I have 3 user roles
ROLE_STAFF
ROLE_ADMIN
ROLE_CUSTOMER
I want to implement following rule for my admin dashboard.
Allow user with role ROLE_ADMIN all access
Do not allow access to user with role ROLE_CUSTOMER to any url starting with /admin
Allow not logged in user to access url starting with /account
Allow user with role ROLE_STAFF to access url starting with /admin/business/*
For the above rule, I have implemented following rule in access_control
access_control:
- { path: ^/account, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/admin/business, role: ROLE_STAFF }
- { path: ^/admin/dashboard, role: ROLE_STAFF }
- { path: ^/admin, role: ROLE_ADMIN }
This is not working as expected, the problem is, when I am logged in with ROLE_STAFF it works but when I login with ROLE_ADMIN it throws access denied error.
What could be possible issue here?
Thanks.
Related
I'm using FOSUser and I would like to return an exception or simply block access to registration if user is already connected. When I'm connected, by url, I can still go to /register.
This is my access_control :
access_control:
- { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
I could override registration controller action and return an AccessDeniedException but I'm sure there is a better solution, with security.yml maybe ?
if you add this:
- { path: ^/register, role: ROLE_ADMIN }
then use:
php bin/console fos:user:promote user_name ROLE_ADMIN
to add "user_name" to the ROLE_ADMIN, then other users will get an Access Denied message.
I finally found the answer. I have to use Voters to check user permissions.
This is doc : http://symfony.com/doc/current/cookbook/security/voters.html
And there is great example here : http://henrik.bjrnskov.dk/symfony2-anonymous-users-access/
And this is what I have :
- { path: ^/register, role: IS_ANONYMOUS }
I want to allow access to users with ROLE_ADMIN to the following path:
/admin
And only allow access to users with ROLE_CONTENT or ROLE_ADMIN to the following path:
/admin?select=pending
Here is my access control config in security.yml:
access_control:
- { path: ^/admin?select=pending, role: [ ROLE_ADMIN, ROLE_CONTENT ] }
- { path: ^/admin, role: ROLE_ADMIN }
However if I try to access to the query string path with a user with ROLE_CONTENT it gives me a 403 access denied error message.
Any suggestions on how to achieve this?
I have made two different login section in my website, one for admin section and another for frontend users.
When I logged into to frontend it logged in. The problem is that when i try to login the admin section it throws access denied error.
Is it possible make two different login sessions so that both login session are independent of eachother
you don't show security.yml, so no way to know for sure:
try deleting this row:
- { path: ^/, roles: IS_AUTHENTICATED_ANONYMOUSLY }
but most likely you have something like this in your security.yml
access_control:
- { path: ^/login$, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/admin/, role: ROLE_ADMIN }
- { path: ^/, role: ROLE_USER }
and your login page is on url /admin/login/
so it requires ROLE_ADMIN to access login page, before you can login as admin
I've noticed that FOSUserBundle's default access_control configuration is
- { path: ^/login$, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
- { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }
But when I try to set these roles to
IS_AUTHENTICATED_ANONYMOUSLY && !IS_AUTHENTICATED_FULLY
it gives me endless loops to /login. How can I make only these three rules to be forbidden for fully authenticated users?
You should not deny access for the login page when the user is logged in, because a 403 forbidden will redirect automatically to login page because it request the user to login.
Better you write a service that checks every request. When it matches login request you need to check if the user is authenticated and redirect him to index page instead to the requested login page.
I have a problem with the firewall thing in Symfony2.
I have these in my security.yml file
- { path: ^/, role: ROLE_USER }
- { path: ^/admin, role: ROLE_ADMIN }
- { path: ^/users, role: ROLE_ADMIN }
In my menu builder im using isGranted and this works perfect, if I login with my ROLE_USER user, the menu does not build the admin menu.
But if I manually type /admin in the browser I get the admin pages. (this happens both in production and dev envoirenment)
In the toolbar in dev env I can see the user dont have the ROLE_ADMIN role
If I dont login at all, I only see the login page, so here is everything fine
Full security.yml: https://gist.github.com/lsv/2e9dce622fd82d31853c
Full config.yml: https://gist.github.com/lsv/ec87592f911262af5417
Im using FOSUserbundle
Entries in access_control should be in the order from more specific to more general. So, in your case, they should be in the following order:
- { path: ^/admin, roles: ROLE_ADMIN }
- { path: ^/, roles: ROLE_USER }