【问题标题】:Expression language in access control security.yml not for routing访问控制 security.yml 中的表达式语言不适用于路由
【发布时间】:2017-10-24 08:27:46
【问题描述】:

我在访问控制中使用参数时遇到问题(symfony 3.3.)* :

-
    path: ^/api
    allow_if: "has_role('ROLE_API_USER') or request.getHost() in '%internal_host%'"

堆栈跟踪错误:

A string value must be composed of strings and/or numbers, but found parameter "internal_host" of type array inside string value "has_role('ROLE_API_USER') or request.getHost() in '%internal_host%'"

我尝试了其他方式,例如 request.getHost() in parameter('internal_host') 或 request.getHost() in container.getParameter('internal_host'),但我收到了类似 The function "parameter" does not exist around position 51 for expression has_role('ROLE_API_USER') or request.getHost() in parameter('internal_host'). 的错误消息(容器服务的消息相同)。

如何在表达式语言的访问控制中使用参数?

【问题讨论】:

标签: symfony symfony-security


【解决方案1】:

如果你使用 Symfony 3,你可以试试:

-
    path: ^/api
    allow_if: "has_role('ROLE_API_USER') or request.getHost() in ['%internal_host%']"

cfAccess global parameters from route condition expressions in Symfony

【讨论】:

  • 是的,我已经尝试过了,但由于 %internal_host% 是参数而无法正常工作
  • 您尝试过使用env parameter 吗?我认为它可以用于内部主机
  • 我有同样的错误:函数“env”在位置 51 附近不存在表达式 has_role('ROLE_API_USER') or request.getHost() in env('internal_host')
  • 你找到解决办法了吗??
猜你喜欢
  • 1970-01-01
  • 2021-03-11
  • 1970-01-01
  • 2020-06-03
  • 1970-01-01
  • 2011-10-04
  • 1970-01-01
  • 2023-03-28
  • 1970-01-01
相关资源
最近更新 更多