This is fork of yii-auth
YiiBooster instead yiistrap
Hi, I found problems to adding security to this module.
For example, in the VIEW action, actually you can update the roles and assignments, which is not good.
I had to move the part where these things were being update to the actionUpdate, and change the 'action' url of the forms that update them.
After this, I've been able to do access control check with accessRules() method, so only people with 'permissions.update' role were able to change them (Add child, remove parent, edit name).
Just what I needed, It seems to work good, I am testing now. Thanks
Please login to leave your comment.