{"id":23889,"date":"2024-11-21T15:04:14","date_gmt":"2024-11-21T07:04:14","guid":{"rendered":"https:\/\/fwq.ai\/blog\/23889\/"},"modified":"2024-11-21T15:04:14","modified_gmt":"2024-11-21T07:04:14","slug":"yii%e6%a1%86%e6%9e%b6%e4%b8%ad%e7%9a%84rbac%e6%9d%83%e9%99%90%e7%ae%a1%e7%90%86%ef%bc%9a%e6%8e%a7%e5%88%b6%e7%94%a8%e6%88%b7%e8%ae%bf%e9%97%ae%e6%9d%83%e9%99%90","status":"publish","type":"post","link":"https:\/\/fwq.ai\/blog\/23889\/","title":{"rendered":"Yii\u6846\u67b6\u4e2d\u7684RBAC\u6743\u9650\u7ba1\u7406\uff1a\u63a7\u5236\u7528\u6237\u8bbf\u95ee\u6743\u9650"},"content":{"rendered":"<p>\u968f\u7740\u4e92\u8054\u7f51\u7684\u4e0d\u65ad\u53d1\u5c55\uff0c\u8d8a\u6765\u8d8a\u591a\u7684\u7f51\u7ad9\u548c\u5e94\u7528\u7a0b\u5e8f\u9700\u8981\u5b9e\u73b0\u7528\u6237\u6743\u9650\u7684\u7ba1\u7406\u548c\u63a7\u5236\uff0c\u4ee5\u4fdd\u969c\u7f51\u7ad9\u548c\u5e94\u7528\u7a0b\u5e8f\u7684\u5b89\u5168\u6027\u548c\u53ef\u9760\u6027\u3002\u800cyii\u6846\u67b6\u4f5c\u4e3a\u4e00\u4e2a\u6d41\u884c\u7684php\u6846\u67b6\uff0c\u63d0\u4f9b\u4e86\u4e00\u5957\u5b8c\u5584\u7684rbac\uff08role-based access control\uff09\u6743\u9650\u7ba1\u7406\u673a\u5236\uff0c\u7528\u4e8e\u63a7\u5236\u7528\u6237\u5bf9\u7cfb\u7edf\u7684\u8bbf\u95ee\u6743\u9650\u3002\u672c\u6587\u5c06\u4ecb\u7ecdyii\u6846\u67b6\u4e2d\u7684rbac\u6743\u9650\u7ba1\u7406\u673a\u5236\uff0c\u5e76\u4ee5\u4e00\u4e2a\u7b80\u5355\u7684\u5b9e\u4f8b\u6f14\u793a\u5176\u4f7f\u7528\u65b9\u6cd5\u3002<\/p>\n<p>\u4e00\u3001RBAC\u6743\u9650\u7ba1\u7406\u673a\u5236\u7b80\u4ecb<\/p>\n<p>RBAC\u662f\u4e00\u79cd\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u63a7\u5236\u673a\u5236\uff0c\u901a\u8fc7\u5c06\u7528\u6237\u548c\u6743\u9650\u5206\u522b\u5173\u8054\u5230\u89d2\u8272\uff0c\u5728\u89d2\u8272\u6388\u6743\u8fc7\u7a0b\u4e2d\u5b9e\u73b0\u7528\u6237\u548c\u6743\u9650\u4e4b\u95f4\u7684\u89e3\u8026\uff0c\u4ece\u800c\u89e3\u51b3\u4e86\u7528\u6237\u6743\u9650\u53d8\u5316\u65f6\u5e26\u6765\u7684\u7cfb\u7edf\u6027\u80fd\u4f4e\u4e0b\u95ee\u9898\u3002\u5728RBAC\u4e2d\uff0c\u5c06\u6743\u9650\u5212\u5206\u4e3a\u64cd\u4f5c\u3001\u5bf9\u8c61\u548c\u89c4\u5219\u3002\u64cd\u4f5c\u662f\u6307\u5bf9\u6570\u636e\u8fdb\u884c\u7684\u64cd\u4f5c\uff0c\u5982\u521b\u5efa\u3001\u8bfb\u53d6\u3001\u66f4\u65b0\u548c\u5220\u9664\u7b49\uff0c\u5bf9\u8c61\u662f\u6307\u9700\u8981\u88ab\u64cd\u4f5c\u7684\u6570\u636e\uff0c\u5982\u6587\u7ae0\u3001\u8bc4\u8bba\u548c\u7528\u6237\u7b49\uff0c\u89c4\u5219\u662f\u5bf9\u6743\u9650\u7684\u4e00\u4e9b\u9650\u5236\u6761\u4ef6\uff0c\u5982\u662f\u5426\u4e3a\u8be5\u6570