extends |
Model |
|---|
Class Ability
Represents a fine-grained permission token within a UI5 application. Abilities define what an actor (role or group) can do or see inside a module.
Abilities are declared in two places, split by what they gate, and synchronized into
the SDK database by ui5:sync:
See comes from the UI5 app's manifest.json, harvested by
{@see \LaravelUi5\Sdk\Platform\Manifest\ManifestAbilityExtractor}. It gates a UI
element, so it is declared where that element is — there is deliberately no PHP
attribute for it.Access, Act and Read come from the PHP attributes of the same name in
{@see \LaravelUi5\Sdk\Security\Attributes\Access},
{@see \LaravelUi5\Sdk\Security\Attributes\Act} and
{@see \LaravelUi5\Sdk\Security\Attributes\Read}. Each gates something the backend
enforces — entering an artifact, running an action, reading an entity set — so it is
declared on the PHP class that owns it.Each ability belongs to one artifact (typically a UI5 App) and can be linked to one or more roles for access control.
"submitOffer" or "Dialogs.ProjectWizard.BtnNext"
Access, Act, See or Read. The integer 0 slot
held the retired Use type and stays vacantAbilities are never managed manually; they are part of the synchronization between manifest definitions and database state.
| Methods | ||
|---|---|---|
public
|
artifact(): BelongsTo
|
# |
public
|
fullKey(): string
|
# |
public
|
roles(): BelongsToMany
|
# |
public
|
__toString(): string
|
# |
| Properties | |||
|---|---|---|---|
public
|
int
|
$id
|
# |
public
|
int
|
$artifact_id
|
# |
public
|
string
|
$ability
|
# |
public
|
AbilityType
|
$type
|
# |
public
|
Carbon|null
|
$created_at
|
# |
public
|
Carbon|null
|
$updated_at
|
# |
public
readonly
|
Artifact
|
$artifact
|
# |
public
readonly
|
Collection|Role[]
|
$roles
|
# |