Main Navigation

\Aksara\Laboratory\Core->setPermission()

The documentation and cheat sheet of our framework

setPermission() enforces module and method permissions.

Purpose

setPermission() enforces module and method permissions. It lets a controller customize Aksara Core behavior while keeping the request inside the built-in CRUD, rendering, permission, validation, and response pipeline.

When to Use

Use it near the beginning of a controller method to configure how Core handles the current request.

Reference

setPermission(array|string $permissiveGroup = [], ?string $redirect = null)

Parameters

ParameterTypeRequiredDefaultDescription
$permissiveGrouparray|stringNo[]Allowed group IDs as an array or comma-separated string. Use 0 to allow every group.
$redirect?stringNonullOptional redirect URL when access is denied.

Return Value

static|Response

Returns the current controller instance when access is allowed, or an Aksara/CodeIgniter response when access is denied or redirected.

Behavior

setPermission() marks the request for Core permission checking. The check uses the active module, method, and group at the time this method is called.

[!IMPORTANT]

Call setPermission() after parentModule() or setMethod() when those methods are needed, because permission is checked using the module and method that are active at call time.

Basic Usage

$this->setPermission([1, 2]);

return $this->render('orders');

Advanced Usage

$this->setTitle(phrase('Orders'))
    ->setIcon('mdi mdi-cart-outline')
    ->setPermission();

Complete Example

namespace Modules\Orders\Controllers;

use Aksara\Laboratory\Core;

class Orders extends Core
{
    public function index()
    {
        $this->setTitle(phrase('Orders'))
            ->setPermission([1, 2]);

        return $this->render('orders');
    }
}

Result

The controller stores the configuration and applies it later in the current request lifecycle.

Notes

  • Call configuration methods before setPermission() or render() when those steps depend on the configured value.
  • Order matters: call parentModule() and setMethod() before setPermission() when needed.

Common Mistakes

  • Calling the method after the permission or render step that already needed it.
  • Spreading related configuration across distant parts of the controller.

Related Methods

Available Methods

addButton addClass addDropdown addField addFilter addSubmitButton addToolbar afterDelete afterInsert afterUpdate allowPublicFormSubmission allowTokenFrom beforeDelete beforeInsert beforeUpdate columnOrder columnSize databaseConfig debug defaultValue deleteBatch deleteData distinct fieldAppend fieldOrder fieldPosition fieldPrepend fieldSize formCallback from fromSubquery getMethod gridView groupBy groupEnd groupField groupStart having havingGroupEnd havingGroupStart havingIn havingLike havingNotIn ignoreQueryString insertData insertId itemReference join like limit mergeContent mergeField modalSize notGroupStart notHavingGroupStart notHavingLike notLike offset orGroupStart orHaving orHavingGroupStart orHavingIn orHavingLike orHavingNotIn orLike orNotGroupStart orNotHavingGroupStart orNotHavingLike orNotLike orWhere orWhereIn orWhereNotIn orderBy parentModule permitUpsert render renderForm renderRead renderTable restrictOnDemo searchable select selectAvg selectCount selectMax selectMin selectSubquery selectSum serialize serializeRow setAiContext setAlias setAttribute setAutocomplete setBreadcrumb setButton setDefault setDescription setField setHeading setIcon setMessages setMethod setOptionLabel setOutput setPermission setPlaceholder setPrimary setRelation setTemplate setTheme setTitle setTooltip setUploadPath setValidation sortable table unsetColumn unsetDelete unsetField unsetMethod unsetRead unsetSelect unsetToolbar unsetTruncate unsetUpdate unsetView updateData validToken validateForm verticalSchema viewOrder where whereIn whereNotIn