PermissionRegistrar
class PermissionRegistrar
Constants
| DEFAULT_ROLE_PIVOT_KEY |
|
| DEFAULT_PERMISSION_PIVOT_KEY |
|
| DEFAULT_TEAM_FOREIGN_KEY |
|
| DEFAULT_CACHE_COLUMN_NAMES_EXCEPT |
|
| ROLE_CATALOG_CACHE_KEY |
|
| MODEL_ROLES_CACHE_KEY_PREFIX |
|
| MODEL_PERMISSIONS_CACHE_KEY_PREFIX |
|
| MODEL_CACHE_TOKEN_KEY |
|
| PERMISSION_CATALOG_CONTEXT_KEY |
|
| WILDCARD_PERMISSION_INDEX_CONTEXT_KEY |
|
| MODEL_VIA_ROLE_PERMISSIONS_CONTEXT_KEY |
|
| protected MODEL_DIRECT_PERMISSIONS_CONTEXT_KEY |
|
| protected MODEL_CLASS_CATALOG_CONTEXT_KEY |
|
| protected DIRTY_CACHE_TOKENS_CONTEXT_KEY |
|
| protected DIRTY_CACHE_VALUES_CONTEXT_KEY |
|
Properties
| static protected string|null | $partitionColumn | ||
| static protected null|Closure(): null|int|string | $partitionResolver | ||
| static protected bool | $initialized | ||
| protected string | $permissionClass | ||
| protected string | $roleClass | ||
| protected string|null | $teamClass | ||
| string | $pivotRole | ||
| string | $pivotPermission | ||
| int | $cacheExpirationTime | ||
| bool | $teams | ||
| protected PermissionsTeamResolver | $teamResolver | ||
| string | $teamsKey | ||
| string | $cacheKey | ||
| protected string | $modelRolesCacheKeyPrefix | ||
| protected string | $modelPermissionsCacheKeyPrefix | ||
| protected string | $modelCacheTokenKey | ||
| protected string|null | $cacheStoreName | ||
| protected Pivot>>> | $assignmentPivotClasses | ||
| protected PermissionRelationContext}>> | $loadedRelationProvenance |
Methods
Create a new permission registrar.
Configure the permission row partition resolver.
Determine whether permission row partitioning is configured.
Get the configured permission partition column.
Resolve the current permission partition.
Ensure a model belongs to the captured permission partition.
Ensure a Role or Permission model uses the permission storage connection.
Initialize cache and config-backed registrar state.
Validate the configured model classes.
Validate that cache serialization retains required model columns.
Validate a configured role model class.
Validate a configured permission model class.
Get the configured cache repository.
Get the memoized cache repository for the current coroutine.
Get the current permissions team id.
Ensure a team-scoped mutation has a selected team.
Flush the permission cache.
Flush the permission cache for an explicit partition.
Invalidate the permission catalog after a model mutation settles.
Rotate the model assignment cache namespace after a model mutation settles.
Forget a model's direct role and permission assignment caches.
Forget a model's assignment caches for an explicit partition and team.
Forget assignment caches for an explicit morph identity, partition, and team.
Invalidate assignment caches after a model mutation settles.
Invalidate assignment caches for an exact identity after a mutation settles.
Forget a model's role assignment cache for an explicit partition and team.
Invalidate a model's role cache after a mutation settles.
Invalidate an exact model identity's role cache after a mutation settles.
Forget a model's permission assignment cache for an explicit partition and team.
Invalidate a model's permission cache after a mutation settles.
Invalidate an exact model identity's permission cache after a mutation settles.
Remember a model's permissions granted through roles.
Remember a model's hydrated direct permissions.
Remember a model's role assignment ids.
Remember a model's permission assignment ids.
Build an assignment cache key for an explicit identity and context.
Build the runtime cache key segment for coroutine-local model state.
Build a coroutine-local cache key for an explicit identity and context.
Get the current model assignment cache token.
Create a new model assignment cache namespace token.
Forget the cached wildcard permission index.
Forget one item from a coroutine-local permission cache.
