Merge branch 'master' into bugfix_type_convertion
This commit is contained in:
@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
## 1.1.1 - Work in progress
|
## 1.1.1 - Work in progress
|
||||||
- Bug #115: Convert client_id to string because pgsql fail with type convertion (Dezinger)
|
- Bug #115: Convert client_id to string because pgsql fail with type convertion (Dezinger)
|
||||||
|
- Bug #119: Security fix: add AccessControl to RuleController (Dezinger)
|
||||||
- Enh #120: 2FA i18n russian translation (Dezinger)
|
- Enh #120: 2FA i18n russian translation (Dezinger)
|
||||||
- Bug #111: Fix migration for PostgreSQL DBMS (MKiselev)
|
- Bug #111: Fix migration for PostgreSQL DBMS (MKiselev)
|
||||||
- Bug #106: Correct exception value returned in `MailEvent::getException` (kartik-v)
|
- Bug #106: Correct exception value returned in `MailEvent::getException` (kartik-v)
|
||||||
|
|||||||
@ -17,10 +17,12 @@ use Da\User\Service\AuthRuleEditionService;
|
|||||||
use Da\User\Traits\AuthManagerAwareTrait;
|
use Da\User\Traits\AuthManagerAwareTrait;
|
||||||
use Da\User\Traits\ContainerAwareTrait;
|
use Da\User\Traits\ContainerAwareTrait;
|
||||||
use Da\User\Validator\AjaxRequestModelValidator;
|
use Da\User\Validator\AjaxRequestModelValidator;
|
||||||
|
use Da\User\Filter\AccessRuleFilter;
|
||||||
use Yii;
|
use Yii;
|
||||||
use yii\filters\VerbFilter;
|
use yii\filters\VerbFilter;
|
||||||
use yii\web\Controller;
|
use yii\web\Controller;
|
||||||
use yii\web\NotFoundHttpException;
|
use yii\web\NotFoundHttpException;
|
||||||
|
use yii\filters\AccessControl;
|
||||||
|
|
||||||
class RuleController extends Controller
|
class RuleController extends Controller
|
||||||
{
|
{
|
||||||
@ -33,12 +35,24 @@ class RuleController extends Controller
|
|||||||
public function behaviors()
|
public function behaviors()
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
[
|
'verbs' => [
|
||||||
'class' => VerbFilter::className(),
|
'class' => VerbFilter::className(),
|
||||||
'actions' => [
|
'actions' => [
|
||||||
'delete' => ['POST'],
|
'delete' => ['POST'],
|
||||||
],
|
],
|
||||||
]
|
],
|
||||||
|
'access' => [
|
||||||
|
'class' => AccessControl::className(),
|
||||||
|
'ruleConfig' => [
|
||||||
|
'class' => AccessRuleFilter::className(),
|
||||||
|
],
|
||||||
|
'rules' => [
|
||||||
|
[
|
||||||
|
'allow' => true,
|
||||||
|
'roles' => ['admin'],
|
||||||
|
],
|
||||||
|
],
|
||||||
|
],
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user