\u636e\u7684\u6240\u6709\u8005\u7b49\u3002\u800c\u89d2\u8272\u662f\u7528\u6237\u6743\u9650\u7684\u96c6\u5408\uff0c\u662f\u7531\u591a\u4e2a\u6743\u9650\u7ec4\u6210\u7684\uff0c\u901a\u5e38\u5305\u542b\u4e00\u7ec4\u64cd\u4f5c\u548c\u4e00\u7ec4\u5bf9\u8c61\u6743\u9650\uff0c\u4ee5\u53ca\u4e00\u4e9b\u89c4\u5219\u3002\u5728Yii\u6846\u67b6\u4e2d\uff0cRBAC\u662f\u901a\u8fc7CPhpAuthManager\u6765\u5b9e\u73b0\u7684\u3002<\/p>\n<p>\u4e8c\u3001RBAC\u6743\u9650\u7ba1\u7406\u7684\u57fa\u672c\u64cd\u4f5c<\/p>\n<p>\u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u5c06\u6743\u9650\u548c\u89d2\u8272\u6dfb\u52a0\u5230\u7cfb\u7edf\u4e2d\u3002\u8fd9\u53ef\u4ee5\u901a\u8fc7\u5728Yii\u6846\u67b6\u4e2d\u7684\u6388\u6743\u7ba1\u7406\u5bf9\u8c61CPhpAuthManager\u4e2d\u6dfb\u52a0\u65b0\u6743\u9650\u548c\u89d2\u8272\u6765\u5b9e\u73b0\u3002\u4e0b\u9762\u662f\u4e00\u4e2a\u6dfb\u52a0\u65b0\u6743\u9650\u7684\u793a\u4f8b\u4ee3\u7801\uff1a<\/p>\n<pre>\/\/ \u6dfb\u52a0\u65b0\u6743\u9650\n$auth=Yii::app()-&amp;gt;authManager; \n$auth-&amp;gt;createOperation('createPost','create a new post'); \n$auth-&amp;gt;createOperation('readPost','read a post'); \n$auth-&amp;gt;createOperation('updatePost','update a post'); \n$auth-&amp;gt;createOperation('deletePost','delete a post'); <\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u6dfb\u52a0\u4e86\u56db\u4e2a\u65b0\u7684\u6743\u9650\uff1a\u521b\u5efa\u6587\u7ae0\u3001\u8bfb\u53d6\u6587\u7ae0\u3001\u66f4\u65b0\u6587\u7ae0\u548c\u5220\u9664\u6587\u7ae0\u3002<\/p>\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u9700\u8981\u5b9a\u4e49\u89d2\u8272\uff0c\u5c06\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d\u3002\u4ee5\u4e0b\u4ee3\u7801\u5c55\u793a\u4e86\u5982\u4f55\u5c06\u4e0a\u9762\u7684\u6743\u9650\u6dfb\u52a0\u5230\u4e00\u4e2a\u540d\u4e3a\u201cadmin\u201d\u7684\u89d2\u8272\u4e2d\uff1a<\/p>\n<pre>\/\/ \u6dfb\u52a0\u4e00\u4e2a\u65b0\u89d2\u8272\uff0c\u5c06\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d\n$auth=Yii::app()-&amp;gt;authManager; \n$role=$auth-&amp;gt;createRole('admin'); \n$role-&amp;gt;addChild('createPost'); \n$role-&amp;gt;addChild('readPost'); \n$role-&amp;gt;addChild('updatePost'); \n$role-&amp;gt;addChild('deletePost'); <\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u5b9a\u4e49\u4e86\u4e00\u4e2a\u540d\u4e3a\u201cadmin\u201d\u7684\u89d2\u8272\uff0c\u5e76\u5c06\u4e0a\u8ff0\u56db\u4e2a\u6743\u9650\u6dfb\u52a0\u5230\u8be5\u89d2\u8272\u4e2d\u3002<\/p>\n<p>\u6700\u540e\uff0c\u5728\u5904\u7406\u7528\u6237\u7684\u8bbf\u95ee\u8bf7\u6c42\u65f6\uff0c\u6