Microsoft 資訊保護 SDK - 檔案 SDK 引擎概念

MIP 檔案 SDK 中的 mip::FileEngine 提供代表指定身分執行所有操作的介面。 為每位登入應用程式的使用者新增一個引擎。 引擎在該身份的情境下執行所有操作。

它 FileEngine 有兩項主要職責:為已認證的使用者列出標籤,以及建立檔案處理器以代表使用者執行檔案操作。

  • mip::FileEngine
  • ListSensitivityLabels():取得已載入引擎的標籤清單。
  • CreateFileHandler():為特定檔案或數據流建立 mip::FileHandler 。

新增檔案引擎

如 Profile 與 engine 物件所述,引擎可以有兩個狀態 - CREATED 或 LOADED。 如果不是這兩個狀態之一,則不存在。 要建立並載入狀態,只需對 進行一次呼叫 FileProfile::LoadAsync。 如果引擎已經存在於快取狀態,則為 LOADED。 如果不存在,則為 CREATED 和 LOADED。 CREATED 表示應用程式擁有載入引擎所需的所有服務資訊。 LOADED 意味著所有使用引擎所需的資料結構都存在於記憶體中。

建立檔案引擎設定

與設定檔類似,引擎也需要設定物件 mip::FileEngine::Settings 此物件儲存唯一引擎識別碼、實作、 mip::AuthDelegate 可自訂的除錯或遙測用戶端資料,以及可選的區域資料。

在這裡,我們會使用應用程式使用者的身分識別來建立 FileEngine::Settings 名為 engineSettings 的物件。

FileEngine::Settings engineSettings(
  mip::Identity(mUsername), // mip::Identity.
  authDelegateImpl,         // auth delegate object
  "",                       // Client data. Customizable by developer, stored with engine.
  "en-US",                  // Locale.
  false);                   // Load sensitive information types for driving classification.

以這種方式建立 engineSettings 時,也請明確設定唯一的 engineId:

engineSettings.SetEngineId(engineId);

使用 使用者名稱或電子郵件 ,有助於確保每次使用者使用服務或應用程式時,同一個引擎都能載入。

此外,也提供自定義引擎識別碼:

FileEngine::Settings engineSettings(
  "myEngineId",     // string
  authDelegateImpl, // auth delegate object
  "",               // Client data in string format. Customizable by developer, stored with engine.
  "en-US",          // Locale. Default is en-US
  false);           // Load sensitive information types for driving classification. Default is false.

最佳實務是使用第一個參數 id,將引擎與相關使用者連結起來。 電子郵件地址、UPN 或 Microsoft Entra 物件 GUID 有助於確保 ID 是唯一,且能從本地狀態載入而無需呼叫服務。

新增檔案引擎

要新增引擎,請改回用來載入設定檔的 promise/future 模式。 與其建立 mip::FileProfile Promise,不如改用 mip::FileEngine 來建立。

  //auto profile will be std::shared_ptr<mip::FileProfile>
  auto profile = profileFuture.get();

  // Instantiate the AuthDelegate implementation.
  auto authDelegateImpl = std::make_shared<sample::auth::AuthDelegateImpl>(appInfo, userName, password);

  //Create the FileEngine::Settings object
  FileEngine::Settings engineSettings("UniqueID", authDelegateImpl, "");

  //Create a promise for std::shared_ptr<mip::FileEngine>
  auto enginePromise = std::make_shared<std::promise<std::shared_ptr<mip::FileEngine>>>();

  //Instantiate the future from the promise
  auto engineFuture = enginePromise->get_future();

  //Add the engine using AddEngineAsync, passing in the engine settings and the promise
  profile->AddEngineAsync(engineSettings, enginePromise);

  //get the future value and store in std::shared_ptr<mip::FileEngine>
  auto engine = engineFuture.get();

程式碼會將已認證使用者的引擎加入設定檔。

列出敏感度標籤

利用新增的引擎,你可以透過呼叫 engine->ListSensitivityLabels(),列出所有可驗證使用者可用的敏感度標籤。

ListSensitivityLabels() 從服務中取得特定使用者的標籤清單及其屬性。 結果會儲存在 std::shared_ptr<mip::Label> 向量中。

更多資訊請參閱mip::Label課程參考。

列出敏感度標籤()

std::vector<shared_ptr<mip::Label>> labels = engine->ListSensitivityLabels();

或者,簡化:

auto labels = engine->ListSensitivityLabels();

列印出這些名稱即可證明應用程式已成功從服務擷取原則並取得標籤。 要套用標籤,你需要標籤識別碼。 以下程式碼會遍歷所有標籤,並顯示每個父標籤和子標籤的 id 與 name。

//Iterate through all labels in the vector
for (const auto& label : labels) {
  //Print label name and GUID
  cout << label->GetName() << " : " << label->GetId() << endl;

  //Print child label name and GUID
  for (const auto& child : label->GetChildren()) {
    cout << "->  " << child->GetName() <<  " : " << child->GetId() << endl;
  }
}

你可以使用 mip::Label 傳回的 GetSensitivityLabels() 集合來顯示使用者可使用的所有標籤,然後在選取後,使用該 ID 將標籤套用至檔案。

下一步

現在設定檔已載入、引擎已加入,且標籤已可供使用,你可以新增處理常式,開始從檔案讀取、寫入或移除標籤。 欲了解更多資訊,請參閱 MIP SDK 中的檔案處理程式。