Updated performAccessCheck doc - #2959
Conversation
8451cec to
f2b1166
Compare
Preview of modified filesPreview of modified Markdown: |
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy and are [logged in using the "rememeber me cookie"]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in). | ||
| It uses the [`AuthenticatedRememberedCheckTrait`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-AuthenticatedRememberedCheckTrait.html) for the latter check. |
There was a problem hiding this comment.
In the description paragraph,
the policy must match example's new Attribute('custom_module', 'custom_function_2'),
the functions should be introduced in the same order than they're used in the example,
and there was a typo in "rememeber".
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy and are [logged in using the "rememeber me cookie"]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in). | |
| It uses the [`AuthenticatedRememberedCheckTrait`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-AuthenticatedRememberedCheckTrait.html) for the latter check. | |
| In the following example the user doesn't have access to the controller unless they are [logged in using the "remember me cookie"]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in) and have the `custom_module/custom_function_2` policy. | |
| It uses the [`AuthenticatedRememberedCheckTrait::performAccessCheck()`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-AuthenticatedRememberedCheckTrait.html#method_performAccessCheck) for the cookie check. |
I still don't get why we need to use the trait directly when we extends Admin UI Controller which already uses it so parent::performAccessCheck would work. https://doc.ibexa.co/en/5.0/api/php_api/php_api_reference/classes/Ibexa-Contracts-AdminUi-Controller-Controller.html.
Where you implements the RestrictedControllerInterface you don't inherit performAccessCheck, got to implement it, and to use the trait's one, here you need the method alias to have a method of the same name and still use it.
| use App\Security\Limitation\CustomLimitationValue; | ||
| use Ibexa\Contracts\AdminUi\Controller\Controller; | ||
| use Ibexa\Contracts\AdminUi\Permission\PermissionCheckerInterface; | ||
| use Ibexa\Contracts\Core\Repository\PermissionResolver; | ||
| use Ibexa\Contracts\User\Controller\AuthenticatedRememberedCheckTrait; | ||
| use Ibexa\Core\MVC\Symfony\Security\Authorization\Attribute; | ||
| use Symfony\Component\HttpFoundation\Request; | ||
| use Symfony\Component\HttpFoundation\Response; | ||
|
|
||
| class CustomLimitationController extends Controller | ||
| { | ||
| use AuthenticatedRememberedCheckTrait { | ||
| AuthenticatedRememberedCheckTrait::performAccessCheck as public traitPerformAccessCheck; | ||
| } |
There was a problem hiding this comment.
Maybe it's a front office controller and we don't want to extend that. Could it simply implements the RestrictedControllerInterface?
| use App\Security\Limitation\CustomLimitationValue; | |
| use Ibexa\Contracts\AdminUi\Controller\Controller; | |
| use Ibexa\Contracts\AdminUi\Permission\PermissionCheckerInterface; | |
| use Ibexa\Contracts\Core\Repository\PermissionResolver; | |
| use Ibexa\Contracts\User\Controller\AuthenticatedRememberedCheckTrait; | |
| use Ibexa\Core\MVC\Symfony\Security\Authorization\Attribute; | |
| use Symfony\Component\HttpFoundation\Request; | |
| use Symfony\Component\HttpFoundation\Response; | |
| class CustomLimitationController extends Controller | |
| { | |
| use AuthenticatedRememberedCheckTrait { | |
| AuthenticatedRememberedCheckTrait::performAccessCheck as public traitPerformAccessCheck; | |
| } | |
| use App\Security\Limitation\CustomLimitationValue; | |
| use Ibexa\Contracts\AdminUi\Permission\PermissionCheckerInterface; | |
| use Ibexa\Contracts\Core\Repository\PermissionResolver; | |
| use Ibexa\Contracts\User\Controller\AuthenticatedRememberedCheckTrait; | |
| use Ibexa\Contracts\User\Controller\RestrictedControllerInterface | |
| use Ibexa\Core\MVC\Symfony\Security\Authorization\Attribute; | |
| use Symfony\Component\HttpFoundation\Request; | |
| use Symfony\Component\HttpFoundation\Response; | |
| class CustomLimitationController implements RestrictedControllerInterface | |
| { | |
| use AuthenticatedRememberedCheckTrait { | |
| AuthenticatedRememberedCheckTrait::performAccessCheck as public traitPerformAccessCheck; | |
| } |
| You can control access to a custom controller by implementing the [`RestrictedControllerInterface`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-RestrictedControllerInterface.html) interface directly or, for back office controllers, by extending the [`\Ibexa\Contracts\AdminUi\Controller\Controller`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-AdminUi-Controller-Controller.html) class. | ||
|
|
||
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy: | ||
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy and are [logged in using the "rememeber me cookie"]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in). |
There was a problem hiding this comment.
