Login CakePHP 2.5.5
App::uses('Controller', 'Controller');
class AppController extends Controller {
public $components = array(
// 'Security',
'Auth' => array(
'loginRedirect' => array(
'controller' => 'users',
'action' => 'index'
'logoutRedirect' => array(
'controller' => 'users',
'action' => 'login',
'authenticate' => array(
'Form' => array(
'userModel' => 'User',
'passwordHasher' => 'Blowfish',
'fields' => array(
'user_email' => 'email',
'user_pass' => 'password'
'authorize' => array('Controller')
public function beforeFilter() {
$this->Auth->allow('index', 'view');
public function isAuthorized($user) {
//Any registered user can access public functions
if(empty($this->request->params['admin'])) {
return true;
//Only admin can access admin function
if(isset($this->request->params['admin'])) {
return (bool)($user['user_role'] === 'admin');
//Default deny
return false;
<!-- login.ctp -->
<?php pr(Debugger::trace()); ?>
<div class="container">
<?php echo $this->Session->flash('auth'); ?>
echo $this->Form->create(
'role' => 'form'
<?php echo __('Please enter your username and password!'); ?>
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Username',
'div' => array(
'class' => 'form-group'
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Password',
'type' => 'password',
'div' => array(
'class' => 'form-group'
echo $this->Form->submit(
'class' => 'btn btn-primary'
<div class="container">
echo $this->Form->create(
'role' => 'form' //role="form"
//User email input
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Email *',
'type' => 'email',
'placeholder' => 'Enter your email',
'div' => array(
'class' => 'form-group'
//Username input
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Username *',
'type' => 'text',
'placeholder' => 'Enter your username',
'div' => array(
'class' => 'form-group'
//Password input
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Password *',
'type' => 'password',
'placeholder' => 'Enter your password',
'div' => array(
'class' => 'form-group'
//Confirm password
echo $this->Form->input(
'class' => 'form-control',
'label' => 'Confirm Password *',
'type' => 'password',
'placeholder' => 'Retype your password',
'div' => array(
'class' => 'form-group'
echo $this->Form->submit(
'class' => 'btn btn-primary'
App::uses('AppModel', 'Model');
//App::import('Vendor', 'CustomPasswordHasher');
class User extends AppModel {
public $validate = array(
'user_email' => array(
'required' => array(
'rule' => array('notEmpty'),
'message' => 'An email is required.'
'user_login' => array(
'required' => array(
'rule' => array('notEmpty'),
'message' => 'A username is required.'
'user_pass' => array(
'required' => array(
'rule' => array('notEmpty'),
'message' => 'A password is required.'
'user_role' => array(
'valid' => array(
'rule' => array('inList', array('admin','user')),
'message' => 'Please enter a valid role',
'allowEmpty' => false
public function beforeSave($option = array()) {
if(isset($this->data[$this->alias]['user_pass'])) {
$passwordHasher = new BlowfishPasswordHasher();
$this->data[$this->alias]['user_pass'] = $passwordHasher->hash($this->data[$this->alias]['user_pass']);
// debug($this->data[$this->alias]['user_pass']);
return true;
App::uses('AppController', 'Controller');
class UsersController extends AppController {
public $name = 'Users';
// public $scaffold;
public function beforeFilter() {
$this->Auth->allow('register', 'logout');
if(!$this->Auth->login()) {
$this->Auth->authError = false;
else $this->Auth->authError = true;
public function index() {
$this->User->recursive = 0;
$this->set('users', $this->paginate());
// $this->helpers['Paginator'] = array('ajax' => 'CustomJS');
public function view($id = null) {
if(!$id) {
throw new NotFoundException(__('User ID is invalid!'));
$this->User->id = $id;
if(!$this->User->exists()) {
throw new NotFoundException(__('User is not exist!'));
$this->set('user', $this->User->read(null, $id));
public function edit($id = null) {
if(!$id) {
throw new NotFoundException(__('User ID is invalid!'));
$this->User->id = $id;
if(!$this->User->exists()) {
throw new NotFoundException(__('User is not exist!'));
if($this->request->is('post') || $this->request->is('put')) {
if($this->User->save($this->request->data)) {
$this->Session->setFlash(__('The user info has been updated!'));
return $this->redirect(array('action' => 'index'));
$this->Session->setFlash(__('Unable to update the user info. Please try again!'));
} else {
$this->request->data = $this->User->read(null, $id);
public function delete($id = null) {
$this->User->id = $id;
if(!$this->User->exists()) {
throw new NotFoundException('User is not exist!');
if($this->User->delete()) {
$this->Session->setFlash(__('The user info has been deleted!'));
return $this->redirect(array('action' => 'index'));
$this->Session->setFlash(__('Unable to delete user %s. Please try again', h($this->request->data['User']['user_login'])));
return $this->redirect(array('action' => 'index'));
public function register() {
if($this->request->is('post')) {
if($this->User->save($this->request->data)) {
$id = $this->User->id;
$this->request->data['User'] = array_merge(
array('id' => $id)
// $this->Session->setFlash(__('The user %s has been added!', h($this->request->data['User']['user_login'])));
return $this->redirect(array('action' => 'index'));
$this->Session->setFlash(__('Unable to add new user. Please try again!'));
public function login() {
if($this->Session->check('Auth.user')) {
$this->redirect(array('action' => 'index'));
if($this->request->is('post')) {
// debug($this->Auth->user());
// debug($this->Auth->login());
if($this->Auth->login()) {
return $this->redirect($this->Auth->redirectUrl());
__('Invalid username or password, try again!'),
public function logout() {
return $this->redirect($this->Auth->logout());
public function isAuthorized($user) {
// All registered user can create new notes
if($this->action === 'add') {
return true;
//Only admin can edit or delete
if(in_array($this->action, array('edit', 'delete'))) {
$noteId = (int) $this->request->params['pass']['0'];
if($this->Note->isOwnedBy($noteId, $user['id'])) {
return true;
return parent::isAuthorized($user);
