Repository navigation
Updated performAccessCheck doc #2959
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
8498460
Updated performAccessCheck doc
mnocon e60738f
Selfreview
mnocon d94bf21
Update docs/permissions/permission_overview.md
mnocon 6efac8c
Review feedback
mnocon 2a2c20f
Merge remote-tracking branch 'origin/5.0' into fix-performAccessCheck
mnocon 7c89d40
Merge remote-tracking branch 'origin/5.0' into fix-performAccessCheck
mnocon 8466384
Fixed typo
mnocon 05048db
Update docs/permissions/custom_policies.md
mnocon File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
61 changes: 61 additions & 0 deletions
61
code_samples/back_office/limitation/src/Controller/CustomLimitationController.php
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,61 @@ | ||
| <?php declare(strict_types=1); | ||
|
|
||
| namespace App\Controller; | ||
|
|
||
| use App\Security\Limitation\CustomLimitationValue; | ||
| use Ibexa\Contracts\AdminUi\Controller\Controller; | ||
| use Ibexa\Contracts\AdminUi\Permission\PermissionCheckerInterface; | ||
| use Ibexa\Contracts\Core\Repository\PermissionResolver; | ||
| use Ibexa\Core\MVC\Symfony\Security\Authorization\Attribute; | ||
| use Symfony\Component\HttpFoundation\Request; | ||
| use Symfony\Component\HttpFoundation\Response; | ||
| use Symfony\Component\Routing\Attribute\Route; | ||
|
|
||
| class CustomLimitationController extends Controller | ||
| { | ||
| public function __construct( | ||
| // ..., | ||
| private readonly PermissionResolver $permissionResolver, | ||
| private readonly PermissionCheckerInterface $permissionChecker | ||
| ) { | ||
| } | ||
|
|
||
| // Controller actions... | ||
| #[Route( | ||
| '/custom-limitation', | ||
| name: 'app.custom_limitation', | ||
| defaults: ['siteaccess_group_whitelist' => '%admin_group_name%'] | ||
| )] | ||
| public function customAction(Request $request): Response | ||
| { | ||
| // ... | ||
| if ($this->getCustomLimitationValue()) { | ||
| // Action only for user having the custom limitation checked | ||
| } | ||
|
|
||
| return new Response('<html><body>...</body></html>'); | ||
| } | ||
|
|
||
| private function getCustomLimitationValue(): bool | ||
| { | ||
| $hasAccess = $this->permissionResolver->hasAccess('custom_module', 'custom_function_2'); | ||
|
|
||
| if (is_bool($hasAccess)) { | ||
| return $hasAccess; | ||
| } | ||
|
|
||
| $customLimitationValues = $this->permissionChecker->getRestrictions( | ||
| $hasAccess, | ||
| CustomLimitationValue::class | ||
| ); | ||
|
|
||
| return $customLimitationValues['value'] ?? false; | ||
| } | ||
|
|
||
| #[\Override] | ||
| public function performAccessCheck(): void | ||
| { | ||
| parent::performAccessCheck(); | ||
| $this->denyAccessUnlessGranted(new Attribute('custom_module', 'custom_function_2')); | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -34,23 +34,21 @@ The more role assignments and complex policies you add for a given user, the mor | |
|
|
||
| ## Permissions for custom controllers | ||
|
|
||
| You can control access to a custom controller by implementing the `performAccessCheck()` method. | ||
| You can control access to a custom controller by implementing the [`RestrictedControllerInterface`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-RestrictedControllerInterface.html) interface directly or, for back office controllers, by extending the [`\Ibexa\Contracts\AdminUi\Controller\Controller`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-AdminUi-Controller-Controller.html) class. | ||
|
|
||
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy: | ||
| In the following example, the user doesn't have access to the controller unless they are [logged in]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in) and have the `section/view` policy. | ||
| The controller uses [`AuthenticatedRememberedCheckTrait::performAccessCheck()`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-AuthenticatedRememberedCheckTrait.html#method_performAccessCheck), aliased as `traitPerformAccessCheck()`, for the login check. | ||
|
|
||
| ``` php {skip-validation} | ||
| use Ibexa\Core\MVC\Symfony\Security\Authorization\Attribute; | ||
|
|
||
| public function performAccessCheck(): void | ||
| { | ||
| parent::performAccessCheck(); | ||
| $this->denyAccessUnlessGranted(new Attribute('section', 'view')); | ||
| } | ||
| ``` php hl_lines="14-16 18-23" | ||
| [[= include_code('code_samples/back_office/limitation/src/Controller/CustomController.php') =]] | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. OK, I understand why a renamed file is in fact still there 😅 |
||
| ``` | ||
|
|
||
| Back office controllers that extend `Ibexa\Contracts\AdminUi\Controller\Controller` already use `AuthenticatedRememberedCheckTrait`. | ||
| To add a policy check, override `performAccessCheck()` and call `parent::performAccessCheck()` first, as in the [custom limitation check example](custom_policies.md#custom-limitation-check). | ||
|
|
||
| `Attribute` accepts three arguments: | ||
|
|
||
| - `module` is the policy module (for example,`content`) | ||
| - `module` is the policy module (for example, `content`) | ||
| - `function` is the function inside the module (for example, `read`) | ||
| - `limitations` are optional limitations to check against. Here you can provide two keys: | ||
| - `valueObject` is the object you want to check for, for example `ContentInfo`. | ||
|
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Really good to explain that part.