Hướng dẫn what user is php - người dùng nào là php

Trong bất kỳ hệ thống nào, việc phân quyền là một điều hết sức quan trọng. Việc phân quyền sẽ quy định người dùng có thể truy cập những chức năng nào, thực hiện những tác vụ nào trong hệ thống.

Hôm nay mình sẽ hướng dẫn các bạn tạo một hệ thống phân quyền đơn giản nhưng khá đầy đủ, sử dụng trong Laravel.

1. Bài toán

Phân quyền quản lý các bài viết trong blog: create, view, update, delete, restore, force delete.

Một user có nhiều role, một role có nhiều permission.

2. Chuẩn bị

2.1 Database Struct

Chúng ta sẽ cần các bảng: users, roles, permissions, role_user và permission_role

Schema::create('users', function (Blueprint $table) {

Schema::create('roles', function (Blueprint $table) {

Schema::create('permissions', function (Blueprint $table) {

Schema::create('role_user', function (Blueprint $table) {


Schema::create('permission_role', function (Blueprint $table) {


Schema::create('posts', function (Blueprint $table) {


2.2 Trait HasPermissions


namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

2.3 Models

Role model

namespace App\Models;

use Illuminate\Database\Eloquent\Model;

class Role extends Model
    public $timestamps = false;

    public function permissions()
        return $this->belongsToMany('App\Models\Permission');

Permission model

namespace App\Models;

use Illuminate\Database\Eloquent\Model;

class Permission extends Model
    public $timestamps = false;

Post model

namespace App\Models;

use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\SoftDeletes;

class Post extends Model
    use SoftDeletes;

    const STATUS_DRAFT = 'draft';
    const STATUS_UNPUBLISHED = 'unpublished';
    const STATUS_PUBLISHED = 'published';

    public function user()
        return $this->belongsTo('App\Models\User');

User model

namespace App\Models;

use Illuminate\Contracts\Auth\MustVerifyEmail;
use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;
use App\Traits\HasPermissions;

class User extends Authenticatable
    use Notifiable, MustVerifyEmail, HasPermissions;

     * The attributes that are mass assignable.
     * @var array
    protected $fillable = [
        'name', 'email', 'password',

     * The attributes that should be hidden for arrays.
     * @var array
    protected $hidden = [
        'password', 'remember_token',

     * The attributes that should be cast to native types.
     * @var array
    protected $casts = [
        'email_verified_at' => 'datetime',

2.3 Seeder Data

		'name' => 'admin',
		'email' => '',
		'password' => bcrypt('123456'),
		'created_at' => now(),
		'updated_at' => now(),
		'email_verified_at' => now(),
		'name' => 'user',
		'email' => '',
		'password' => bcrypt('123456'),
		'created_at' => now(),
		'updated_at' => now(),
		'email_verified_at' => now(),

	['name' => 'review_post'],
	['name' => 'update_post'],
	['name' => 'delete_post'],
	['name' => 'restore_post'],
	['name' => 'force_delete_post'],

	['name' => 'admin'],
	'role_id' => 1,
	'user_id' => 1,
	['permisison_id' => 1, 'role_id' => 1],
	['permisison_id' => 2, 'role_id' => 1],
	['permisison_id' => 3, 'role_id' => 1],
	['permisison_id' => 4, 'role_id' => 1],
	['permisison_id' => 5, 'role_id' => 1],

3 Phân quyền

Chúng ta sẽ sử dụng Policy trong Laravel để kiểm tra quyền truy cập của user vào Controller.

