{"id":305978,"date":"2020-06-26T15:00:51","date_gmt":"2020-06-26T15:00:51","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=305978"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=305978","title":{"rendered":"\u041f\u0440\u043e\u0441\u0442\u043e\u0435 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 ACL \u0432 Symfony"},"content":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/508424\/\"><b><i>\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0432 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043a\u0443\u0440\u0441\u0430 <a href=\"https:\/\/otus.pw\/y4dU\/\">\u00abSymfony Framework\u00bb<\/a>.<\/i><\/b><\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/zq\/nb\/ca\/zqnbcatp2nq5swvptivkqozhb4y.png\">  <\/p>\n<hr>\n<p>  \u041d\u0435 \u0441\u0435\u043a\u0440\u0435\u0442, \u0447\u0442\u043e ACL (access control lists) \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0441\u043b\u043e\u0436\u043d\u044b \u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438. \u041f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 Symfony \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u0435\u0442 <a href=\"https:\/\/symfony.com\/doc\/current\/security\/voters.html?ref=hackernoon.com\">\u0438\u0437\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u0435\u0439<\/a> (voters) \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u044b ACL, \u044f \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0440\u0435\u0448\u0438\u043b, \u0447\u0442\u043e \u043d\u0430\u043f\u0438\u0448\u0443 \u0441\u0432\u043e\u0439 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0439 \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 Symfony 5 \u0431\u0430\u043d\u0434\u043b \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u043f\u0438\u0441\u043a\u0430\u043c\u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 (ACL) \u0432 \u043c\u043e\u0438\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445.<\/p>\n<p>  <code>programarivm\/easy-acl-bundle<\/code> \u0438\u0437\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e \u0431\u044b\u043b \u043d\u0430\u043f\u0438\u0441\u0430\u043d \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0432 JWT-\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c API \u0434\u043b\u044f \u043e\u0434\u043d\u043e\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (single page applications \u2014 SPA), \u043d\u043e \u043e\u043d \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u0435\u043d \u0432 \u0440\u044f\u0434\u0435 \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0435\u0432, \u043a\u043e\u0433\u0434\u0430 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f Security \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442 \u2014 \u0447\u0442\u043e \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 \u0441\u043b\u0443\u0447\u0430\u0435\u0432, \u043f\u043e \u043c\u043e\u0435\u043c\u0443 \u0441\u043a\u0440\u043e\u043c\u043d\u043e\u043c\u0443 \u043c\u043d\u0435\u043d\u0438\u044e, \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442 \u0434\u043b\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043c\u043d\u043e\u0433\u043e\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (multi-page applications \u2014 MPA).<a name=\"habracut\"><\/a>  <\/p>\n<blockquote><p><code>EasyAclBundle<\/code>.<\/p>\n<p>  <i>\u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u043e\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0443\u0449\u043d\u043e\u0441\u0442\u0438 \u0438 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 Doctrine, \u0447\u0442\u043e \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442, \u0447\u0442\u043e \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0441\u0442\u043e \u0445\u0440\u0430\u043d\u044f\u0442\u0441\u044f \u0432 \u0431\u0430\u0437\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u0431\u0435\u0437 \u043f\u0440\u0438\u0432\u044f\u0437\u043a\u0438 \u043a \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0435 \u0432\u0430\u0448\u0435\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/i><\/p><\/blockquote>\n<p>  \u0422\u0435\u043c \u043d\u0435 \u043c\u0435\u043d\u0435\u0435, \u0432\u043e\u0442 \u043a\u0430\u043a \u043b\u0435\u0433\u043a\u043e JWT-\u0442\u043e\u043a\u0435\u043d\u044b \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0442\u0441\u044f \u0438 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0443\u044e\u0442\u0441\u044f \u0432 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0435 \u0441\u043e\u0431\u044b\u0442\u0438\u0439 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0445 easy ACL-\u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432.