我已经定义了我的控制器,但我想保护所有这些,如下所示:
// In my Controller Class
public function chooseDateAction()
{
if($this->get('MY.roles_features')
->isGranted($this->container->get('request')->get('_route')))
{
// Do something
}
else
{
throw new AccessDeniedException();
}
return array( );
}
Run Code Online (Sandbox Code Playgroud)
我必须设计自己的'isGranted'功能,因为它roles是动态的.BTW功能正常!
所以我的问题是我是否必须重复isGranted我的所有功能,Controllers或者我可以把它放在某处以减少代码冗余.
我知道我必须isGranted在我的安全的一些顶级层面,但问题是如何以及在哪里?
尝试编写一个基本控制器,如果isGranted方法通过,将检查构造,否则抛出异常.例如:
<?php
namespace Acme\DolanBundle\Controller;
use Symfony\Bundle\FrameworkBundle\Controller\Controller;
use Symfony\Component\Security\Core\Exception\AccessDeniedException;
class BaseController extends Controller
{
public function __construct()
{
if(!$this->get('MY.roles_features')
->isGranted($this->container->get('request')->get('_route')))
{
throw new AccessDeniedException('Gooby pls');
}
}
}
Run Code Online (Sandbox Code Playgroud)
然后只需在其他控制器中扩展BaseController.
| 归档时间: |
|
| 查看次数: |
790 次 |
| 最近记录: |