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy and are [logged in using the "rememeber me cookie"]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in). | |
| In the following example, the user doesn't have access to the controller unless they have the `section/view` policy and are [logged in using the "remember me" cookie]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in). |
a5a560a to
6efac8c
Compare
Summary
Errors per inputErrors in site/cdp/cdp_activation/cdp_data_export/index.html
Errors in site/content_management/field_types/field_type_reference/urlfield/index.html
Errors in site/getting_started/requirements/index.html
Errors in site/ibexa_cloud/ibexa_cloud_guide/index.html
Errors in site/ibexa_products/ibexa_commerce/index.html
Errors in site/ibexa_products/ibexa_experience/index.html
Errors in site/ibexa_products/ibexa_headless/index.html
Errors in site/infrastructure_and_maintenance/cache/http_cache/reverse_proxy/index.html
Errors in site/infrastructure_and_maintenance/security/reporting_issues/index.html
Errors in site/product_catalog/quable/install_quable/index.html
Errors in site/product_catalog/quable/quable_api/index.html
Errors in site/recommendations/raptor_integration/connector_installation_configuration/index.html
Errors in site/recommendations/raptor_integration/raptor_connector/index.html
Errors in site/recommendations/raptor_integration/raptor_connector_guide/index.html
Errors in site/release_notes/cohesivo_v6.0_deprecations/index.html
Errors in site/release_notes/ez_platform_v1.10.0/index.html
Errors in site/release_notes/ez_platform_v1.11.0/index.html
Errors in site/release_notes/ez_platform_v1.12.0/index.html
Errors in site/release_notes/ez_platform_v1.13.0_lts/index.html
Errors in site/release_notes/ez_platform_v1.7.0_lts/index.html
Errors in site/release_notes/ez_platform_v1.8.0/index.html
Errors in site/release_notes/ez_platform_v1.9.0/index.html
Errors in site/release_notes/ibexa_dxp_v4.0/index.html
Errors in site/release_notes/ibexa_dxp_v4.4/index.html
Errors in site/release_notes/ibexa_dxp_v4.6/index.html
Errors in site/release_notes/ibexa_dxp_v5.0/index.html
Errors in site/resources/new_in_doc/index.html
Redirects per inputRedirects in site/cdp/cdp_activation/cdp_data_export/index.htmlRedirects in site/content_management/field_types/field_type_reference/urlfield/index.html
Redirects in site/getting_started/requirements/index.html
Redirects in site/ibexa_cloud/ibexa_cloud_guide/index.htmlRedirects in site/ibexa_products/ibexa_commerce/index.html
Redirects in site/ibexa_products/ibexa_experience/index.html
Redirects in site/ibexa_products/ibexa_headless/index.html
Redirects in site/infrastructure_and_maintenance/cache/http_cache/reverse_proxy/index.html
Redirects in site/infrastructure_and_maintenance/security/reporting_issues/index.html
Redirects in site/product_catalog/quable/quable_api/index.html
Redirects in site/release_notes/cohesivo_v6.0_deprecations/index.html
Redirects in site/release_notes/ez_platform_v1.13.0_lts/index.htmlRedirects in site/release_notes/ez_platform_v1.7.0_lts/index.htmlRedirects in site/release_notes/ibexa_dxp_v4.0/index.html
Redirects in site/release_notes/ibexa_dxp_v4.4/index.html
Redirects in site/release_notes/ibexa_dxp_v5.0/index.html
Redirects in site/resources/new_in_doc/index.html
|
|
@adriendupuis I've reworked this example so that:
|
|
|
||
| In the following example the user doesn't have access to the controller unless they have the `section/view` policy: | ||
| In the following example, the user doesn't have access to the controller unless they are [logged in]([[= symfony_doc =]]/security.html#checking-to-see-if-a-user-is-logged-in) and have the `section/view` policy. | ||
| The controller uses [`AuthenticatedRememberedCheckTrait::performAccessCheck()`](/api/php_api/php_api_reference/classes/Ibexa-Contracts-User-Controller-AuthenticatedRememberedCheckTrait.html#method_performAccessCheck), aliases as `traitPerformAccessCheck()`, for the login check. |
| $this->denyAccessUnlessGranted(new Attribute('section', 'view')); | ||
| } | ||
| ``` php hl_lines="14-16 18-23" | ||
| [[= include_code('code_samples/back_office/limitation/src/Controller/CustomController.php') =]] |
There was a problem hiding this comment.
OK, I understand why a renamed file is in fact still there 😅
| [[= include_code('code_samples/back_office/limitation/src/Controller/CustomLimitationController.php') =]] | ||
| ``` | ||
|
|
||
| The `siteaccess_group_whitelist` route default limits the route to the back office SiteAccess group. |
There was a problem hiding this comment.
Really good to explain that part.
Co-authored-by: Adrien Dupuis <61695653+adriendupuis@users.noreply.github.com>
code_samples/ change report
|
* Updated performAccessCheck doc * Selfreview * Update docs/permissions/permission_overview.md * Review feedback * Fixed typo * Update docs/permissions/custom_policies.md Co-authored-by: Adrien Dupuis <61695653+adriendupuis@users.noreply.github.com> --------- Co-authored-by: Adrien Dupuis <61695653+adriendupuis@users.noreply.github.com>
Things done:
include_filecalls manually.