211\u4eec\u9700\u8981\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709\u76f8\u5e94\u7684\u6743\u9650\u3002\u4ee5\u4e0b\u4ee3\u7801\u6f14\u793a\u4e86\u5982\u4f55\u68c0\u67e5\u4e00\u4e2a\u7528\u6237\u662f\u5426\u5177\u6709\u201ccreatePost\u201d\u6743\u9650\uff1a<\/p>\n<pre>\/\/\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709createPost\u6743\u9650\n$auth=Yii::app()-&amp;gt;authManager; \nif($auth-&amp;gt;checkAccess('createPost',$userId))\n{\n    \/\/ \u7528\u6237\u5177\u6709\u6743\u9650\uff0c\u8fdb\u884c\u64cd\u4f5c\n}\nelse\n{\n    \/\/ \u7528\u6237\u4e0d\u5177\u6709\u6743\u9650\uff0c\u8fd4\u56de\u9519\u8bef\n}<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u9996\u5148\u83b7\u53d6\u4e86\u6388\u6743\u7ba1\u7406\u5bf9\u8c61$auth\uff0c\u7136\u540e\u8c03\u7528\u5176checkAccess\u65b9\u6cd5\u6765\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709createPost\u6743\u9650\u3002\u82e5\u7528\u6237\u5177\u6709\u8be5\u6743\u9650\uff0c\u5219\u53ef\u4ee5\u6267\u884c\u76f8\u5e94\u7684\u64cd\u4f5c\uff0c\u5426\u5219\u9700\u8981\u8fd4\u56de\u9519\u8bef\u4fe1\u606f\u3002<\/p>\n<p>\u4e09\u3001RBAC\u6743\u9650\u7ba1\u7406\u793a\u4f8b<\/p>\n<p>\u5047\u8bbe\u6211\u4eec\u6709\u4e00\u4e2a\u535a\u5ba2\u7f51\u7ad9\uff0c\u7f51\u7ad9\u5305\u542b\u6587\u7ae0\u3001\u8bc4\u8bba\u548c\u7528\u6237\u4e09\u4e2a\u57fa\u672c\u5b9e\u4f53\uff0c\u9700\u8981\u63a7\u5236\u7528\u6237\u5bf9\u8fd9\u4e09\u4e2a\u5b9e\u4f53\u7684\u8bbf\u95ee\u6743\u9650\u3002\u5728\u672c\u793a\u4f8b\u4e2d\uff0c\u6211\u4eec\u5c06\u5b9a\u4e49\u4e24\u4e2a\u57fa\u672c\u89d2\u8272\uff1a\u7ba1\u7406\u5458\u548c\u666e\u901a\u7528\u6237\u3002\u7ba1\u7406\u5458\u5177\u6709\u5bf9\u6240\u6709\u5b9e\u4f53\u7684\u521b\u5efa\u3001\u8bfb\u53d6\u3001\u66f4\u65b0\u548c\u5220\u9664\u6743\u9650\uff0c\u800c\u666e\u901a\u7528\u6237\u4ec5\u5177\u6709\u5bf9\u6587\u7ae0\u548c\u8bc4\u8bba\u7684\u8bfb\u53d6\u6743\u9650\u3002<\/p>\n<p>\u9996\u5148\uff0c\u5728Yii\u6846\u67b6\u7684\u914d\u7f6e\u6587\u4ef6\u4e2d\u914d\u7f6eRBAC\u6743\u9650\u7ba1\u7406\u7ec4\u4ef6\uff1a<\/p>\n<pre>'authManager'=&amp;gt;array(\n    'class' =&amp;gt; 'CDbAuthManager',\n    'connectionID' =&amp;gt; 'db',\n    'itemTable' =&amp;gt; '{{authitem}}',\n    'assignmentTable' =&amp;gt; '{{authassignment}}',\n    'itemChildTable' =&amp;gt; '{{authitemchild}}',\n),<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u7136\u540e\uff0c\u5728\u6211\u4eec\u7684\u63a7\u5236\u5668\u4e2d\uff0c\u6dfb\u52a0\u4e0b\u5217\u4ee3\u7801\u4ee5\u6dfb\u52a0\u65b0\u6743\u9650\u548c\u89d2\u8272\uff1a<\/p>\n<pre>$auth = Yii::app()-&amp;gt;authManager;\n\n\/\/ \u6dfb\u52a0\u65b0\u6743\u9650\n$auth-&amp;gt;createOperation('createArticle', 'create a new article');\n$auth-&amp;gt;createOperation('readArticle', 'read an article');\n$auth-&amp;gt;createOperation('updateArticle', 'update an article');\n$auth-&amp;gt;createOperation('deleteArticle', 'delete an article');\n$auth-&amp;gt;createOperation('createComment', 'create a new comment');\n$auth-&amp;gt;createOperation('readComment', 'read a comment');\n$auth-&amp;gt;createOperation('updateComment', 'update a comment');\n$auth-&amp;gt;createOperation('deleteComment', 'delete a comment');\n\n\/\/ \u6dfb\u52a0\u65b0\u89d2\u8272\n$roleAdmin = $auth-&amp;gt;createRole('admin');\n$roleAdmin-&amp;gt;addChild('createArticle');\n$roleAdmin-&amp;gt;addChild('readArticle');\n$roleAdmin-&amp;gt;addChild('updateArticle');\n$roleAdmin-&amp;gt;addChild('deleteArticle');\n$roleAdmin-&amp;gt;addChild('createComment');\n$roleAdmin-&amp;gt;addChild('readComment');\n$roleAdmin-&amp;gt;addChild('updateComment');\n$roleAdmin-&amp;gt;addChild('deleteComment');\n\n$roleUser = $auth-&amp;gt;createRole('user');\n$roleUser-&amp;gt;addChild('readArticle');\n$roleUser-&amp;gt;addChild('readComment');\n\n\/\/ \u5c06\u89d2\u8272\u5206\u914d\u7ed9\u7528\u6237\n$auth-&amp;gt;assign('admin', 1);\n$auth-&amp;gt;assign('user', 2);<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u9996\u5148\u521b\u5efa\u4e86\u516b\u4e2a\u65b0\u6743\u9650\uff0c\u5206\u522b\u7528\u4e8e\u63a7\u5236\u6587\u7ae0\u548c\u8bc4\u8bba\u7684CRUD\u64cd\u4f5c\u3002\u7136\u540e\uff0c\u6211\u4eec\u5b9a\u4e49\u4e86\u4e24\u4e2a\u65b0\u89d2\u8272\uff1aadmin\u548cuser\uff0c\u5c06\u76f8\u5e94\u7684\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d\u3002\u6700\u540e\uff0c\u6211\u4eec\u5c06admin\u89d2\u8272\u5206\u914d\u7ed9\u7528\u62371\uff0c\u5c06user\u89d2\u8272\u5206\u914d\u7ed9\u7528\u62372\u3002<\/p>\n<p>\u63a5\u4e0b\u6765\uff0c\u5728\u63a7\u5236\u5668\u4e2d\uff0c\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u8c03\u7528checkAccess\u65b9\u6cd5\u6765\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709\u76f8\u5e94\u7684\u6743\u9650\uff0c\u5e76\u6267\u884c\u76f8\u5e94\u7684\u64cd\u4f5c\uff0c\u5982\u4e0b\u5217\u4ee3\u7801\u6240\u793a\uff1a<\/p>\n<pre>if(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('createArticle'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u521b\u5efa\u6587\u7ae0\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('readArticle'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u8