Skip to content

Commit f3630d8

Browse files
committed
Add AuthorizationComponent::skipAuthorizationActions()
The `skipAuthorization` config key already marks controller actions as public, but unlike `authorizeModel()` and `mapAction()` it has no fluent setter, so it can only be set through `loadComponent()` options or `setConfig()`. Add a variadic setter that merges into the existing config, matching the `authorizeModel(string ...$actions)` signature. `authorizeAction()` runs on `Controller.startup`, which dispatches after `Controller.initialize`, so registering actions from `beforeFilter()` takes effect.
1 parent ee0fbc4 commit f3630d8

3 files changed

Lines changed: 40 additions & 0 deletions

File tree

‎docs/en/component.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,12 @@ $this->loadComponent('Authorization.Authorization', [
3434
]);
3535
```
3636

37+
The same can be done at runtime, for example in `beforeFilter()`:
38+
39+
```php
40+
$this->Authorization->skipAuthorizationActions('login', 'logout');
41+
```
42+
3743
By default, every action requires authorization when authorization checking is
3844
enabled.
3945

‎src/Controller/Component/AuthorizationComponent.php‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -178,6 +178,22 @@ public function skipAuthorization()
178178
return $this;
179179
}
180180

181+
/**
182+
* Adds actions that should skip the automatic authorization check.
183+
*
184+
* Actions registered here are marked as authorized in `authorizeAction()`,
185+
* which runs on the configured `authorizationEvent`.
186+
*
187+
* @param string ...$actions Controller actions to skip authorization for.
188+
* @return $this
189+
*/
190+
public function skipAuthorizationActions(string ...$actions)
191+
{
192+
$this->_config['skipAuthorization'] = array_merge($this->_config['skipAuthorization'], $actions);
193+
194+
return $this;
195+
}
196+
181197
/**
182198
* Allows to map controller action to another authorization policy action.
183199
*

‎tests/TestCase/Controller/Component/AuthorizationComponentTest.php‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -550,6 +550,24 @@ public function testAuthorizeModel(): void
550550
$this->assertEquals(['foo', 'bar', 'baz'], $this->Auth->getConfig('authorizeModel'));
551551
}
552552

553+
public function testSkipAuthorizationActions(): void
554+
{
555+
$this->Auth->skipAuthorizationActions('foo', 'bar');
556+
$this->assertEquals(['foo', 'bar'], $this->Auth->getConfig('skipAuthorization'));
557+
558+
$this->Auth->skipAuthorizationActions('baz');
559+
$this->assertEquals(['foo', 'bar', 'baz'], $this->Auth->getConfig('skipAuthorization'));
560+
}
561+
562+
public function testSkipAuthorizationActionsAppliedOnAuthorizeAction(): void
563+
{
564+
$service = $this->Controller->getRequest()->getAttribute('authorization');
565+
566+
$this->Auth->skipAuthorizationActions('edit');
567+
$this->Auth->authorizeAction();
568+
$this->assertTrue($service->authorizationChecked());
569+
}
570+
553571
public function testMapAction(): void
554572
{
555573
$this->Auth->mapAction('foo', 'bar');

0 commit comments

Comments
 (0)