Class LaravelUi5\Sdk\Security\Models\Ability

extends Model

Class Ability

Represents a fine-grained permission token within a UI5 application. Abilities define what an actor (role or group) can do or see inside a module.

Abilities are declared in two places, split by what they gate, and synchronized into the SDK database by ui5:sync:

  • See comes from the UI5 app's manifest.json, harvested by {@see \LaravelUi5\Sdk\Platform\Manifest\ManifestAbilityExtractor}. It gates a UI element, so it is declared where that element is — there is deliberately no PHP attribute for it.
  • Access, Act and Read come from the PHP attributes of the same name in {@see \LaravelUi5\Sdk\Security\Attributes\Access}, {@see \LaravelUi5\Sdk\Security\Attributes\Act} and {@see \LaravelUi5\Sdk\Security\Attributes\Read}. Each gates something the backend enforces — entering an artifact, running an action, reading an entity set — so it is declared on the PHP class that owns it.

Each ability belongs to one artifact (typically a UI5 App) and can be linked to one or more roles for access control.

Key Concepts

  • ability — technical key, e.g. "submitOffer" or "Dialogs.ProjectWizard.BtnNext"
  • type — {@see AbilityType}: Access, Act, See or Read. The integer 0 slot held the retired Use type and stays vacant
  • artifact_id — links the ability to its source app or module

Abilities are never managed manually; they are part of the synchronization between manifest definitions and database state.

  • Illuminate\Database\Eloquent\Model
    • LaravelUi5\Sdk\Security\Models\Ability
Methods
Properties