【发布时间】:2011-10-08 01:07:29
【问题描述】:
我的学生控制器中有以下 isAuthorized() 函数:
function isAuthorized() {
$studentId = $this->Auth->user('id');
$studentEmail = $this->Auth->user('email');
if ($this->Auth->user('active') == 1 && $this->Auth->user('level_complete') != 1) {
$this->Auth->loginRedirect = '/classrooms/view';
return true;
} elseif (!$this->Student->hasPayed($studentId)) {
$this->Session->write('Payment.student_id', $studentId);
$this->Session->write('Payment.student_email', $studentEmail);
$this->Session->write('Payment.examScore', $this->Student->getPlacementScore($studentId));
$this->Auth->logout();
$this->redirect(array('controller'=>'payments', 'action'=>'pay'));
} elseif ($this->Auth->user('level_complete') == 1) {
$this->Session->write('Payment.student_id', $studentId);
$this->Session->write('Payment.student_email', $studentEmail);
$this->Auth->logout();
$this->redirect(array('controller' => 'payments', 'action' => 'repay'));
} else {
$this->Auth->logout();
$this->redirect(array('controller' => 'students', 'action' => 'disabled'));
}
return false;
}
这个方法基本上涵盖了四种可能的状态:
- 用户处于活动状态且尚未完成关卡 = 已授权
- 用户尚未付款 = 未授权
- 用户已完成一个关卡,必须再次付费 = 未授权
- 用户帐户未激活
我遇到的问题是我的标题中有一个登录表单,我可以从任何控制器登录。如果我从除 Student Controller 以外的其他控制器登录,则不会调用 isAuthorized() 方法,即使用户无法登录,也可以登录。
有什么想法吗?
编辑:在检查 API 对 isAuthorized() 方法的定义后,我认为该方法仅在学生控制器的操作被请求时才被调用。那我还能在哪里实现这个逻辑呢?谢谢
【问题讨论】:
-
你在用
beforeFilter()吗? -
是的,在 beforeFilter() 中设置 Auth 组件,但不适用于此逻辑。我虽然在用户尝试登录时调用了 isAuthorized() 方法。
-
您在每个控制器中都有登录操作?