bfb\u53d6\u6587\u7ae0\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('updateArticle'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u66f4\u65b0\u6587\u7ae0\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('deleteArticle'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u5220\u9664\u6587\u7ae0\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('createComment'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u521b\u5efa\u8bc4\u8bba\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('readComment'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u8bfb\u53d6\u8bc4\u8bba\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('updateComment'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u66f4\u65b0\u8bc4\u8bba\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}\n\nif(Yii::app()-&amp;gt;user-&amp;gt;checkAccess('deleteComment'))\n{\n    \/\/ \u5f53\u524d\u7528\u6237\u5177\u6709\u5220\u9664\u8bc4\u8bba\u6743\u9650\uff0c\u8fdb\u884c\u76f8\u5e94\u64cd\u4f5c\n}<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u901a\u8fc7\u8c03\u7528checkAccess\u65b9\u6cd5\u6765\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709\u76f8\u5e94\u7684\u6743\u9650\uff0c\u5e76\u5728\u5177\u6709\u76f8\u5e94\u6743\u9650\u65f6\u6267\u884c\u76f8\u5e94\u7684\u64cd\u4f5c\u3002\u4f8b\u5982\uff0c\u5728\u7528\u6237\u5177\u6709\u521b\u5efa\u6587\u7ae0\u6743\u9650\u65f6\uff0c\u6211\u4eec\u53ef\u4ee5\u6267\u884c\u76f8\u5e94\u7684\u521b\u5efa\u6587\u7ae0\u64cd\u4f5c\u3002<\/p>\n<p>\u56db\u3001\u7ed3\u8bba<\/p>\n<p>\u901a\u8fc7\u672c\u6587\u7684\u4ecb\u7ecd\uff0c\u6211\u4eec\u53ef\u4ee5\u770b\u5230\uff0cYii\u6846\u67b6\u63d0\u4f9b\u4e86\u4e00\u5957\u5b8c\u5584\u7684RBAC\u6743\u9650\u7ba1\u7406\u673a\u5236\uff0c\u7528\u4e8e\u63a7\u5236\u7528\u6237\u5bf9\u7cfb\u7edf\u7684\u8bbf\u95ee\u6743\u9650\u3002\u901a\u8fc7\u5b9a\u4e49\u89d2\u8272\uff0c\u5e76\u5c06\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d\uff0c\u6211\u4eec\u53ef\u4ee5\u5f88\u5bb9\u6613\u5730\u63a7\u5236\u7528\u6237\u5bf9\u7cfb\u7edf\u4e2d\u5404\u5b9e\u4f53\u7684\u8bbf\u95ee\u6743\u9650\u3002\u5f53\u7136\uff0c\u9664\u4e86RBAC\u6743\u9650\u7ba1\u7406\u673a\u5236\u4e4b\u5916\uff0cYii\u6846\u67b6\u8fd8\u63d0\u4f9b\u4e86\u8bb8\u591a\u5176\u5b83\u7684\u5b89\u5168\u7279\u6027\uff0c\u5982\u5bc6\u7801\u52a0\u5bc6\u3001\u9632\u6b62\u8de8\u7ad9\u70b9\u8bf7\u6c42\u4f2a\u9020\u7b49\uff0c\u5f00\u53d1\u4eba\u5458\u53ef\u4ee5\u6839\u636e\u5b9e\u9645\u60c5\u51b5\u9009\u62e9\u4f7f\u7528\u3002<\/p>\n<p>\u4ee5\u4e0a\u5c31\u662fYii\u6846\u67b6\u4e2d\u7684RBAC\u6743\u9650\u7ba1\u7406\uff1a\u63a7\u5236\u7528\u6237\u8bbf\u95ee\u6743\u9650\u7684\u8be6\u7ec6\u5185\u5bb9\uff0c\u66f4\u591a\u8bf7\u5173\u6ce8\u7c73\u4e91\u5176\u5b83\u76f8\u5173\u6587\u7ae0\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u968f\u7740\u4e92\u8054\u7f51\u7684\u4e0d\u65ad\u53d1\u5c55\uff0c\u8d8a\u6765\u8d8a\u591a\u7684\u7f51\u7ad9\u548c\u5e94\u7528\u7a0b\u5e8f\u9700\u8981\u5b9e\u73b0\u7528\u6237\u6743\u9650\u7684\u7ba1\u7406\u548c\u63a7\u5236\uff0c\u4ee5\u4fdd\u969c\u7f51\u7ad9\u548c\u5e94\u7528\u7a0b\u5e8f\u7684\u5b89\u5168\u6027\u548c\u53ef\u9760\u6027\u3002\u800cyii\u6846\u67b6\u4f5c\u4e3a\u4e00\u4e2a\u6d41\u884c\u7684php\u6846\u67b6\uff0c\u63d0\u4f9b\u4e86\u4e00\u5957\u5b8c\u5584\u7684rbac\uff08role-based access control\uff09\u6743\u9650\u7ba1\u7406\u673a\u5236\uff0c\u7528\u4e8e\u63a7\u5236\u7528\u6237\u5bf9\u7cfb\u7edf\u7684\u8bbf\u95ee\u6743\u9650\u3002\u672c\u6587\u5c06\u4ecb\u7ecdyii\u6846\u67b6\u4e2d\u7684rbac\u6743\u9650\u7ba1\u7406\u673a\u5236\uff0c\u5e76\u4ee5\u4e00\u4e2a\u7b80\u5355\u7684\u5b9e\u4f8b\u6f14\u793a\u5176\u4f7f\u7528\u65b9\u6cd5\u3002 \u4e00\u3001RBAC\u6743\u9650\u7ba1\u7406\u673a\u5236\u7b80\u4ecb RBAC\u662f\u4e00\u79cd\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u63a7\u5236\u673a\u5236\uff0c\u901a\u8fc7\u5c06\u7528\u6237\u548c\u6743\u9650\u5206\u522b\u5173\u8054\u5230\u89d2\u8272\uff0c\u5728\u89d2\u8272\u6388\u6743\u8fc7\u7a0b\u4e2d\u5b9e\u73b0\u7528\u6237\u548c\u6743\u9650\u4e4b\u95f4\u7684\u89e3\u8026\uff0c\u4ece\u800c\u89e3\u51b3\u4e86\u7528\u6237\u6743\u9650\u53d8\u5316\u65f6\u5e26\u6765\u7684\u7cfb\u7edf\u6027\u80fd\u4f4e\u4e0b\u95ee\u9898\u3002\u5728RBAC\u4e2d\uff0c\u5c06\u6743\u9650\u5212\u5206\u4e3a\u64cd\u4f5c\u3001\u5bf9\u8c61\u548c\u89c4\u5219\u3002\u64cd\u4f5c\u662f\u6307\u5bf9\u6570\u636e\u8fdb\u884c\u7684\u64cd\u4f5c\uff0c\u5982\u521b\u5efa\u3001\u8bfb\u53d6\u3001\u66f4\u65b0\u548c\u5220\u9664\u7b49\uff0c\u5bf9\u8c61\u662f\u6307\u9700\u8981\u88ab\u64cd\u4f5c\u7684\u6570\u636e\uff0c\u5982\u6587\u7ae0\u3001\u8bc4\u8bba\u548c\u7528\u6237\u7b49\uff0c\u89c4\u5219\u662f\u5bf9\u6743\u9650\u7684\u4e00\u4e9b\u9650\u5236\u6761\u4ef6\uff0c\u5982\u662f\u5426\u4e3a\u8be5\u6570\u636e\u7684\u6240\u6709\u8005\u7b49\u3002\u800c\u89d2\u8272\u662f\u7528\u6237\u6743\u9650\u7684\u96c6\u5408\uff0c\u662f\u7531\u591a\u4e2a\u6743\u9650\u7ec4\u6210\u7684\uff0c\u901a\u5e38\u5305\u542b\u4e00\u7ec4\u64cd\u4f5c\u548c\u4e00\u7ec4\u5bf9\u8c61\u6743\u9650\uff0c\u4ee5\u53ca\u4e00\u4e9b\u89c4\u5219\u3002\u5728Yii\u6846\u67b6\u4e2d\uff0cRBAC\u662f\u901a\u8fc7CPhpAuthManager\u6765\u5b9e\u73b0\u7684\u3002 \u4e8c\u3001RBAC\u6743\u9650\u7ba1\u7406\u7684\u57fa\u672c\u64cd\u4f5c \u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u5c06\u6743\u9650\u548c\u89d2\u8272\u6dfb\u52a0\u5230\u7cfb\u7edf\u4e2d\u3002\u8fd9\u53ef\u4ee5\u901a\u8fc7\u5728Yii\u6846\u67b6\u4e2d\u7684\u6388\u6743\u7ba1\u7406\u5bf9\u8c61CPhpAuthManager\u4e2d\u6dfb\u52a0\u65b0\u6743\u9650\u548c\u89d2\u8272\u6765\u5b9e\u73b0\u3002\u4e0b\u9762\u662f\u4e00\u4e2a\u6dfb\u52a0\u65b0\u6743\u9650\u7684\u793a\u4f8b\u4ee3\u7801\uff1a \/\/ \u6dfb\u52a0\u65b0\u6743\u9650 $auth=Yii::app()-&amp;gt;authManager; $auth-&amp;gt;createOperation(&#8216;createPost&#8217;,&#8217;create a new post&#8217;); $auth-&amp;gt;createOperation(&#8216;readPost&#8217;,&#8217;read a post&#8217;); $auth-&amp;gt;createOperation(&#8216;updatePost&#8217;,&#8217;update a post&#8217;); $auth-&amp;gt;createOperation(&#8216;deletePost&#8217;,&#8217;delete a post&#8217;); \u767b\u5f55\u540e\u590d\u5236 \u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u6dfb\u52a0\u4e86\u56db\u4e2a\u65b0\u7684\u6743\u9650\uff1a\u521b\u5efa\u6587\u7ae0\u3001\u8bfb\u53d6\u6587\u7ae0\u3001\u66f4\u65b0\u6587\u7ae0\u548c\u5220\u9664\u6587\u7ae0\u3002 \u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u9700\u8981\u5b9a\u4e49\u89d2\u8272\uff0c\u5c06\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d\u3002\u4ee5\u4e0b\u4ee3\u7801\u5c55\u793a\u4e86\u5982\u4f55\u5c06\u4e0a\u9762\u7684\u6743\u9650\u6dfb\u52a0\u5230\u4e00\u4e2a\u540d\u4e3a\u201cadmin\u201d\u7684\u89d2\u8272\u4e2d\uff1a \/\/ \u6dfb\u52a0\u4e00\u4e2a\u65b0\u89d2\u8272\uff0c\u5c06\u6743\u9650\u6dfb\u52a0\u5230\u89d2\u8272\u4e2d $auth=Yii::app()-&amp;gt;authManager; $role=$auth-&amp;gt;createRole(&#8216;admin&#8217;); $role-&amp;gt;addChild(&#8216;createPost&#8217;); $role-&amp;gt;addChild(&#8216;readPost&#8217;); $role-&amp;gt;addChild(&#8216;updatePost&#8217;); $role-&amp;gt;addChild(&#8216;deletePost&#8217;); \u767b\u5f55\u540e\u590d\u5236 \u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u5b9a\u4e49\u4e86\u4e00\u4e2a\u540d\u4e3a\u201cadmin\u201d\u7684\u89d2\u8272\uff0c\u5e76\u5c06\u4e0a\u8ff0\u56db\u4e2a\u6743\u9650\u6dfb\u52a0\u5230\u8be5\u89d2\u8272\u4e2d\u3002 \u6700\u540e\uff0c\u5728\u5904\u7406\u7528\u6237\u7684\u8bbf\u95ee\u8bf7\u6c42\u65f6\uff0c\u6211\u4eec\u9700\u8981\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709\u76f8\u5e94\u7684\u6743\u9650\u3002\u4ee5\u4e0b\u4ee3\u7801\u6f14\u793a\u4e86\u5982\u4f55\u68c0\u67e5\u4e00\u4e2a\u7528\u6237\u662f\u5426\u5177\u6709\u201ccreatePost\u201d\u6743\u9650\uff1a \/\/\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709createPost\u6743\u9650 $auth=Yii::app()-&amp;gt;authManager; if($auth-&amp;gt;checkAccess(&#8216;createPost&#8217;,$userId)) { \/\/ \u7528\u6237\u5177\u6709\u6743\u9650\uff0c\u8fdb\u884c\u64cd\u4f5c } else { \/\/ \u7528\u6237\u4e0d\u5177\u6709\u6743\u9650\uff0c\u8fd4\u56de\u9519\u8bef } \u767b\u5f55\u540e\u590d\u5236 \u4ee5\u4e0a\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u9996\u5148\u83b7\u53d6\u4e86\u6388\u6743\u7ba1\u7406\u5bf9\u8c61$auth\uff0c\u7136\u540e\u8c03\u7528\u5176checkAccess\u65b9\u6cd5\u6765\u68c0\u67e5\u7528\u6237\u662f\u5426\u5177\u6709createPost\u6743\u9650\u3002\u82e5\u7528\u6237\u5177\u6709\u8be5\u6743\u9650\uff0c\u5219\u53ef\u4ee5\u6267\u884c\u76f8\u5e94\u7684\u64cd\u4f5c\uff0c\u5426\u5219\u9700\u8981\u8fd4\u56de\u9519\u8bef\u4fe1\u606f\u3002 \u4e09\u3001RBAC\u6743\u9650\u7ba1\u7406\u793a\u4f8b \u5047\u8bbe\u6211\u4eec\u6709\u4e00\u4e2a\u535a\u5ba2\u7f51\u7ad9\uff0c\u7f51\u7ad9\u5305\u542b\u6587\u7ae0\u3001\u8bc4\u8bba\u548c\u7528\u6237\u4e09\u4e2a\u57fa\u672c\u5b9e\u4f53\uff0c\u9700\u8981\u63a7\u5236\u7528\u6237\u5bf9\u8fd9\u4e09\u4e2a\u5b9e\u4f53\u7684\u8bbf\u95ee\u6743\u9650\u3002\u5728\u672c\u793a\u4f8b\u4e2d\uff0c\u6211\u4eec\u5c06\u5b9a\u4e49\u4e24\u4e2a\u57fa\u672c\u89d2\u8272\uff1a\u7ba1\u7406\u5458\u548c\u666e\u901a\u7528\u6237\u3002\u7ba1\u7406\u5458\u5177\u6709\u5bf9\u6240\u6709\u5b9e\u4f53\u7684\u521b\u5efa\u3001\u8bfb\u53d6\u3001\u66f4\u65b0\u548c\u5220\u9664\u6743\u9650\uff0c\u800c\u666e\u901a\u7528\u6237\u4ec5\u5177\u6709\u5bf9\u6587\u7ae0\u548c\u8bc4\u8bba\u7684\u8bfb\u53d6\u6743\u9650\u3002 \u9996\u5148\uff0c\u5728Yii\u6846\u67b6\u7684\u914d\u7f6e\u6587\u4ef6\u4e2d\u914d\u7f6eRBAC\u6743\u9650\u7ba1\u7406\u7ec4\u4ef6\uff1a &#8216;authManager&#8217;=&amp;gt;array( [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[],"class_list":["post-23889","post","type-post","status-publish","format-standard","hentry","category-16"],"_links":{"self":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/23889","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/comments?post=23889"}],"version-history":[{"count":0,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/23889\/revisions"}],"wp:attachment":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/media?parent=23889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/categories?post=23889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/tags?post=23889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}