<\/p>\n<pre><code class=\"php\">\/\/ src\/EventSubscriber\/TokenSubscriber.php  namespace App\\EventSubscriber;  use App\\Controller\\AccessTokenController; use Doctrine\\ORM\\EntityManagerInterface; use Firebase\\JWT\\JWT; use Symfony\\Component\\EventDispatcher\\EventSubscriberInterface; use Symfony\\Component\\HttpKernel\\Event\\ControllerEvent; use Symfony\\Component\\HttpKernel\\Exception\\AccessDeniedHttpException; use Symfony\\Component\\HttpKernel\\KernelEvents;  class TokenSubscriber implements EventSubscriberInterface {     public function __construct(EntityManagerInterface $em)     {         $this-&gt;em = $em;     }      public function onKernelController(ControllerEvent $event)     {         $controller = $event-&gt;getController();          \/\/ \u043a\u043e\u0433\u0434\u0430 \u043a\u043b\u0430\u0441\u0441 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u0442 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e action \u043c\u0435\u0442\u043e\u0434\u043e\u0432, \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440         \/\/ \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442\u0441\u044f \u043a\u0430\u043a [$controllerInstance, 'methodName']         if (is_array($controller)) {             $controller = $controller[0];         }          if ($controller instanceof AccessTokenController) {             $jwt = substr($event-&gt;getRequest()-&gt;headers-&gt;get('Authorization'), 7);              try {                 $decoded = JWT::decode($jwt, getenv('JWT_SECRET'), ['HS256']);             } catch (\\Exception $e) {                 throw new AccessDeniedHttpException('Whoops! Access denied.');             }              $user = $this-&gt;em-&gt;getRepository('App:User')                         -&gt;findOneBy(['id' =&gt; $decoded-&gt;sub]);              $identity = $this-&gt;em-&gt;getRepository('EasyAclBundle:Identity')                             -&gt;findBy(['user' =&gt; $user]);              $rolename = $identity[0]-&gt;getRole()-&gt;getName();             $routename = $event-&gt;getRequest()-&gt;get('_route');              $isAllowed = $this-&gt;em-&gt;getRepository('EasyAclBundle:Permission')                             -&gt;isAllowed($rolename, $routename);              if (!$isAllowed) {                 throw new AccessDeniedHttpException('Whoops! Access denied.');             }         }     }      public static function getSubscribedEvents()     {         return [             KernelEvents::CONTROLLER =&gt; 'onKernelController',         ];     } }<\/code><\/pre>\n<p>  \u0411\u043e\u043b\u044c\u0448\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u044d\u0442\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u043e\u0431\u044a\u044f\u0441\u043d\u0435\u043d\u0438\u044f, \u0435\u0441\u043b\u0438 \u0432\u044b \u043e\u043f\u044b\u0442\u043d\u044b\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a; \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c, \u0435\u0441\u043b\u0438 \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0442\u043e\u043a\u0435\u043d \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u0434\u0435\u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u043d, \u0447\u0442\u043e \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442, \u0447\u0442\u043e \u0434\u0430\u043d\u043d\u044b\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d, \u043a\u043e\u0434 \u043f\u044b\u0442\u0430\u0435\u0442\u0441\u044f \u0432\u044b\u044f\u0441\u043d\u0438\u0442\u044c, \u0438\u043c\u0435\u0435\u0442 \u043b\u0438 \u043e\u043d \u043f\u0440\u0430\u0432\u0430 \u0434\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0442\u0435\u043a\u0443\u0449\u0435\u043c\u0443 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0443.<\/p>\n<pre><code class=\"php\">...  $user = $this-&gt;em-&gt;getRepository('App:User')         -&gt;findOneBy(['id' =&gt; $decoded-&gt;sub]);  $identity = $this-&gt;em-&gt;getRepository('EasyAclBundle:Identity')             -&gt;findBy(['user' =&gt; $user]);  $rolename = $identity[0]-&gt;getRole()-&gt;getName(); $routename = $event-&gt;getRequest()-&gt;get('_route');  $isAllowed = $this-&gt;em-&gt;getRepository('EasyAclBundle:Permission')             -&gt;isAllowed($rolename, $routename);  ...<\/code><\/pre>\n<p>  \u0414\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u0432\u0443\u0445 easy ACL-\u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432 (<code>Identity<\/code> \u0438 <code>Permission<\/code>) \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u0442\u043e\u0433\u043e, \u043c\u043e\u0436\u0435\u0442 \u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0442\u0435\u043a\u0443\u0449\u0435\u043c\u0443 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0443.