php - 如何限制用户访问 YII 框架中的个人资料信息

标签 php yii


我已经为用户尝试过 Controller ,他们可以访问其他用户的 Controller 索引。请描述如何更改 YII 框架中的设置,使每个用户只能访问他们的信息。

我使用的是 1.1.X 版本

我又来了,我有我以前的问题 我希望他们只看到他们的笔记


class TextController extends Controller
     * @var string the default layout for the views. Defaults to '//layouts/column2', meaning
     * using two-column layout. See 'protected/views/layouts/column2.php'.
    public $layout='//layouts/column2';

     * @return array action filters
    public function filters()
        return array(
            'accessControl', // perform access control for CRUD operations
            'postOnly + delete', // we only allow deletion via POST request

     * Specifies the access control rules.
     * This method is used by the 'accessControl' filter.
     * @return array access control rules
    public function accessRules()
        return array(
            array('allow',  // allow all users to perform 'index' and 'view' actions
            array('allow', // allow authenticated user to perform 'create' and 'update' actions
            array('allow', // allow admin user to perform 'admin' and 'delete' actions
            array('deny',  // deny all users

     * Displays a particular model.
     * @param integer $id the ID of the model to be displayed
    public function actionView($id)

     * Creates a new model.
     * If creation is successful, the browser will be redirected to the 'view' page.
    public function actionCreate()
        $model=new Text;

        // Uncomment the following line if AJAX validation is needed
        // $this->performAjaxValidation($model);



     * Updates a particular model.
     * If update is successful, the browser will be redirected to the 'view' page.
     * @param integer $id the ID of the model to be updated
    public function actionUpdate($id)

        // Uncomment the following line if AJAX validation is needed
        // $this->performAjaxValidation($model);



     * Deletes a particular model.
     * If deletion is successful, the browser will be redirected to the 'admin' page.
     * @param integer $id the ID of the model to be deleted
    public function actionDelete($id)

        // if AJAX request (triggered by deletion via admin grid view), we should not redirect the browser
            $this->redirect(isset($_POST['returnUrl']) ? $_POST['returnUrl'] : array('admin'));

     * Lists all models.
    public function actionIndex()
        $dataProvider=new CActiveDataProvider('Text');

     * Manages all models.
    public function actionAdmin()
        $model=new Text('search');
        $model->unsetAttributes();  // clear any default values


     * Returns the data model based on the primary key given in the GET variable.
     * If the data model is not found, an HTTP exception will be raised.
     * @param integer $id the ID of the model to be loaded
     * @return Text the loaded model
     * @throws CHttpException
    public function loadModel($id)
            throw new CHttpException(404,'The requested page does not exist.');
        return $model;

     * Performs the AJAX validation.
     * @param Text $model the model to be validated
    protected function performAjaxValidation($model)
        if(isset($_POST['ajax']) && $_POST['ajax']==='text-form')
            echo CActiveForm::validate($model);

显示的限制已解决。但是用户通过URL可以访问别人做的笔记要做到这一点,给那个人可以更改top number然后他就可以访问其他用户的信息对于这个问题我该怎么办?



  public function actionIndex()
    $dataProvider=new CActiveDataProvider('Text',array(
        'criteria' => array(
            'condition' => 'user_id=:user_id',
            'params' => array(':user_id' => Yii::app()->User->id),);

