becklyn / static-roles-bundle
This bundle provides a simple way to define all available roles and their hierarchy in your configuration
Installs: 2 399
Dependents: 0
Suggesters: 0
Security: 0
Stars: 4
Watchers: 3
Forks: 2
Open Issues: 1
Type:symfony-bundle
Requires
- php: >=8.1
- symfony/config: ^6.1 || ^5.0
- symfony/dependency-injection: ^6.1 || ^5.0
- symfony/form: ^6.1 || ^5.0
- symfony/http-kernel: ^6.1 || ^5.0
- symfony/options-resolver: ^6.1 || ^5.0
- symfony/security-core: ^6.1 || ^5.0
- twig/twig: ^2.10 || ^3.0
Requires (Dev)
- symfony/phpunit-bridge: ^5.0
This package is auto-updated.
Last update: 2024-10-12 19:12:00 UTC
README
As user roles are directly coupled to the application code and we would like to configure our roles using an existing VCS (instead of the DB) this bundle implements a simple role system.
You define your roles including the hierarchy in your security.yml and the system provides ways to validated that, list them and for you to select them.
Installation
You can install it via composer:
$ composer require becklyn/static-roles-bundle
Afterwards, you need to activate the bundle in your app/AppKernel.php
:
public function registerBundles() { $bundles = array( // ... new \Becklyn\StaticRolesBundle\BecklynStaticRolesBundle(), // ... ); // ... }
Configuration
Open up app/config/security.yml
and first remove the section role_hierarchy
that is automatically provided by symfony.
Then add your own role configuration on top of the file:
becklyn_static_roles: roles: ROLE_ADMIN: title: "Admin" included_roles: [ROLE_USER] ROLE_USER: title: "User" description: "The default frontend user" tags: [tag1, tag2]
Assigning roles to a user entity
The bundle provides a form type to be used in user forms:
$builder ->add("roles", "static_role", [ "label" => "User roles", "multiple" => true, "expanded" => true, ]);
You will receive an array of roles in the entity as values: ["ROLE_ADMIN", "ROLE_USER"]
.
The mapping of these values can be done using the simple_array
type of doctrine. You need to set it nullable to properly support a user without any roles.
class User implements UserInterface { // ... /** * @var string[] * * @ORM\Column(name="roles", type="simple_array", nullable=true) * */ private $userRoles = null; // ... /** * @inheritdoc */ public function getRoles () { return $this->roles; } /** * @param string[]|null $roles */ public function setRoles (array $roles = null) { $this->roles = $roles; } // ... }
Hidden roles
If you are using roles, that should be used internally, but shouldn't be presented in the form type, you can add hidden: true
to the role definition:
becklyn_static_roles: roles: ROLE_ADMIN: title: "Admin" included_roles: [ROLE_ALLOWED_TO_SWITCH] ROLE_ALLOWED_TO_SWITCH: title: "Internal: The user is allowed to switch roles" hidden: true
In this example, only ROLE_ADMIN
will be selectable by the user.
Tagging
You can tag roles. This is a way to filter the visible roles in the form type. All roles that have at least one of your defined tags will be included.
$builder ->add("roles", "static_role", [ "label" => "User roles", "multiple" => true, "expanded" => true, "roles_with_tags" => ["tag1", "tag2"], // only include roles with either "tag1" or "tag2" ]);
becklyn_static_roles: roles: ROLE_USER_1: title: "User 1" tags: [tag1, tag3] # will be included, as it has at least one of the defined roles ROLE_USER_2: title: "User 2" tags: [tag3, tag4] # will not be included, as it has none of the defined roles
If you don't define any tags in your form, all roles will be included.
$builder ->add("roles", "static_role", [ "label" => "User roles", "multiple" => true, "expanded" => true, "roles_with_tags" => [], // includes all roles ]); // This is also the default value, so you can omit it: $builder ->add("roles", "static_role", [ "label" => "User roles", "multiple" => true, "expanded" => true, ]);
Twig helper functions
staticRoleTitle(key)
Returns the role title by key. Returns null if the role key is not found.
Note
If you are transforming sensitive data, please keep in mind that updating the roles of the user entity won't automatically update the roles of the authenticated user token. You need to refresh this token.
You can fix this issue by adding this configuration in your app/config/security.yml
:
security: always_authenticate_before_granting: true