<\/p>\n<h3>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f<\/h3>\n<p>  \u0422\u0435\u043f\u0435\u0440\u044c \u0434\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0432 \u0447\u0435\u043c \u0436\u0435 \u0432\u0441\u044f \u043c\u0430\u0433\u0438\u044f. \u0412 \u0446\u0435\u043b\u043e\u043c, \u0432\u0441\u0435 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u0438 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432 \u0432\u0430\u0448\u0435\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f:<\/p>\n<pre><code class=\"php\"># config\/routes.yaml api_post_create:     path:       \/api\/posts     controller: App\\Controller\\Post\\CreateController::index     methods:    POST  api_post_delete:     path:       \/api\/posts\/{id}     controller: App\\Controller\\Post\\DeleteController::index     methods:    DELETE  api_post_edit:     path:       \/api\/posts\/{id}     controller: App\\Controller\\Post\\EditController::index     methods:    PUT<\/code><\/pre>\n<p>  \u0410 \u0442\u0430\u043a\u0436\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u0439:<\/p>\n<pre><code class=\"php\"># config\/packages\/programarivm_easy_acl.yaml programarivm_easy_acl:   target: App\\Entity\\User   permission:     -       role: Superadmin       routes:         - api_post_create         - api_post_delete         - api_post_edit     -       role: Admin       routes:         - api_post_create         - api_post_edit     -       role: Basic       routes:         - api_post_create<\/code><\/pre>\n<p>  \u0418\u0442\u0430\u043a, \u0442\u0435\u043f\u0435\u0440\u044c, \u0435\u0441\u043b\u0438 \u0432\u0430\u0448\u0430 \u0441\u0445\u0435\u043c\u0430 \u0431\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0430:<\/p>\n<pre><code class=\"php\">php bin\/console doctrine:schema:update --force<\/code><\/pre>\n<p>  \u0427\u0435\u0442\u044b\u0440\u0435 \u043f\u0443\u0441\u0442\u044b\u0435 \u0442\u0430\u0431\u043b\u0438\u0446\u044b \u0431\u0443\u0434\u0443\u0442 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u044b \u0432 \u0432\u0430\u0448\u0443 \u0431\u0430\u0437\u0443 \u0434\u0430\u043d\u043d\u044b\u0445:<\/p>\n<ul>\n<li><code>easy_acl_identity<\/code><\/li>\n<li><code>easy_acl_permission<\/code><\/li>\n<li><code>easy_acl_role<\/code><\/li>\n<li><code>easy_acl_route<\/code><\/li>\n<\/ul>\n<p>  \u042d\u0442\u0430 \u0447\u0435\u0442\u0432\u0435\u0440\u043a\u0430 \u0438\u0434\u0435\u0442 \u0440\u0443\u043a\u0430 \u043e\u0431 \u0440\u0443\u043a\u0443 \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c\u0438 \u0441\u0443\u0449\u043d\u043e\u0441\u0442\u044f\u043c\u0438:<\/p>\n<ul>\n<li><code>Programarivm\\EasyAclBundle\\Entity\\Identity<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Entity\\Permission<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Entity\\Role<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Entity\\Route<\/code><\/li>\n<\/ul>\n<p>  \u0418 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u043c\u0438:<\/p>\n<ul>\n<li><code>Programarivm\\EasyAclBundle\\Repository\\IdentityRepository<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Repository\\PermissionRepository<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Repository\\RoleRepository<\/code><\/li>\n<li><code>Programarivm\\EasyAclBundle\\Repository\\RouteRepository<\/code><\/li>\n<\/ul>\n<p>  \u041d\u0430\u043a\u043e\u043d\u0435\u0446, \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u0430\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u0430 <code>easy-acl:setup<\/code> \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0430 \u0434\u043b\u044f \u0437\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0442\u0430\u0431\u043b\u0438\u0446 easy ACL.<\/p>\n<pre><code class=\"php\">php bin\/console easy-acl:setup This will reset the ACL. Are you sure to continue? (y) y<\/code><\/pre>\n<p>  \u041a\u043e\u043d\u0441\u043e\u043b\u044c MySQL:<\/p>\n<pre><code class=\"php\">mysql&gt; select * from easy_acl_identity; Empty set (0.01 sec)  mysql&gt; select * from easy_acl_permission; +----+------------+-----------------+ | id | rolename   | routename       | +----+------------+-----------------+ |  1 | Superadmin | api_post_create | |  2 | Superadmin | api_post_delete | |  3 | Superadmin | api_post_edit   | |  4 | Admin      | api_post_create | |  5 | Admin      | api_post_edit   | |  6 | Basic      | api_post_create | +----+------------+-----------------+ 6 rows in set (0.00 sec)  mysql&gt; select * from easy_acl_role; +----+------------+ | id | name       | +----+------------+ |  1 | Superadmin | |  2 | Admin      | |  3 | Basic      | +----+------------+ 3 rows in set (0.00 sec)  mysql&gt; select * from easy_acl_route; +----+-----------------+---------+-----------------+ | id | name            | methods | path            | +----+-----------------+---------+-----------------+ |  1 | api_post_create | POST    | \/api\/posts      | |  2 | api_post_delete | DELETE  | \/api\/posts\/{id} | |  3 | api_post_edit   | PUT     | \/api\/posts\/{id} | +----+-----------------+---------+-----------------+ 3 rows in set (0.00 sec)<\/code><\/pre>\n<p>  <\/p>\n<h3>\u0414\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439<\/h3>\n<p>  \u041a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u044f \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u0430\u043a\u0435\u0442\u0443 \u0432\u043e\u043e\u0431\u0449\u0435 \u043d\u0435 \u0432\u043c\u0435\u0448\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0432\u0430\u0448\u0443 \u0431\u0430\u0437\u0443 \u0434\u0430\u043d\u043d\u044b\u0445, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043d\u0435 \u0438\u0437\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0438\u043c.<\/p>\n<p>  \u041a\u0430\u043a \u0432\u044b \u043c\u043e\u0436\u0435\u0442\u0435 \u0432\u0438\u0434\u0435\u0442\u044c, \u0442\u0440\u0438 <code>EasyAcl<\/code> \u0442\u0430\u0431\u043b\u0438\u0446\u044b \u0437\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u044b \u0434\u0430\u043d\u043d\u044b\u043c\u0438, \u043d\u043e, \u043a\u043e\u043d\u0435\u0447\u043d\u043e \u0436\u0435, \u044d\u0442\u043e \u0432\u0430\u0448\u0430 \u0437\u0430\u0434\u0430\u0447\u0430 \u2014 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0442\u044c \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0441\u0432\u043e\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u043a\u0430\u043a \u0432 \u043f\u0440\u0438\u043c\u0435\u0440\u0435, \u043f\u043e\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u043c \u043d\u0438\u0436\u0435.<\/p>\n<pre><code class=\"php\">\/\/ src\/DataFixtures\/EasyAcl\/IdentityFixtures.php  namespace App\\DataFixtures\\EasyAcl;  use App\\DataFixtures\\UserFixtures; use Doctrine\\Bundle\\FixturesBundle\\Fixture; use Doctrine\\Bundle\\FixturesBundle\\FixtureGroupInterface; use Doctrine\\Common\\DataFixtures\\DependentFixtureInterface; use Doctrine\\Common\\Persistence\\ObjectManager; use Programarivm\\EasyAclBundle\\EasyAcl; use Programarivm\\EasyAclBundle\\Entity\\Identity;  class IdentityFixtures extends Fixture implements FixtureGroupInterface, DependentFixtureInterface {     private $easyAcl;      public function __construct(EasyAcl $easyAcl)     {         $this-&gt;easyAcl = $easyAcl;     }      public function load(ObjectManager $manager)     {         for ($i = 0; $i &lt; UserFixtures::N; $i++) {             $index = rand(0, count($this-&gt;easyAcl-&gt;getPermission())-1);             $user = $this-&gt;getReference(&quot;user-$i&quot;);             $role = $this-&gt;getReference(&quot;role-$index&quot;);             $manager-&gt;persist(                 (new Identity())                     -&gt;setUser($user)                     -&gt;setRole($role)             );         }          $manager-&gt;flush();     }      public static function getGroups(): array     {         return [             'easy-acl',         ];     }      public function getDependencies(): array     {         return [             RoleFixtures::class,             UserFixtures::class,         ];     } } <\/code><\/pre>\n<p>  \u0414\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0431\u043e\u043b\u0435\u0435 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0447\u0438\u0442\u0430\u0439\u0442\u0435 <a href=\"https:\/\/github.com\/programarivm\/easy-acl-bundle?ref=hackernoon.com\">\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u044e<\/a>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u0442 \u0432\u0430\u0441 \u0447\u0435\u0440\u0435\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0431\u0430\u043d\u0434\u043b\u0430 easy ACL.<\/p>\n<p>  \u041d\u0430 \u044d\u0442\u043e\u043c \u0432\u0441\u0435. \u0411\u044b\u043b \u043b\u0438 \u044d\u0442\u043e\u0442 \u043f\u043e\u0441\u0442 \u043f\u043e\u043b\u0435\u0437\u0435\u043d? \u042f \u043d\u0430\u0434\u0435\u044e\u0441\u044c, \u0447\u0442\u043e \u0434\u0430. \u0420\u0430\u0441\u0441\u043a\u0430\u0436\u0438\u0442\u0435 \u043d\u0430\u043c \u0432 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f\u0445 \u043d\u0438\u0436\u0435!