This is an example of how beforeExecuteRoute method is dealing with allowing users and guests to appropriate area resources:
if($allowed != Phalcon\Acl::ALLOW)
//If he doesn't have access forward him to the index controller
$this->flashSession->warning("You don't have access to this module");
//Returning "false" we tell to the dispatcher to stop the current operation
return false;
What if i have one more role - admins and don't want to have users end up in index page when they try to enter admin area(also want to send another message than to guests)?? Here is my Security.php code:
use Phalcon\Events\Event,
Phalcon\Acl\Adapter\Memory as AclList,
class Security extends Plugin
public function _getAcl()
if (!isset($this->persistent->acl))
//Create the ACL
$acl = new AclList();
//The default action is DENY access
//Register three roles, Users are registered users,
//Admin is the registered SuperUser
//and Guests are users without a defined identity
$roles = array(
'users' => new Phalcon\Acl\Role('Users'),
'guests' => new Phalcon\Acl\Role('Guests'),
'admin' => new Phalcon\Acl\Role('Admin')
foreach ($roles as $role)
//Admin area resources
$adminResources = array(
'users' => array('index', 'new', 'edit', 'delete'),
foreach ($adminResources as $resource => $actions)
$acl->addResource(new Phalcon\Acl\Resource($resource), $actions);
// User area resources
$userResources = array(
'calendar' => array('index', 'update', 'book', 'done'),
foreach ($userResources as $resource => $actions)
$acl->addResource(new Phalcon\Acl\Resource($resource), $actions);
//Public area resources (frontend)
$publicResources = array(
'session' => array('index', 'start', 'end'),
'notfound' => array('route404')
foreach ($publicResources as $resource => $actions)
$acl->addResource(new Phalcon\Acl\Resource($resource), $actions);
//Grant access to public areas to all
foreach ($roles as $role)
foreach ($publicResources as $resource => $actions)
$acl->allow($role->getName(), $resource, '*');
//Grant access to calendar area to roles Users and Admin
foreach ($userResources as $resource => $actions)
foreach ($actions as $action)
$acl->allow('Users', $resource, $action);
$acl->allow('Admin', $resource, $action);
//Grant access to admin area to role Admin only
foreach ($adminResources as $resource => $actions)
foreach ($actions as $action)
$acl->allow('Admin', $resource, $action);
return $acl;
public function beforeExecuteRoute(Event $event, Dispatcher $dispatcher)
//Check whether the "auth" variable exists in session to define the active role
$auth = $this->session->get('auth');
$role = 'Guests';
else if($auth['admin_role'] == 0)
$role = 'Users';
$role = 'Admin';
//Take the active controller/action from the dispatcher
$controller = $dispatcher->getControllerName();
$action = $dispatcher->getActionName();
//Obtain the ACL list
$acl = $this->_getAcl();
//Check if the Role have access to the controller (resource)
$allowed = $acl->isAllowed($role, $controller, $action);
if($acl->isAllowed('Users', 'users', 'index'))
$this->flashSession->warning("You don't have access to admin area");
//It does not work this way!!
if($allowed != Phalcon\Acl::ALLOW)
//If he doesn't have access forward him to the session/index controller
$this->flashSession->warning("You don't have access to this module");
//Returning "false" we tell to the dispatcher to stop the current operation
return false;