1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
use App\Common\Acl; |
4
|
|
|
use App\Common\Config\Definition\AclConfigDefinition; |
5
|
|
|
|
6
|
|
|
// ACL |
7
|
|
|
return [ |
8
|
|
|
'definition' => AclConfigDefinition::class, |
9
|
|
|
|
10
|
|
|
'acl' => [ |
11
|
|
|
'default_role' => 'guest', |
12
|
|
|
|
13
|
|
|
'roles' => [ |
14
|
|
|
// role => [multiple parents specification as array] |
15
|
|
|
'guest' => [], |
16
|
|
|
'user' => ['guest'], |
17
|
|
|
'admin' => ['user'], |
18
|
|
|
], |
19
|
|
|
|
20
|
|
|
/** |
21
|
|
|
* just a list of generic resources for manual checking |
22
|
|
|
* specified here so can be used in the code if needs be |
23
|
|
|
* Example: ['user' => null] |
24
|
|
|
*/ |
25
|
|
|
'resources' => [ |
26
|
|
|
// resource => parent |
27
|
|
|
], |
28
|
|
|
|
29
|
|
|
// where we specify the guarding! |
30
|
|
|
'guards' => [ |
31
|
|
|
|
32
|
|
|
/** |
33
|
|
|
* list of resource to roles to permissions |
34
|
|
|
* optional |
35
|
|
|
* if included all resources default to deny unless specified. |
36
|
|
|
* Example: ['user', ['admin']] |
37
|
|
|
*/ |
38
|
|
|
Acl::GUARD_TYPE_RESOURCE => [ |
39
|
|
|
|
40
|
|
|
], |
41
|
|
|
|
42
|
|
|
/** |
43
|
|
|
* list of literal routes for guarding. |
44
|
|
|
* optional |
45
|
|
|
* if included all routes default to deny unless specified. |
46
|
|
|
* Similar format to resource 'resource' route, roles, 'permission' action |
47
|
|
|
* ['route', ['roles'], ['privilege1', 'privilege2']] |
48
|
|
|
*/ |
49
|
|
|
Acl::GUARD_TYPE_ROUTE => [ |
50
|
|
|
// resource, [roles as array], [privileges as array] |
|
|
|
|
51
|
|
|
['/api/token', ['guest'], [Acl::PRIVILEGE_POST]], |
52
|
|
|
['/api/user', ['user'], [Acl::PRIVILEGE_GET]], |
53
|
|
|
['/api/upload', ['user'], [Acl::PRIVILEGE_POST]], |
54
|
|
|
], |
55
|
|
|
|
56
|
|
|
/** |
57
|
|
|
* list of callables to resolve against |
58
|
|
|
* optional |
59
|
|
|
* if included all callables default to deny unless specified. |
60
|
|
|
* 'permission' section is combined into the callable section |
61
|
|
|
* ['callable', ['roles']] |
62
|
|
|
*/ |
63
|
|
|
Acl::GUARD_TYPE_CALLABLE => [ |
64
|
|
|
// resource, [roles as array], [privileges as array] |
|
|
|
|
65
|
|
|
['App\Controller\CrudController', ['user']], |
66
|
|
|
['App\Controller\CrudController:actionIndex', ['user']], |
67
|
|
|
['App\Controller\CrudController:actionGet', ['user']], |
68
|
|
|
['App\Controller\CrudController:actionCreate', ['user']], |
69
|
|
|
['App\Controller\CrudController:actionUpdate', ['user']], |
70
|
|
|
['App\Controller\CrudController:actionDelete', ['user']], |
71
|
|
|
|
72
|
|
|
['App\Controller\UploadController:actionUpload', ['user']], |
73
|
|
|
|
74
|
|
|
['App\Controller\UserController:actionIndex', ['user']], |
75
|
|
|
['App\Controller\UserController:actionGet', ['user']], |
76
|
|
|
['App\Controller\UserController:actionCreate', ['admin']], |
77
|
|
|
['App\Controller\UserController:actionUpdate', ['admin']], |
78
|
|
|
['App\Controller\UserController:actionDelete', ['admin']], |
79
|
|
|
], |
80
|
|
|
], |
81
|
|
|
], |
82
|
|
|
]; |
83
|
|
|
|
Sometimes obsolete code just ends up commented out instead of removed. In this case it is better to remove the code once you have checked you do not need it.
The code might also have been commented out for debugging purposes. In this case it is vital that someone uncomments it again or your project may behave in very unexpected ways in production.
This check looks for comments that seem to be mostly valid code and reports them.