<\/p>\n<h3>\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u0432\u0430\u0441 \u0442\u0430\u043a\u0436\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u0443\u0435\u0442&#8230;<\/h3>\n<p>  <\/p>\n<ul>\n<li>\u0417\u0430\u043f\u0438\u0441\u044c CASL React Abilities \u0432 JSON-\u0444\u0430\u0439\u043b \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043a\u043e\u043c\u0430\u043d\u0434\u044b Laravel Artisan.<\/li>\n<li><a href=\"https:\/\/hackernoon.com\/an-spa-gui-session-as-a-non-httponly-cookie-s7r2b34?ref=hackernoon.com\">\u0421\u0435\u0430\u043d\u0441 SPA GUI \u043a\u0430\u043a Non-HttpOnly Cookie<\/a><\/li>\n<li>\u0421\u043e\u0432\u0435\u0442 \u0434\u043b\u044f \u043b\u0435\u043d\u0438\u0432\u044b\u0445 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 Symfony.<\/li>\n<\/ul>\n<p>  <\/p>\n<hr>\n<p>  <a href=\"https:\/\/otus.pw\/y4dU\/\">\u0423\u0437\u043d\u0430\u0442\u044c \u043e \u043a\u0443\u0440\u0441\u0435 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u0435\u0435.<\/a><\/p>\n<hr>\n<\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/508424\/\"> https:\/\/habr.com\/ru\/company\/otus\/blog\/508424\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/508424\/\"><b><i>\u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0432 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043a\u0443\u0440\u0441\u0430 <a href=\"https:\/\/otus.pw\/y4dU\/\">\u00abSymfony Framework\u00bb<\/a>.<\/i><\/b><\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/zq\/nb\/ca\/zqnbcatp2nq5swvptivkqozhb4y.png\">  <\/p>\n<hr>\n<p>  \u041d\u0435 \u0441\u0435\u043a\u0440\u0435\u0442, \u0447\u0442\u043e ACL (access control lists) \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0441\u043b\u043e\u0436\u043d\u044b \u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438. \u041f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 Symfony \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u0435\u0442 <a href=\"https:\/\/symfony.com\/doc\/current\/security\/voters.html?ref=hackernoon.com\">\u0438\u0437\u0431\u0438\u0440\u0430\u0442\u0435\u043b\u0435\u0439<\/a> (voters) \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u044b ACL, \u044f \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0440\u0435\u0448\u0438\u043b, \u0447\u0442\u043e \u043d\u0430\u043f\u0438\u0448\u0443 \u0441\u0432\u043e\u0439 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0439 \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 Symfony 5 \u0431\u0430\u043d\u0434\u043b \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u043f\u0438\u0441\u043a\u0430\u043c\u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 (ACL) \u0432 \u043c\u043e\u0438\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445.<\/p>\n<p>  <code>programarivm\/easy-acl-bundle<\/code> \u0438\u0437\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e \u0431\u044b\u043b \u043d\u0430\u043f\u0438\u0441\u0430\u043d \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0432 JWT-\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c API \u0434\u043b\u044f \u043e\u0434\u043d\u043e\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (single page applications \u2014 SPA), \u043d\u043e \u043e\u043d \u0442\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u0435\u043d \u0432 \u0440\u044f\u0434\u0435 \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0435\u0432, \u043a\u043e\u0433\u0434\u0430 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f Security \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442 \u2014 \u0447\u0442\u043e \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 \u0441\u043b\u0443\u0447\u0430\u0435\u0432, \u043f\u043e \u043c\u043e\u0435\u043c\u0443 \u0441\u043a\u0440\u043e\u043c\u043d\u043e\u043c\u0443 \u043c\u043d\u0435\u043d\u0438\u044e, \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442 \u0434\u043b\u044f \u0441\u0435\u0430\u043d\u0441\u043e\u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043c\u043d\u043e\u0433\u043e\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (multi-page applications \u2014 MPA).<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-305978","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/305978","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=305978"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/305978\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=305978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=305978"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=305978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}