15.9 KB
Newer Older
Alexander Makarov committed
1 2 3

Larry Ullman committed
4 5
In keeping with the MVC approach, a model in Yii is intended for storing or temporarily representing application data, as well as defining the busines rules by which the data must abide.

Alexander Makarov committed
Yii models have the following basic features:
Alexander Makarov committed

Larry Ullman committed
8 9 10 11
- Attribute declaration: a model defines what is considered an attribute.
- Attribute labels: each attribute may be associated with a label for display purpose.
- Massive attribute assignment: the ability to populate multiple model attributes in one step.
- Scenario-based data validation.
Alexander Makarov committed

Models in Yii extend from the [[yii\base\Model]] class. Models are typically used to both hold data and define
Alexander Makarov committed
14 15 16 17 18
the validation rules for that data (aka, the business logic). The business logic greatly simplifies the generation
of models from complex web forms by providing validation and error reporting.

The Model class is also the base class for more advanced models with additional functionality, such
as [Active Record](
Alexander Makarov committed
19 20 21 22


23 24 25
The actual data represented by a model is stored in the model's *attributes*. Model attributes can
be accessed like the member variables of any object. For example, a `Post` model
may contain a `title` attribute and a `content` attribute, accessible as follows:
Alexander Makarov committed
26 27

$post = new Post();
Alexander Makarov committed
$post->title = 'Hello, world';
Alexander Makarov committed
$post->content = 'Something interesting is happening.';
Alexander Makarov committed
31 32 33 34
echo $post->title;
echo $post->content;

Since [[yii\base\Model|Model]] implements the [ArrayAccess]( interface,
you can also access the attributes as if they were array elements:
Alexander Makarov committed
37 38

$post = new Post();
Alexander Makarov committed
40 41 42 43 44 45
$post['title'] = 'Hello, world';
$post['content'] = 'Something interesting is happening';
echo $post['title'];
echo $post['content'];

By default, [[yii\base\Model|Model]] requires that attributes be declared as *public* and *non-static*
Qiang Xue committed
47 48
class member variables. In the following example, the `LoginForm` model class declares two attributes:
`username` and `password`.
Alexander Makarov committed
49 50 51 52 53

// LoginForm has two attributes: username and password
class LoginForm extends \yii\base\Model
54 55
    public $username;
    public $password;
Alexander Makarov committed
56 57 58

59 60
Derived model classes may declare attributes in different ways, by overriding the [[yii\base\Model::attributes()|attributes()]]
method. For example, [[yii\db\ActiveRecord]] defines attributes using the column names of the database table
Qiang Xue committed
that is associated with the class.
Alexander Makarov committed
62 63

Qiang Xue committed
Attribute Labels
Carsten Brandt committed
Alexander Makarov committed
66 67

Attribute labels are mainly used for display purpose. For example, given an attribute `firstName`, we can declare
a label `First Name` that is more user-friendly when displayed to end users in places such as form labels and
error messages. Given an attribute name, you can obtain its label by calling [[yii\base\Model::getAttributeLabel()]].
Alexander Makarov committed

To declare attribute labels, override the [[yii\base\Model::attributeLabels()]] method. The overridden method returns
Alexander Makarov committed
a mapping of attribute names to attribute labels, as shown in the example below. If an attribute is not found
73 74
in this mapping, its label will be generated using the [[yii\base\Model::generateAttributeLabel()]] method.
In many cases, [[yii\base\Model::generateAttributeLabel()]] will generate reasonable labels (e.g. `username` to `Username`,
Alexander Makarov committed
`orderNumber` to `Order Number`).
Alexander Makarov committed
76 77 78 79 80

// LoginForm has two attributes: username and password
class LoginForm extends \yii\base\Model
81 82 83 84 85 86 87 88 89 90
    public $username;
    public $password;

    public function attributeLabels()
        return [
            'username' => 'Your name',
            'password' => 'Your password',
Alexander Makarov committed
91 92 93 94 95 96


A model may be used in different *scenarios*. For example, a `User` model may be used to collect user login inputs,
Alexander Makarov committed
98 99
but it may also be used for user registration purposes. In the one scenario, every piece of data is required;
in the other, only the username and password would be.
100 101 102 103