Forget coroutine-local permission cache items for a partition.
Clear already-loaded permissions collection.
Clear all permission runtime state in the current coroutine.
Clear permission runtime state for an explicit partition.
Mark the context that produced a loaded permission relation.
Determine whether a loaded permission relation matches current context.
Forget loaded permission relation provenance for a model.
Get the permissions based on the passed params.
Get the roles based on the passed params.
Get indexed models for supported exact lookup shapes.
Filter a model collection by attributes.
Determine if an attribute matches a requested value.
Get the permission model class.
Get the connection that owns permission storage.
Run a permission-storage mutation in step with its subject transaction.
Get the current global permission cache key.
Add the permission partition to a cache key.
Resolve an optional explicit partition argument.
Build the runtime key prefix for a partition.
Set the permission model class.
Get the role model class.
Set the role model class.
Get the team model class.
Get the pivot class selected by a model's public assignment relation.
Set the team model class.
Get the unmemoized repository for observing committed shared cache state.
Get the cache store.
Get permissions with their roles.
Get roles for cache.
Determine if any cached role-permission edge is denied.
Determine if a value is a UUID or ULID.
Flush all static state.
Details
at line 128
__construct(CacheManager $cacheManager, Repository $config, Container $app, ModelCacheCoordinator $modelCacheCoordinator)
Create a new permission registrar.
at line 149
static void
resolvePartitionUsing(string $column, Closure $resolver)
Configure the permission row partition resolver.
Register before resolving the Permission registrar or Gate.
Boot-only. The column and callback persist in static properties for the worker lifetime and affect every subsequent permission operation.
at line 169
static bool
partitioningEnabled()
Determine whether permission row partitioning is configured.
at line 177
static string|null
partitionColumn()
Get the configured permission partition column.
at line 185
PermissionPartition|null
resolvePartition()
Resolve the current permission partition.
at line 211
PermissionPartition
partitionFromRecord(Model $model)
Resolve a permission partition from a persisted record.
at line 241
void
ensureModelMatchesPartition(Model $model, PermissionPartition $partition)
Ensure a model belongs to the captured permission partition.
at line 256
void
ensureModelUsesPermissionConnection(Model $model)
Ensure a Role or Permission model uses the permission storage connection.
at line 271
void
initializeCache()
Initialize cache and config-backed registrar state.
Boot or tests only. The values are stored on the singleton registrar and affect every later permission lookup in this worker.
at line 330
protected void
validateModelClasses()
Validate the configured model classes.
at line 339
protected void
validateCacheColumnExclusions()
Validate that cache serialization retains required model columns.
at line 385
protected void
validateRoleClass(string $roleClass)
Validate a configured role model class.
at line 405
protected void
validatePermissionClass(string $permissionClass)
Validate a configured permission model class.
at line 423
protected Repository
configuredCacheRepository()
Get the configured cache repository.
at line 431
protected Repository
cacheRepository()
Get the memoized cache repository for the current coroutine.
at line 657
void
setPermissionsTeamId(int|string|Model|null $id)
Set the current permissions team id.
at line 665
int|string|null
getPermissionsTeamId()
Get the current permissions team id.
at line 673
void
ensureTeamIsSelectedForMutation(PermissionRelationContext|null $context = null)
Ensure a team-scoped mutation has a selected team.
at line 689
bool
registerPermissions(Gate $gate)
Register the permission check method on the gate.
at line 714
bool
forgetCachedPermissions()
Flush the permission cache.
