# Best way to create a custom rbac

**URL:** https://discourse.cakephp.org/t/best-way-to-create-a-custom-rbac/6914
**Category:** Need Help
**Created:** [November 23, 2019, 6:08pm UTC](https://discourse.cakephp.org/t/best-way-to-create-a-custom-rbac/6914 "2019-11-23T18:08:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![udarts](https://avatars.discourse-cdn.com/v4/letter/u/d9b06d/32.png) [@udarts](https://discourse.cakephp.org/u/udarts)
#### Post date: [November 23, 2019, 6:08pm UTC](https://discourse.cakephp.org/t/best-way-to-create-a-custom-rbac/6914/1 "2019-11-23T18:08:25Z")

</div>

I am using cakephp 3.8 and create a backend with frontend features, I want to use a rbac system to show certain menu elements (depending on the rights a user has) and to control the access of controllers and actions.

Anyone an idea of ways to do this.

I know there are plugins that have that, but they are not working with the way my backend is created.

---

<div class="post-metadata">

### Author: ![Schlaefer](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/schlaefer/32/1001_2.png) [@Schlaefer](https://discourse.cakephp.org/u/Schlaefer)
#### Post date: [November 24, 2019, 4:45pm UTC](https://discourse.cakephp.org/t/best-way-to-create-a-custom-rbac/6914/2 "2019-11-24T16:45:14Z")

</div>

It’s hard to make a general recommendation, this can be accomplished in many ways. You can check something like

```php
if ($Rbac->check($resource, $role)) { ...

```

and bring your own RBAC permission provider, resource identifier and role identifier. How to set it up/bootstrap the configuration, where to check and who provides all this information depends on your particular needs.

In broad strokes here’s what I did in the past: The RBAC main facility is a Component which receives the access-control configuration, the resource configuration and the request (which identifies the current user and its role somehow). With these it has everything required for a permission-check, which can be done in a Component event (startup), the Controller (beforeFilter, the action itself), or passed to the View for permission-checking.

---

<div class="post-metadata">

### Author: ![dakota](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/dakota/32/1421_2.png) [@dakota](https://discourse.cakephp.org/u/dakota)
#### Post date: [November 26, 2019, 10:08am UTC](https://discourse.cakephp.org/t/best-way-to-create-a-custom-rbac/6914/3 "2019-11-26T10:08:25Z")

</div>

Maybe [one of these plugins](https://github.com/friendsofcake/awesome-cakephp#authentication-and-authorization) can help?