To easily implement the business logic for different scenarios, each model has a property named `scenario`
that stores the name of the scenario that the model is currently being used in. As will be explained in the next
few sections, the concept of scenarios is mainly used for data validation and massive attribute assignment.
Alexander Makarov committed
104 105 106

Associated with each scenario is a list of attributes that are *active* in that particular scenario. For example,
in the `login` scenario, only the `username` and `password` attributes are active; while in the `register` scenario,
additional attributes such as `email` are *active*. When an attribute is *active* this means that it is subject to validation.
Alexander Makarov committed

109 110
Possible scenarios should be listed in the `scenarios()` method. This method returns an array whose keys are the scenario
names and whose values are lists of attributes that should be active in that scenario:
Alexander Makarov committed
111 112 113 114

class User extends \yii\db\ActiveRecord
115 116 117 118 119 120 121
    public function scenarios()
        return [
            'login' => ['username', 'password'],
            'register' => ['username', 'email', 'password'],
Alexander Makarov committed
122 123 124

Alexander Makarov committed
125 126 127
If `scenarios` method is not defined, default scenario is applied. That means attributes with validation rules are
considered *active*.

If you want to keep the default scenario available besides your own scenarios, use inheritance to include it:

130 131 132
class User extends \yii\db\ActiveRecord
133 134 135 136 137 138 139
    public function scenarios()
        $scenarios = parent::scenarios();
        $scenarios['login'] = ['username', 'password'];
        $scenarios['register'] = ['username', 'email', 'password'];
        return $scenarios;
140 141 142 143

144 145
Sometimes, we want to mark an attribute as not safe for massive assignment (but we still want the attribute to be validated).
We may do so by prefixing an exclamation character to the attribute name when declaring it in `scenarios()`. For example:
Alexander Makarov committed
146 147

Alexander Makarov committed
['username', 'password', '!secret']
Alexander Makarov committed
149 150

151 152 153
In this example `username`, `password` and `secret` are *active* attributes but only `username` and `password` are
considered safe for massive assignment.

Identifying the active model scenario can be done using one of the following approaches:
155 156 157 158

class EmployeeController extends \yii\web\Controller
159 160 161 162 163 164 165 166 167 168 169 170 171 172 173
    public function actionCreate($id = null)
        // first way
        $employee = new Employee(['scenario' => 'managementPanel']);

        // second way
        $employee = new Employee();
        $employee->scenario = 'managementPanel';

        // third way
        $employee = Employee::find()->where('id = :id', [':id' => $id])->one();
        if ($employee !== null) {
            $employee->scenario = 'managementPanel';
174 175 176

The example above presumes that the model is based upon [Active Record]( For basic form models,
Alexander Makarov committed
178 179 180
scenarios are rarely needed, as the basic form model is normally tied directly to a single form and, as noted above,
the default implementation of the `scenarios()` returns every property with active validation rule making it always
available for mass assignment and validation.


Alexander Makarov committed
183 184 185 186 187 188 189 190 191

When a model is used to collect user input data via its attributes, it usually needs to validate the affected attributes
to make sure they satisfy certain requirements, such as an attribute cannot be empty, an attribute must contain letters
only, etc. If errors are found in validation, they may be presented to the user to help him fix the errors.
The following example shows how the validation is performed:

$model = new LoginForm();
Alexander Makarov committed
193 194 195
$model->username = $_POST['username'];
$model->password = $_POST['password'];
if ($model->validate()) {
    // ... login the user ...
Alexander Makarov committed
} else {
198 199
    $errors = $model->getErrors();
    // ... display the errors to the end user ...
Alexander Makarov committed
200 201 202 203 204

The possible validation rules for a model should be listed in its `rules()` method. Each validation rule applies to one
or several attributes and is effective in one or several scenarios. A rule can be specified using a validator object - an
instance of a [[yii\validators\Validator]] child class, or an array with the following format:
Alexander Makarov committed
206 207

Alexander Makarov committed
209 210 211 212 213 214 215 216 217 218
    ['attribute1', 'attribute2', ...],
    'validator class or alias',
    // specifies in which scenario(s) this rule is active.
    // if not given, it means it is active in all scenarios
    'on' => ['scenario1', 'scenario2', ...],
    // the following name-value pairs will be used
    // to initialize the validator properties
    'property1' => 'value1',
    'property2' => 'value2',
    // ...
Alexander Makarov committed
Alexander Makarov committed
220 221 222 223