3.1 Tạo policy

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

namespace App\Policies;

use App\Models\User;
use App\Models\Post;
use Illuminate\Auth\Access\HandlesAuthorization;

class PostPolicy
    use HandlesAuthorization;

     * Determine whether the user can view the post.
     * @param  \App\Models\User  $user
     * @param  \App\Models\Post  $post
     * @return mixed
    public function view(?User $user, Post $post)
        return (
            $post->status == Post::STATUS_PUBLISHED ||
            ($user && (
                $user->id == $post->user_id
                || $user->hasPermission('review_post')

     * Determine whether the user can create posts.
     * @param  \App\Models\User  $user
     * @return mixed
    public function create(User $user)
        return $user->hasVerifiedEmail()

     * Determine whether the user can update the post.
     * @param  \App\Models\User  $user
     * @param  \App\Models\Post  $post
     * @return mixed
    public function update(User $user, Post $post)
        return ($user->id == $post->user_id || $user->hasPermission('update_post'));

     * Determine whether the user can delete the post.
     * @param  \App\Models\User  $user
     * @param  \App\Models\Post  $post
     * @return mixed
    public function delete(User $user, Post $post)
        return ($user->id == $post->user_id || $user->hasPermission('delete_post'));

     * Determine whether the user can restore the post.
     * @param  \App\Models\User  $user
     * @param  \App\Models\Post  $post
     * @return mixed
    public function restore(User $user, Post $post)
        return ($user->id == $post->user_id || $user->hasPermission('restore_post'));

     * Determine whether the user can permanently delete the post.
     * @param  \App\Models\User  $user
     * @param  \App\Models\Post  $post
     * @return mixed
    public function forceDelete(User $user, Post $post)
        return ($user->id == $post->user_id || $user->hasPermission('force_delete_post'));

3.2 Gán Policy cho Model

Trong file app/Providers/AuthServiceProvider.php, chúng ta gán PostPolicy cho model Post:app/Providers/AuthServiceProvider.php, chúng ta gán PostPolicy cho model Post:app/Providers/AuthServiceProvider.php, chúng ta gán PostPolicy cho model Post:

protected $policies = [
    \App\Models\Post::class => \App\Policies\PostPolicy::class,

3.3 Check Policy

Chúng ta có thể check Policy ở bất kỳ đâu có thể sử dụng Authorization.

Ở controller:

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

Trong đoạn code

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    4 chính là tên method trong
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    6 (Post Model) là paramter thứ 2 được truyền vào method
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    4 trong
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    5 sau
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();

Thông qua User model

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();
4 và

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();
6 tương tự như ví dụ bên trên.

Ở Middleware

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

Trong đoạn code

namespace App\Models;

use Illuminate\Database\Eloquent\Model;

class Role extends Model
    public $timestamps = false;

    public function permissions()
        return $this->belongsToMany('App\Models\Permission');
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    4 chính là tên method trong
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    6 (Post Model) là paramter thứ 2 được truyền vào method
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    4 trong
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();
    5 sau
    namespace App\Traits;
    use App\Models\Role;
    trait HasPermissions
        protected $permissionList = null;
        public function roles()
            return $this->belongsToMany(Role::class);
        public function hasRole($role)
            if (is_string($role)) {
                return $this->roles->contains('name', $role);
            return false;
        public function hasPermission($permission = null)
            if (is_null($permission)) {
                return $this->getPermissions()->count() > 0;
            if (is_string($permission)) {
                return $this->getPermissions()->contains('name', $permission);
            return false;
        private function getPermissions()
            $role = $this->roles->first();
            if ($role) {
                if (! $role->relationLoaded('permissions')) {
                $this->permissionList = $this->roles->pluck('permissions')->flatten();
            return $this->permissionList ?? collect();

Thông qua User model

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();
4 và

namespace App\Traits;

use App\Models\Role;

trait HasPermissions
    protected $permissionList = null;

    public function roles()
        return $this->belongsToMany(Role::class);

    public function hasRole($role)
        if (is_string($role)) {
            return $this->roles->contains('name', $role);

        return false;

    public function hasPermission($permission = null)
        if (is_null($permission)) {
            return $this->getPermissions()->count() > 0;

        if (is_string($permission)) {
            return $this->getPermissions()->contains('name', $permission);

        return false;

    private function getPermissions()
        $role = $this->roles->first();
        if ($role) {
            if (! $role->relationLoaded('permissions')) {

            $this->permissionList = $this->roles->pluck('permissions')->flatten();

        return $this->permissionList ?? collect();
6 tương tự như ví dụ bên trên.