You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit fc3ed11
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/book/v7/core-features/authorization.md
+14-29Lines changed: 14 additions & 29 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,8 +25,7 @@ Dotkernel API makes use of `mezzio-authorization-rbac` and includes the full con
25
25
26
26
The configuration file for the role and permission definitions is `config/autoload/authorization.global.php`.
27
27
28
-
Roles are the backed enums `Core\Admin\Enum\AdminRoleEnum` (`superuser`, `admin`) and
29
-
`Core\User\Enum\UserRoleEnum` (`user`, `guest`), so the array keys are their `->value` strings.
28
+
Roles are the backed enums `Core\Admin\Enum\AdminRoleEnum` (`superuser`, `admin`) and `Core\User\Enum\UserRoleEnum` (`user`, `guest`), so the array keys are their `->value` strings.
30
29
31
30
```php
32
31
use Core\Admin\Enum\AdminRoleEnum;
@@ -97,28 +96,21 @@ return [
97
96
```
98
97
99
98
That is the complete shipped configuration, not an excerpt.
100
-
Between them the three populated roles grant **38 permissions covering all 38 routes**: every route
101
-
the application declares is reachable by at least one role, and no permission names a route that
102
-
does not exist.
99
+
Between them the three populated roles grant **38 permissions covering all 38 routes**: every route the application declares is reachable by at least one role, and no permission names a route that does not exist.
103
100
Only `app::view-index` and `app::create-error-report` are granted twice, to both `admin` and `guest`.
104
101
105
-
> See [mezzio-authorization-rbac](https://docs.mezzio.dev/mezzio-authorization-rbac/v1/basic-usage/)
106
-
> for more information.
102
+
> See [mezzio-authorization-rbac](https://docs.mezzio.dev/mezzio-authorization-rbac/v1/basic-usage/) for more information.
107
103
108
104
## Usage
109
105
110
-
Based on the configuration file above, we have two admin roles (`superuser`, `admin`) and two user
111
-
roles (`user`, `guest`).
106
+
Based on the configuration file above, we have two admin roles (`superuser`, `admin`) and two user roles (`user`, `guest`).
112
107
113
-
A permission in Dotkernel API is a **route name** — the third argument given to the route in a
114
-
module's `RoutesDelegator`. To list the names you can grant, run
115
-
`php ./bin/cli.php route:list`; see [Displaying Dotkernel API endpoints](../commands/display-available-endpoints.md).
108
+
A permission in Dotkernel API is a **route name** — the third argument given to the route in a module's `RoutesDelegator`.
109
+
To list the names you can grant, run `php ./bin/cli.php route:list`; see [Displaying Dotkernel API endpoints](../commands/display-available-endpoints.md).
116
110
117
111
### How inheritance works here
118
112
119
-
The array under `roles` maps a role to its **parents**, and inheritance runs in the direction that
120
-
often surprises people: a **parent receives the permissions of its children**, because
121
-
`laminas-permissions-rbac` resolves `hasPermission()` by walking down into child roles.
113
+
The array under `roles` maps a role to its **parents**, and inheritance runs in the direction that often surprises people: a **parent receives the permissions of its children**, because `laminas-permissions-rbac` resolves `hasPermission()` by walking down into child roles.
122
114
123
115
So in the shipped configuration:
124
116
@@ -128,12 +120,9 @@ So in the shipped configuration:
128
120
|`admin => [superuser]`|`superuser` is the parent of `admin`, so **`superuser` inherits everything granted to `admin`**|
129
121
|`guest => [user]`|`user` is the parent of `guest`, so **`user` inherits everything granted to `guest`**|
130
122
131
-
That is why `superuser` needs no permissions of its own: its list is empty, yet it can reach all 23
132
-
routes granted to `admin`.
123
+
That is why `superuser` needs no permissions of its own: its list is empty, yet it can reach all 23 routes granted to `admin`.
133
124
134
-
It is also why `user` ends up with 17 effective permissions — its own 6 plus the 11 granted to
135
-
`guest` — while `guest` keeps only its own 11 and cannot reach the account routes reserved for a
136
-
signed-in user.
125
+
It is also why `user` ends up with 17 effective permissions — its own 6 plus the 11 granted to `guest` — while `guest` keeps only its own 11 and cannot reach the account routes reserved for a signed-in user.
137
126
138
127
Effective totals, once inheritance is applied:
139
128
@@ -146,23 +135,19 @@ Effective totals, once inheritance is applied:
146
135
147
136
### How a request is authorized
148
137
149
-
`AuthorizationMiddleware` injects `Mezzio\Authorization\AuthorizationInterface` rather than an RBAC
150
-
class directly — the RBAC adapter is bound by `Mezzio\Authorization\Rbac\ConfigProvider`, registered
151
-
in `config/config.php`.
138
+
`AuthorizationMiddleware` injects `Mezzio\Authorization\AuthorizationInterface` rather than an RBAC class directly — the RBAC adapter is bound by `Mezzio\Authorization\Rbac\ConfigProvider`, registered in `config/config.php`.
152
139
153
140
For each request it:
154
141
155
-
1. Reads `oauth_client_id` from the authenticated identity and loads the matching record — `admin` from the `admin` table, `frontend` from the `user` table, or a `Guest` instance when the client is `guest`. An unrecognised client is rejected.
142
+
1. Reads `oauth_client_id` from the authenticated identity and loads the matching record — `admin` from the `admin` table, `frontend` from the `user` table, or a `Guest` instance when the client is `guest`.
143
+
An unrecognised client is rejected.
156
144
2. Rejects an account that is inactive, or a user that has been deleted.
157
145
3. Replaces the identity's roles with the role names read from that record.
158
146
4. Calls `isGranted()` once per role and allows the request as soon as **any** role grants the route.
159
147
160
-
If no role grants it, the response is `403 Forbidden` with
161
-
`You are not allowed to access this resource.`
148
+
If no role grants it, the response is `403 Forbidden` with `You are not allowed to access this resource.`
162
149
163
-
> Note this middleware returns a plain JSON error body rather than a Problem Details document, so an
164
-
> authorization failure does not look like the errors described in
> Note this middleware returns a plain JSON error body rather than a Problem Details document, so an authorization failure does not look like the errors described in [Problem details](../extended-features/problem-details.md).
0 commit comments