# |
Aug 22nd 2019, 15:20 |
nemmons |
does anyone have enough familiarity with the CakePHP Authorization middleware to help me understand something? in RequestAuthorizationMiddleware::invoke(), it calls `$service->can($identity, $this->getConfig('method'), $request);`. However, AuthorizationService::can() has the signature `can($user, $action, $resource)`.. I'm struggling to understand where/how the the request gets converted to a resource. I feel like i must be missing some |
# |
Aug 22nd 2019, 14:23 |
kaliel |
cakephp talks + onsens sounds great, but the fly is too expensive for me :disappointed_relieved: |
# |
Aug 22nd 2019, 14:11 |
alexdd55976 |
@spriz oh, that’s a great idea. My company won’t pay for a vacation in Japan, so this could be an alternative |
# |
Aug 22nd 2019, 14:09 |
spriz |
I'll buy a pass to see things online if possible though @alexdd55976 :) |
# |
Aug 22nd 2019, 14:00 |
spriz |
Unfortunately not :slightly_smiling_face: |
# |
Aug 22nd 2019, 13:58 |
ricksaccous |
undecided, i'll try to make it though |
# |
Aug 22nd 2019, 13:57 |
neon1024 |
I’m attending |
# |
Aug 22nd 2019, 13:55 |
alexdd55976 |
it does not mean, that you won't be there then |
# |
Aug 22nd 2019, 13:54 |
ricksaccous |
i don't think cakefest is until november |
# |
Aug 22nd 2019, 13:47 |
alexdd55976 |
are you guys all at cakefest? |
# |
Aug 22nd 2019, 13:33 |
spriz |
woops, better to hide then |
# |
Aug 22nd 2019, 13:32 |
lorenzo |
mostly the devs... pulling lots of deps |
# |
Aug 22nd 2019, 13:32 |
spriz |
lukers gotta be poked |
# |
Aug 22nd 2019, 13:32 |
spriz |
poke your lazy devops guy for making them too slow ;P |
# |
Aug 22nd 2019, 13:32 |
lorenzo |
I need to do something while wating for dockerfiles to build! |
# |
Aug 22nd 2019, 13:32 |
neon1024 |
Hope all is well with you @lorenzo :slightly_smiling_face: |
# |
Aug 22nd 2019, 13:31 |
lorenzo |
:) |
# |
Aug 22nd 2019, 13:31 |
spriz |
waiting for advanced ORM questions and you will jump out like an angry troll |
# |
Aug 22nd 2019, 13:31 |
spriz |
You are such a lurker @lorenzo... |
# |
Aug 22nd 2019, 13:30 |
slackebot2 |
Action: lorenzo hides behind a facade |
# |
Aug 22nd 2019, 13:30 |
neon1024 |
Saying the guy who failed the PHP quiz :bow: |
# |
Aug 22nd 2019, 13:30 |
neon1024 |
I don’t think they’re clever at all, it’s just a facade! A static facade! :,) |
# |
Aug 22nd 2019, 13:29 |
neon1024 |
Bah, I think it’s a ruse |
# |
Aug 22nd 2019, 13:29 |
spriz |
I'm just grateful to be in user-land :) |
# |
Aug 22nd 2019, 13:29 |
spriz |
Haha, I'd have to spend quite a few hundred hours on internals before I'd be somewhere near the lower boundary of skills of those peeps |
# |
Aug 22nd 2019, 13:29 |
neon1024 |
Here you are @admad actual proof. If you call doing a quiz on LinkedIn proof :,) |
# |
Aug 22nd 2019, 13:28 |
neon1024 |
:thinking_face: |
# |
Aug 22nd 2019, 13:23 |
neon1024 |
“Make Cake Danish again!” |
# |
Aug 22nd 2019, 13:23 |
neon1024 |
Spriz for the core team! |
# |
Aug 22nd 2019, 13:23 |
spriz |
and I have yet to find a use case for the `Cross Controller Communication` myself :slightly_smiling_face: |
# |
Aug 22nd 2019, 13:22 |
spriz |
and don't put things in hidden formfields that should really be hidden in first place |
# |
Aug 22nd 2019, 13:22 |
spriz |
much rather avoid mass-assignment of entities and use modelless forms and be gone with it |
# |
Aug 22nd 2019, 13:21 |
spriz |
I don't think that's really worth it though |
# |
Aug 22nd 2019, 13:21 |
spriz |
core members told me just to disable it if not using the form tampering prevention |
# |
Aug 22nd 2019, 13:21 |
neon1024 |
It does do form tampering |
# |
Aug 22nd 2019, 13:20 |
spriz |
It's the conclusion I was given after having some troubles with it after putting our app behind CF |
# |
Aug 22nd 2019, 13:20 |
spriz |
Then you don't care craps about SSL :) |
# |
Aug 22nd 2019, 13:20 |
neon1024 |
Jusst me and my Macbook! :beers: |
# |
Aug 22nd 2019, 13:19 |
neon1024 |
Who knows, I don’t have a server yet |
# |
Aug 22nd 2019, 13:19 |
spriz |
if your only usage of `Security` is : `$this->Security->setConfig('blackHoleCallback', 'fooBar');` then just kill it right away |
# |
Aug 22nd 2019, 13:19 |
spriz |
chances are you only use it to enforce https which is quite a lot easier in your LB/webserver |