Return the backend result when settled immediately, or true once the reset is registered against an open transaction.
at line 722
bool
forgetCachedPermissionsFor(PermissionPartition|null $partition)
Flush the permission cache for an explicit partition.
at line 736
void
invalidatePermissionCatalogAfterMutation(PermissionPartition|null $partition)
Invalidate the permission catalog after a model mutation settles.
at line 748
void
rotateModelAssignmentCacheTokenAfterMutation(PermissionPartition|null $partition)
Rotate the model assignment cache namespace after a model mutation settles.
at line 778
void
forgetModelAssignmentCache(Model $model)
Forget a model's direct role and permission assignment caches.
at line 790
void
forgetModelAssignmentCacheFor(Model $model, PermissionPartition|null $partition, int|string|null $team)
Forget a model's assignment caches for an explicit partition and team.
at line 806
void
forgetModelAssignmentCacheForIdentity(string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Forget assignment caches for an explicit morph identity, partition, and team.
at line 850
void
invalidateModelAssignmentCacheAfterMutation(Model $model, PermissionPartition|null $partition, int|string|null $team)
Invalidate assignment caches after a model mutation settles.
at line 866
void
invalidateModelAssignmentCacheForIdentityAfterMutation(string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Invalidate assignment caches for an exact identity after a mutation settles.
at line 895
void
forgetModelRoleCache(Model $model)
Forget a model's cached role assignments.
at line 907
void
forgetModelRoleCacheFor(Model $model, PermissionPartition|null $partition, int|string|null $team)
Forget a model's role assignment cache for an explicit partition and team.
at line 937
void
invalidateModelRoleCacheAfterMutation(Model $model, PermissionPartition|null $partition, int|string|null $team)
Invalidate a model's role cache after a mutation settles.
at line 953
void
invalidateModelRoleCacheForIdentityAfterMutation(string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Invalidate an exact model identity's role cache after a mutation settles.
at line 984
void
forgetModelPermissionCache(Model $model)
Forget a model's cached permission assignments.
at line 996
void
forgetModelPermissionCacheFor(Model $model, PermissionPartition|null $partition, int|string|null $team)
Forget a model's permission assignment cache for an explicit partition and team.
at line 1026
void
invalidateModelPermissionCacheAfterMutation(Model $model, PermissionPartition|null $partition, int|string|null $team)
Invalidate a model's permission cache after a mutation settles.
at line 1042
void
invalidateModelPermissionCacheForIdentityAfterMutation(string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Invalidate an exact model identity's permission cache after a mutation settles.
at line 1075
Collection
rememberModelViaRolePermissions(Model $model, Closure $callback)
Remember a model's permissions granted through roles.
at line 1093
void
forgetModelViaRolePermissions(Model $model)
Forget a model's permissions granted through roles.
at line 1106
Collection
rememberModelDirectPermissions(Model $model, Closure $callback)
Remember a model's hydrated direct permissions.
at line 1127
array
rememberModelRoleAssignments(Model $model, Closure $callback)
Remember a model's role assignment ids.
at line 1144
array
rememberModelPermissionAssignments(Model $model, Closure $callback)
Remember a model's permission assignment ids.
at line 1158
protected string
modelCacheKey(string $prefix, Model $model)
Build the cache key for model assignment caches.
at line 1172
protected string
modelCacheKeyForIdentity(string $prefix, string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Build an assignment cache key for an explicit identity and context.
at line 1191
protected string
modelRuntimeCacheKey(Model $model)
Build the runtime cache key segment for coroutine-local model state.
at line 1204
protected string
modelRuntimeCacheKeyForIdentity(string $morphType, int|string $modelKey, PermissionPartition|null $partition, int|string|null $team)
Build a coroutine-local cache key for an explicit identity and context.
at line 1222
string
modelAssignmentCacheToken(PermissionPartition|null $partition = null)
Get the current model assignment cache token.
at line 1251
protected string
newModelAssignmentCacheToken()
Create a new model assignment cache namespace token.
at line 1259
void
forgetWildcardPermissionIndex(Model|null $record = null)
Forget the cached wildcard permission index.
at line 1287
array
getWildcardPermissionIndex(Model $record)
Get the wildcard permission index for a model.
at line 1310
protected string
wildcardPermissionIndexKey(Model $record)
Build the coroutine-local wildcard permission index key.
at line 1318
protected void
forgetRuntimeCacheItem(string $contextKey, string $itemKey)
Forget one item from a coroutine-local permission cache.
at line 1328
protected void
forgetRuntimeCacheItemsForPartition(string $contextKey, PermissionPartition|null $partition)
Forget coroutine-local permission cache items for a partition.
