Download the PHP package germania-kg/authorization without Composer
On this page you can find all versions of the php package germania-kg/authorization. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package authorization
Germania KG · Authorization
Simple authorization solution with PSR-11 Container compatibility and PSR-7 style Middleware. No hierarchical stuff so far.
Installation
Setup
The Authorization constructor requires an Access Control List, i.e. an array with tasks as keys and allowed roles arrays as elements. The second parameter defines whether to permit in case a task is not defined.
Usage
The Authorization class implements the AuthorizationInterface which defines a single authorize method. Additionally, Authorization provides a __invoke function und thus is callable.
Per-task logging: Both authorize and __invoke Methods do accept an optional PSR-3 Logger instance. This enables you to disable or override the default logger you passed on instantiation. Example:
Container Interoperability
The AuthorizationInterface implements both PSR-11 ContainerInterface and the deprecated Interop\Container\ContainerInterface for backward compatibility. So you can test if your Authorization instance has a task and get the allowed roles.
If a task is not defined, a TaskNotFoundException exception will be thrown. This class implements both the Interop\Container\Exception\NotFoundException and PSR-11's Psr\Container\NotFoundExceptionInterface interface.
More information: PSR-11 Container • container-interop/container-interop
PSR 7-style Middleware
This packages offers three PSR7-style middlewares. All take a Callable authorizer (e.g. class Authorization, see above) and optionally a PSR-3 Logger.
If authorization fails, the Response object gets a 401 Unauthorized
status; after that, the next middelware will be called. This enables you to work with unauthorized requests in later middlewares or controllers.—Well, this is what basically happens inside:
Request URI Authorization
RequestUriAuthorizationMiddleware will check PSR-7 Request's URI string; suitable in most cases.
Route Name Authorization
RouteNameAuthorizationMiddleware is for those working with Slim Framework's Route Names. To get access to current route name, set determineRouteBeforeAppMiddleware in Slim's configuration settings to true.
Customizable Authorization
AuthorizationMiddleware is the base class of the two above, and more configurable. It takes another Callable returning a custom term (or “permission”, you name it) you like to authorize, next to our Authorization Callable from the examples above.
Issues
See issues list.
Development
Unit tests
Either copy phpunit.xml.dist
to phpunit.xml
and adapt to your needs, or leave as is. Run PhpUnit test or composer scripts like this:
All versions of authorization with dependencies
psr/log Version ^1.0
psr/http-message Version ^1.0
psr/container Version ^1.0
psr/http-server-middleware Version ^1.0
nyholm/psr7 Version ^1.4