You are viewing revision #9 of this wiki article.
This version may not be up to date with the latest version.
You may want to view the differences to the latest version or see the changes made in this revision.
How to create a simple (non-RBAC) authorization system
As I notice reading the forum, this is a frequent doubt, so I decided to write this article.
This article covers only the authorization system. I assume you already know how to create an authentication system ( login ).
Database ¶
Firstly, in the 'user' table, create a new integer field called 'accessLevel', that defines the user's access level
Extending CWebUser ¶
in your config file (usually protected/config/main.php)
//tell the application to use your WebUser class instead of the default CWebUser
In your components folder ( protected/components ) create a 'WebUser.php' file and a class like this:
class WebUser extends CWebUser{
private $_user;
//is the user a superadmin ?
function getIsSuperAdmin(){
return ( $this->user && $this->user->accessLevel == User::LEVEL_SUPERADMIN );
//is the user an administrator ?
function getIsAdmin(){
return ( $this->user && $this->user->accessLevel >= User::LEVEL_ADMIN );
//get the logged user
function getUser(){
if( $this->isGuest )
if( $this->_user === null ){
$this->_user = User::model()->findByPk( $this->id );
return $this->_user;
Usage ¶
now to validate the user using the filter accessControl
//in your controller
function accessRules(){
return array(
//only accessable by admins
//the 'user' var in an accessRule expression is a reference to Yii::app()->user
//deny all other users
using it in your views
echo 'Welcome, administrator!';
echo 'You are the man!';
Data representation ¶
Now in your User model, to facilitate the data representation of an integer field do the following
class User extends CActiveRecord{
//define the number of levels that you need
//define the label for each level
static function getAccessLevelList( $level = null ){
self::LEVEL_REGISTERED => 'Registered',
self::LEVEL_AUTHOR => 'Author',
self::LEVEL_ADMIN => 'Administrator'
if( $level === null)
return $levelList;
return $levelList[ $level ];
//using it in forms
//using it in DetailView
//using it in GridView
//display the administrator label
echo User::getAccessLevelList( User::LEVEL_ADMIN );
And that is it. I hope that helps you.
Cheers, Gustavo
Read more ¶
- Definitive guide - Authentication and Authorization
- Wiki - Understanding Virtual Attributes and get/set methods
- Wiki - How to add more information to Yii::app()->user
- Wiki - Add information to Yii::app()->user by extending CWebUser
Yii already had built in for authorized
Yii had built in function for authorized here
If you have any questions, please ask in the forum instead.
Signup or Login in order to comment.