at line 1347
void
clearPermissionsCollection()
Clear already-loaded permissions collection.
at line 1355
protected void
clearAllPermissionRuntimeState()
Clear all permission runtime state in the current coroutine.
at line 1367
protected void
clearPermissionRuntimeStateFor(PermissionPartition|null $partition)
Clear permission runtime state for an explicit partition.
at line 1400
void
markLoadedRelation(Model $model, string $relation, Collection $collection, PermissionRelationContext $context)
Mark the context that produced a loaded permission relation.
at line 1421
bool
loadedRelationIsCurrent(Model $model, string $relation)
Determine whether a loaded permission relation matches current context.
at line 1462
void
forgetLoadedRelationProvenance(Model $model, string|null $relation = null)
Forget loaded permission relation provenance for a model.
at line 1543
Collection
getPermissions(array $params = [], bool $onlyOne = false, string|null $permissionClass = null)
Get the permissions based on the passed params.
at line 1583
Collection
getRoles(array $params = [], bool $onlyOne = false, string|null $roleClass = null)
Get the roles based on the passed params.
at line 1689
protected Collection|null
indexedModels(array $params, bool $onlyOne, string $modelType)
Get indexed models for supported exact lookup shapes.
at line 1792
protected Collection
filterModels(Collection $models, array $params, bool $onlyOne)
Filter a model collection by attributes.
at line 1813
static protected bool
attributeMatches(mixed $actual, mixed $expected)
Determine if an attribute matches a requested value.
at line 1833
string
getPermissionClass()
Get the permission model class.
at line 1841
Connection
getPermissionConnection()
Get the connection that owns permission storage.
at line 1859
void
runPermissionStorageMutationAfterSubjectCommit(Connection $subjectConnection, Closure $mutation)
Run a permission-storage mutation in step with its subject transaction.
at line 1875
string
getCacheKey()
Get the current global permission cache key.
at line 1883
protected string
partitionedCacheKey(string $key, PermissionPartition|null $partition = null)
Add the permission partition to a cache key.
at line 1897
protected PermissionPartition|null
resolvedPartitionArgument(PermissionPartition|null $partition)
Resolve an optional explicit partition argument.
at line 1907
protected string
partitionRuntimePrefix(PermissionPartition|null $partition)
Build the runtime key prefix for a partition.
at line 1920
PermissionRegistrar
setPermissionClass(string $permissionClass)
Set the permission model class.
Boot or tests only. The model class is stored on the singleton registrar and affects every later permission lookup in this worker.
at line 1935
string
getRoleClass()
Get the role model class.
at line 1948
PermissionRegistrar
setRoleClass(string $roleClass)
Set the role model class.
Boot or tests only. The model class is stored on the singleton registrar and affects every later role lookup in this worker.
at line 1963
string|null
getTeamClass()
Get the team model class.
at line 1973
string
getAssignmentPivotClass(Model $model, string $relation)
Get the pivot class selected by a model's public assignment relation.
at line 1995
PermissionRegistrar
setTeamClass(string|null $teamClass)
Set the team model class.
Boot or tests only. The model class is stored on the singleton registrar and affects every later team permission lookup in this worker.
at line 2006
Repository
getCacheRepository()
Get the unmemoized repository for observing committed shared cache state.
at line 2014
Store
getCacheStore()
Get the cache store.
at line 2022
protected Collection
getPermissionsWithRoles(string|null $permissionClass = null)
Get permissions with their roles.
at line 2032
protected Collection
getRolesForCache()
Get roles for cache.
at line 2095
bool
hasDeniedRolePermissions()
Determine if any cached role-permission edge is denied.
at line 2103
protected bool
pivotIsDenied(Model $model)
Determine if a hydrated pivot marks the permission as denied.
at line 2117
protected Collection
relationCollection(Model $model, string $relation)
Get a hydrated relation collection.
at line 2270
static bool
isUid(mixed $value)
Determine if a value is a UUID or ULID.
at line 2290
static void
flushState()
Flush all static state.