AccessControl.php 5.24 KB
Newer Older
1 2 3 4 5 6 7
 * @link
 * @copyright Copyright (c) 2008 Yii Software LLC
 * @license

namespace yii\filters;
9 10 11 12

use Yii;
use yii\base\Action;
use yii\base\ActionFilter;
use yii\di\Instance;
14 15
use yii\web\User;
use yii\web\ForbiddenHttpException;
16 17

18 19 20 21 22
 * AccessControl provides simple access control based on a set of rules.
 * AccessControl is an action filter. It will check its [[rules]] to find
 * the first rule that matches the current context variables (such as user IP address, user role).
 * The matching rule will dictate whether to allow or deny the access to the requested controller
 * action. If no rule matches, the access will be denied.
24 25 26 27 28 29 30 31
 * To use AccessControl, declare it in the `behaviors()` method of your controller class.
 * For example, the following declarations will allow authenticated users to access the "create"
 * and "update" actions and deny all other users from accessing these two actions.
 * ~~~
 * public function behaviors()
 * {
Alexander Makarov committed
32 33
 *     return [
 *         'access' => [
 *             'class' => \yii\filters\AccessControl::className(),
Alexander Makarov committed
35 36
 *             'only' => ['create', 'update'],
 *             'rules' => [
 *                 // deny all POST requests
Alexander Makarov committed
 *                 [
 *                     'allow' => false,
Alexander Makarov committed
40 41
 *                     'verbs' => ['POST']
 *                 ],
 *                 // allow authenticated users
Alexander Makarov committed
 *                 [
 *                     'allow' => true,
Alexander Makarov committed
45 46
 *                     'roles' => ['@'],
 *                 ],
 *                 // everything else is denied
Alexander Makarov committed
48 49 50
 *             ],
 *         ],
 *     ];
51 52
 * }
 * ~~~
53 54 55 56 57 58
 * @author Qiang Xue <>
 * @since 2.0
class AccessControl extends ActionFilter
59 60 61 62
     * @var User|string the user object representing the authentication status or the ID of the user application component.
    public $user = 'user';
63 64 65 66 67 68 69 70 71 72
     * @var callable a callback that will be called if the access should be denied
     * to the current user. If not set, [[denyAccess()]] will be called.
     * The signature of the callback should be as follows:
     * ~~~
     * function ($rule, $action)
     * ~~~
Qiang Xue committed
73 74
     * where `$rule` is the rule that denies the user, and `$action` is the current [[Action|action]] object.
     * `$rule` can be `null` if access is denied because none of the rules matched.
75 76 77 78 79 80
    public $denyCallback;
     * @var array the default configuration of access rules. Individual rule configurations
     * specified via [[rules]] will take precedence when the same property of the rule is configured.
    public $ruleConfig = ['class' => 'yii\filters\AccessRule'];
82 83 84 85 86 87 88
     * @var array a list of access rule objects or configuration arrays for creating the rule objects.
     * If a rule is specified via a configuration array, it will be merged with [[ruleConfig]] first
     * before it is used for creating the rule object.
     * @see ruleConfig
    public $rules = [];


91 92 93 94 95 96
     * Initializes the [[rules]] array by instantiating rule objects from configurations.
    public function init()
        $this->user = Instance::ensure($this->user, User::className());
98 99 100 101 102 103
        foreach ($this->rules as $i => $rule) {
            if (is_array($rule)) {
                $this->rules[$i] = Yii::createObject(array_merge($this->ruleConfig, $rule));

105 106 107
     * This method is invoked right before an action is to be executed (after all possible filters.)
     * You may override this method to do last-minute preparation for the action.
     * @param Action $action the action to be executed.
109 110 111 112
     * @return boolean whether the action should continue to be executed.
    public function beforeAction($action)
        $user = $this->user;
114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130
        $request = Yii::$app->getRequest();
        /** @var AccessRule $rule */
        foreach ($this->rules as $rule) {
            if ($allow = $rule->allows($action, $user, $request)) {
                return true;
            } elseif ($allow === false) {
                if (isset($rule->denyCallback)) {
                    call_user_func($rule->denyCallback, $rule, $action);
                } elseif (isset($this->denyCallback)) {
                    call_user_func($this->denyCallback, $rule, $action);
                } else {
                return false;
        if (isset($this->denyCallback)) {
            call_user_func($this->denyCallback, null, $action);
132 133 134 135 136 137 138 139 140 141
        } else {
        return false;

     * Denies the access of the user.
     * The default implementation will redirect the user to the login page if he is a guest;
     * if the user is already logged, a 403 HTTP exception will be thrown.
     * @param User $user the current user
143 144 145 146 147 148 149 150 151 152
     * @throws ForbiddenHttpException if the user is already logged in.
    protected function denyAccess($user)
        if ($user->getIsGuest()) {
        } else {
            throw new ForbiddenHttpException(Yii::t('yii', 'You are not allowed to perform this action.'));
Zander Baldwin committed