'role' | ['roles'] | '*' * 'prefix' => 'Prefix' | , (default = null) * 'plugin' => 'Plugin' | , (default = null) * 'controller' => 'Controller' | ['Controllers'] | '*', * 'action' => 'action' | ['actions'] | '*', * 'allowed' => true | false | callback (default = true) * ] * You could use '*' to match anything * 'allowed' will be considered true if not defined. It allows a callable to manage complex * permissions, like this * 'allowed' => function (array $user, $role, Request $request) {} * * Example, using allowed callable to define permissions only for the owner of the Posts to edit/delete * * (remember to add the 'uses' at the top of the permissions.php file for Hash, TableRegistry and Request [ 'role' => ['user'], 'controller' => ['Posts'], 'action' => ['edit', 'delete'], 'allowed' => function(array $user, $role, Request $request) { $postId = Hash::get($request->params, 'pass.0'); $post = TableRegistry::getTableLocator()->get('Posts')->get($postId); $userId = Hash::get($user, 'id'); if (!empty($post->user_id) && !empty($userId)) { return $post->user_id === $userId; } return false; } ], */ return [ 'CakeDC/Auth.permissions' => [ //all bypass [ 'prefix' => false, 'plugin' => 'CakeDC/Users', 'controller' => 'Users', 'action' => [ // LoginTrait 'socialLogin', 'login', 'logout', 'socialEmail', 'verify', // RegisterTrait 'register', 'validateEmail', // PasswordManagementTrait used in RegisterTrait 'changePassword', 'resetPassword', 'requestResetPassword', // UserValidationTrait used in PasswordManagementTrait 'resendTokenValidation', 'linkSocial', //Webauthn2fa actions 'webauthn2fa', 'webauthn2faRegister', 'webauthn2faRegisterOptions', 'webauthn2faAuthenticate', 'webauthn2faAuthenticateOptions', ], 'bypassAuth' => true, ], [ 'prefix' => false, 'plugin' => 'CakeDC/Users', 'controller' => 'SocialAccounts', 'action' => [ 'validateAccount', 'resendValidation', ], 'bypassAuth' => true, ], //admin role allowed to all the things [ 'role' => \CakeDC\Users\Model\Table\UsersTable::ROLE_ADMIN, 'prefix' => '*', 'extension' => '*', 'plugin' => '*', 'controller' => '*', 'action' => '*', ], //specific actions allowed for the all roles in Users plugin [ 'role' => '*', 'plugin' => 'CakeDC/Users', 'controller' => 'Users', 'action' => ['profile', 'logout', 'linkSocial', 'callbackLinkSocial'], ], [ 'role' => '*', 'plugin' => 'CakeDC/Users', 'controller' => 'Users', 'action' => 'resetOneTimePasswordAuthenticator', 'allowed' => function (array $user, $role, \Cake\Http\ServerRequest $request) { $userId = \Cake\Utility\Hash::get($request->getAttribute('params'), 'pass.0'); if (!empty($userId) && !empty($user)) { return $userId === $user['id']; } return false; } ], //all roles allowed to Pages/display [ 'role' => '*', 'controller' => 'Pages', 'action' => 'display', ], [ 'role' => '*', 'plugin' => 'DebugKit', 'controller' => '*', 'action' => '*', 'bypassAuth' => true, ], ] ];