When `validate()` is called, the actual validation rules executed are determined using both of the following criteria:

Carsten Brandt committed
224 225
- the rule must be associated with at least one active attribute;
- the rule must be active for the current scenario.
Alexander Makarov committed
226 227

228 229 230
### Creating your own validators (Inline validators)

If none of the built in validators fit your needs, you can create your own validator by creating a method in you model class.
231 232
This method will be wrapped by an [[yii\validators\InlineValidator|InlineValidator]] an be called upon validation.
You will do the validation of the attribute and [[yii\base\Model::addError()|add errors]] to the model when validation fails.
233 234 235 236 237 238 239 240

The method has the following signature `public function myValidator($attribute, $params)` while you are free to choose the name.

Here is an example implementation of a validator validating the age of a user:

public function validateAge($attribute, $params)
241 242 243 244
    $value = $this->$attribute;
    if (strtotime($value) > strtotime('now - ' . $params['min'] . ' years')) {
        $this->addError($attribute, 'You must be at least ' . $params['min'] . ' years old to register for this service.');
245 246 247 248

public function rules()
249 250 251 252
    return [
        // ...
        [['birthdate'], 'validateAge', 'params' => ['min' => '12']],
253 254 255

256 257
You may also set other properties of the [[yii\validators\InlineValidator|InlineValidator]] in the rules definition,
for example the [[yii\validators\InlineValidator::$skipOnEmpty|skipOnEmpty]] property:
258 259 260 261 262

[['birthdate'], 'validateAge', 'params' => ['min' => '12'], 'skipOnEmpty' => false],

### Conditional validation
264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290

To validate attributes only when certain conditions apply, e.g. the validation of
one field depends on the value of another field you can use [[yii\validators\Validator::when|the `when` property]]
to define such conditions:

['state', 'required', 'when' => function($model) { return $model->country == Country::USA; }],
['stateOthers', 'required', 'when' => function($model) { return $model->country != Country::USA; }],
['mother', 'required', 'when' => function($model) { return $model->age < 18 && $model->married != true; }],

For better readability the conditions can also be written like this:

public function rules()
    $usa = function($model) { return $model->country == Country::USA; };
    $notUsa = function($model) { return $model->country != Country::USA; };
    $child = function($model) { return $model->age < 18 && $model->married != true; };
    return [
        ['state', 'required', 'when' => $usa],
        ['stateOthers', 'required', 'when' => $notUsa], // note that it is not possible to write !$usa
        ['mother', 'required', 'when' => $child],

Evgeniy Tkachenko committed
291 292 293 294 295 296 297 298 299
When you need conditional validation logic on client-side (`enableClientValidation` is true), don't forget 
to add `whenClient`:

public function rules()
    $usa = [
        'server-side' => function($model) { return $model->country == Country::USA; },
        'client-side' => "function (attribute, value) {return $('#country').value == 'USA';}"
Evgeniy Tkachenko committed
Evgeniy Tkachenko committed
301 302 303 304 305 306 307
    return [
        ['state', 'required', 'when' => $usa['server-side'], 'whenClient' => $usa['client-side']],


Alexander Makarov committed
309 310 311 312 313 314 315 316
Massive Attribute Retrieval and Assignment

Attributes can be massively retrieved via the `attributes` property.
The following code will return *all* attributes in the `$post` model
as an array of name-value pairs.

Alexander Makarov committed
$post = Post::findOne(42);
Alexander Makarov committed
if ($post) {
319 320
    $attributes = $post->attributes;
Alexander Makarov committed
Alexander Makarov committed
322 323 324 325 326

Using the same `attributes` property you can massively assign data from associative array to model attributes:

Alexander Makarov committed
$post = new Post();
Alexander Makarov committed
$attributes = [
329 330
    'title' => 'Massive assignment example',
    'content' => 'Never allow assigning attributes that are not meant to be assigned.',
Alexander Makarov committed
Alexander Makarov committed
$post->attributes = $attributes;
MetalGuardian committed
Alexander Makarov committed
334 335

Carsten Brandt committed
In the code above we're assigning corresponding data to model attributes named as array keys. The key difference from mass
Alexander Makarov committed
337 338 339
retrieval that always works for all attributes is that in order to be assigned an attribute should be **safe** else
it will be ignored.

