如何将定义的权限分配给 Spatie/Laravel-permission 中正确的策略和控制器方法?
这似乎是一个简单的问题,但是我在Laravel策略文档或Spatie/Laravel-permission文档中都找不到解决方案。
这是问题:
这就是我将权限分配给prisemenceSeeder.php中某些角色的方式:
public function run()
{
// Reset cached roles and permissions
app()[PermissionRegistrar::class]->forgetCachedPermissions();
// create permissions
Permission::create(['name' => 'view own tickets']);
Permission::create(['name' => 'view all tickets']);
Permission::create(['name' => 'forward a ticket']);
Permission::create(['name' => 'close a ticket']);
Permission::create(['name' => 'write a ticket']);
Permission::create(['name' => 'assign permissions to roles']);
Permission::create(['name' => 'hide a ticket']);
// create roles and assign existing permissions
$role1 = Role::create(['name' => 'staff']);
$role1->givePermissionTo('view own tickets');
$role1->givePermissionTo('forward a ticket');
$role1->givePermissionTo('close a ticket');
$role1->givePermissionTo('write a ticket');
$role2 = Role::create(['name' => 'admin']);
$role2->givePermissionTo('view own tickets');
$role2->givePermissionTo('forward a ticket');
$role2->givePermissionTo('close a ticket');
$role2->givePermissionTo('write a ticket');
$role2->givePermissionTo('hide a ticket');
$role2->givePermissionTo('view all tickets');
$role3 = Role::create(['name' => 'Super-Admin']);
}
现在让我给您一个示例,说明如何转发方法的控制器方法外观:
class TicketController extends Controller
{
/**
* forward a ticket to another user.
*
* @param Request $request
* @return Response
*/
public function forwardTo(Request $request)
{
$ticket = TicketTitle::find($request->ticket_id);
$ticket->forwarded_to = $request->user_id;
$ticket->status = TicketTitle::STATUS_FORWARDED;
$ticket->save();
return \response($ticket, 200);
}
}
有必要首先验证用户有权限以转发票证在执行此方法之前...您能解释一下如何执行此操作吗?
如果我必须定义一个策略,鉴于我的方法的名称和我的允许,该策略应称为什么?
我还检查了类似的问题,但是它们都没有我想要的答案。
This may seem a simple problem, but I could not find a solution either in Laravel policy documentation or in Spatie/Laravel-permission documentation.
Here is the problem:
This is how I've assigned permissions to certain roles in PermissionSeeder.php:
public function run()
{
// Reset cached roles and permissions
app()[PermissionRegistrar::class]->forgetCachedPermissions();
// create permissions
Permission::create(['name' => 'view own tickets']);
Permission::create(['name' => 'view all tickets']);
Permission::create(['name' => 'forward a ticket']);
Permission::create(['name' => 'close a ticket']);
Permission::create(['name' => 'write a ticket']);
Permission::create(['name' => 'assign permissions to roles']);
Permission::create(['name' => 'hide a ticket']);
// create roles and assign existing permissions
$role1 = Role::create(['name' => 'staff']);
$role1->givePermissionTo('view own tickets');
$role1->givePermissionTo('forward a ticket');
$role1->givePermissionTo('close a ticket');
$role1->givePermissionTo('write a ticket');
$role2 = Role::create(['name' => 'admin']);
$role2->givePermissionTo('view own tickets');
$role2->givePermissionTo('forward a ticket');
$role2->givePermissionTo('close a ticket');
$role2->givePermissionTo('write a ticket');
$role2->givePermissionTo('hide a ticket');
$role2->givePermissionTo('view all tickets');
$role3 = Role::create(['name' => 'Super-Admin']);
}
Now let me give you an example of how my controller method for forwarding a method looks:
class TicketController extends Controller
{
/**
* forward a ticket to another user.
*
* @param Request $request
* @return Response
*/
public function forwardTo(Request $request)
{
$ticket = TicketTitle::find($request->ticket_id);
$ticket->forwarded_to = $request->user_id;
$ticket->status = TicketTitle::STATUS_FORWARDED;
$ticket->save();
return \response($ticket, 200);
}
}
It is necessary to first verify that the user has the permission to forward a ticket before executing this method... Could you please explain how to do this?
If I have to define a policy, given the name of my method and my permission, what should the policy be called?
I also checked similar questions, but none of them had the answer I was looking for.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
尝试这个。提交更多问题
try this one.commit for further issues
您可以从方法:有权使用如下:
You can from method: has Permission To Use as follows: