions.Write;
        int requiredPermissions = readPermission | writePermission;

        // Query the user's effective permissions (accounts for groups and inheritance)
        int userPermissions = workItemSecurity.QueryEffectivePermissions(projectSecurityToken, targetUsername);

        // Check if user has at least one of the required permissions
        return (userPermissions & requiredPermissions) != 0;
    }
    catch (Exception ex)
    {
        // Handle exceptions like server unavailability or insufficient query permissions
        Console.WriteLine($"Error checking access: {ex.Message}");
        return false;
    }
}

// Example usage
public static void Main()
{
    string tfsServer = "http://your-tfs-server:8080/tfs/DefaultCollection";
    string targetProject = "YourProjectName";
    string targetUser = "DOMAIN\\UserName";

    bool hasAccess = HasProjectAccess(tfsServer, targetProject, targetUser);
    Console.WriteLine(hasAccess ? "User has access to the project" : "User does NOT have access to the project");
}

Key Details

  • No Target User Password Required: This uses the current executing user's credentials to connect to TFS. That user needs permission to view security settings (typically a project admin or someone with "View Permissions" rights).
  • Effective Permissions Check: The QueryEffectivePermissions method accounts for all group memberships and inherited permissions, so it returns the actual access the user has, not just direct assignments.
  • TFS 2010 Compatibility: This uses APIs specific to TFS 2010—make sure you're using the correct version of client libraries (not newer TFS/Azure DevOps versions which have different APIs).

Why This Is Better Than Your VB Code

Your original VB code authenticated as the target user, which required their password. This approach authenticates as a trusted user who can query permissions, then checks the target user's access directly through TFS's security system—no target credentials needed.

内容的提问来源于stack exchange,提问作者Yallappa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:52:39