Carsten Brandt committed

Alexander Makarov committed
341 342 343 344 345 346 347 348
Validation rules and mass assignment

In Yii2 unlike Yii 1.x validation rules are separated from mass assignment. Validation
rules are described in `rules()` method of the model while what's safe for mass
assignment is described in `scenarios` method:

Alexander Makarov committed
class User extends ActiveRecord
Alexander Makarov committed
351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371
    public function rules()
        return [
            // rule applied when corresponding field is "safe"
            ['username', 'string', 'length' => [4, 32]],
            ['first_name', 'string', 'max' => 128],
            ['password', 'required'],

            // rule applied when scenario is "signup" no matter if field is "safe" or not
            ['hashcode', 'check', 'on' => 'signup'],

    public function scenarios()
        return [
            // on signup allow mass assignment of username
            'signup' => ['username', 'password'],
            'update' => ['username', 'first_name'],
Alexander Makarov committed
Alexander Makarov committed
373 374

For the code above mass assignment will be allowed strictly according to `scenarios()`:
Alexander Makarov committed
376 377

Alexander Makarov committed
$user = User::findOne(42);
Alexander Makarov committed
379 380
$data = ['password' => '123'];
$user->attributes = $data;
Alexander Makarov committed
382 383 384 385 386

Will give you empty array because there's no default scenario defined in our `scenarios()`.

Alexander Makarov committed
$user = User::findOne(42);
Alexander Makarov committed
388 389
$user->scenario = 'signup';
$data = [
390 391 392
    'username' => 'samdark',
    'password' => '123',
    'hashcode' => 'test',
Alexander Makarov committed
393 394
$user->attributes = $data;
Alexander Makarov committed
396 397 398 399 400 401

Will give you the following:

402 403 404 405
    'username' => 'samdark',
    'first_name' => null,
    'password' => '123',
    'hashcode' => null, // it's not defined in scenarios method
Alexander Makarov committed
406 407 408 409

In case of not defined `scenarios` method like the following:
Alexander Makarov committed

Alexander Makarov committed
411 412
class User extends ActiveRecord
Alexander Makarov committed
414 415 416 417 418 419 420 421
    public function rules()
        return [
            ['username', 'string', 'length' => [4, 32]],
            ['first_name', 'string', 'max' => 128],
            ['password', 'required'],
Alexander Makarov committed
422 423 424

Alexander Makarov committed
425 426 427
The code above assumes default scenario so mass assignment will be available for all fields with `rules` defined:

Alexander Makarov committed
$user = User::findOne(42);
Alexander Makarov committed
$data = [
430 431 432 433
    'username' => 'samdark',
    'first_name' => 'Alexander',
    'last_name' => 'Makarov',
    'password' => '123',
Alexander Makarov committed
434 435
$user->attributes = $data;
Alexander Makarov committed
437 438 439

Will give you the following:
Alexander Makarov committed

Alexander Makarov committed
441 442
443 444 445
    'username' => 'samdark',
    'first_name' => 'Alexander',
    'password' => '123',
Alexander Makarov committed
446 447
Carsten Brandt committed

Alexander Makarov committed
If you want some fields to be unsafe for default scenario:
450 451 452 453

class User extends ActiveRecord
454 455 456 457 458 459 460 461 462 463 464 465 466 467 468
    function rules()
        return [
            ['username', 'string', 'length' => [4, 32]],
            ['first_name', 'string', 'max' => 128],
            ['password', 'required'],

    public function scenarios()
        return [
            self::SCENARIO_DEFAULT => ['username', 'first_name', '!password']
469 470 471 472 473 474

Mass assignment is still available by default:

Alexander Makarov committed
$user = User::findOne(42);
$data = [
477 478 479
    'username' => 'samdark',
    'first_name' => 'Alexander',
    'password' => '123',
480 481
$user->attributes = $data;
Alexander Makarov committed
483 484 485 486 487 488

The code above gives you:

489 490 491
    'username' => 'samdark',
    'first_name' => 'Alexander',
    'password' => null, // because of ! before field name in scenarios
492 493 494

Alexander Makarov committed
495 496 497 498
See also

- [Model validation reference](
- [[yii\base\Model]]