You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CodeIgniter中通过Ion Auth实现会员子账户继承权限功能?

Hey there! Let's work through the optimal way to add sub-account functionality where child accounts inherit all parent privileges, building on your existing Ion Auth setup. This plan keeps changes minimal to your current system while meeting all your requirements:

1. Minimal Database Schema Tweaks

Since you're using a modified Ion Auth users table, we just need to add a couple of fields to link parent and child accounts:

  • Add parent_user_id (INT, nullable, foreign key referencing users.id): This marks which main account the sub-account belongs to. Set to NULL for primary accounts.
  • Optional (but helpful): Add is_sub_account (TINYINT, default 0): A quick flag to distinguish primary vs sub-accounts for faster queries.

You can run this SQL (adjust table prefix if needed):

ALTER TABLE `users` 
ADD COLUMN `parent_user_id` INT NULL AFTER `group_id`,
ADD CONSTRAINT `fk_user_parent` FOREIGN KEY (`parent_user_id`) REFERENCES `users`(`id`) ON DELETE CASCADE;

-- Optional flag for quick filtering
ALTER TABLE `users` ADD COLUMN `is_sub_account` TINYINT(1) NOT NULL DEFAULT 0 AFTER `parent_user_id`;
2. Sub-Account Creation Workflow

Keep your existing primary account registration (package selection → form → payment) intact. For sub-accounts, build a separate flow tied to the primary user's dashboard:

  • Entry Point: Add a "Create Sub-Account" button in the regular member's user dashboard. Restrict this button to users with parent_user_id = NULL (primary accounts) only.
  • Simplified Form: Skip the package selection step entirely. The form only needs essential fields: email/username, password, display name (no package dropdown).
  • Backend Logic: When the form submits:
    1. Grab the currently logged-in user's ID (the parent)
    2. Use Ion Auth's create_user() method, but override/set parent_user_id to the parent's ID, and is_sub_account = 1 (if using the flag)
    3. Assign the sub-account to the same user group as the parent (since they inherit all privileges)

Example code snippet (PHP, assuming CodeIgniter/Ion Auth setup):

// In your user controller
public function create_sub_account() {
    // Only primary members can create sub-accounts
    if (!$this->ion_auth->logged_in() || $this->ion_auth->user()->row()->parent_user_id !== NULL) {
        redirect('dashboard');
    }

    $parent_id = $this->ion_auth->user()->row()->id;
    $data = [
        'email' => $this->input->post('email'),
        'username' => $this->input->post('username'),
        'password' => $this->input->post('password'),
        'parent_user_id' => $parent_id,
        'is_sub_account' => 1,
        // Inherit parent's user group
        'group_id' => $this->ion_auth->get_users_groups($parent_id)->row()->id
    ];

    $this->ion_auth->create_user($data);
    // Redirect to sub-account list or show success message
}
3. Privilege Inheritance Implementation

The key here is to make sure sub-accounts pull their privileges from the parent account, not their own:

  • Override Permission Checks: Modify your existing functions that check user packages/privileges to first check if the user is a sub-account. If yes, use the parent's package data instead.

Example for package validation:

function get_user_active_package($user_id) {
    $user = $this->ion_auth->user($user_id)->row();
    
    // If it's a sub-account, fetch parent's package
    if ($user->parent_user_id) {
        $parent = $this->ion_auth->user($user->parent_user_id)->row();
        return $this->packages_model->get_active_package($parent->id);
    }
    
    // Primary account uses their own package
    return $this->packages_model->get_active_package($user_id);
}
  • Real-Time Sync: Don't cache the parent's package status for sub-accounts. This ensures if the parent's package expires or changes, the sub-account's privileges update immediately.
4. Compatibility with Existing Registration

No changes needed here! Your primary account flow (select package → form → payment) stays exactly as is. The sub-account flow is a separate, optional feature only accessible to logged-in primary members.

5. Management Enhancements
  • Primary Member Controls: Let primary users view, edit, or delete their own sub-accounts from their dashboard. Add a "My Sub-Accounts" page that lists all accounts linked to their parent_user_id.
  • Admin/Editor Controls: Extend your admin panel to show a hierarchy view (primary accounts → sub-accounts) so admins can manage all accounts. Add filters to sort by primary/sub-account status.
  • Sub-Account Dashboard: When a sub-account logs in, show a note like "You are accessing this account as a sub-user of [Parent Name]" and restrict them from creating their own sub-accounts.
6. Security & Limits
  • Sub-Account Quantity Limits: If you want to tie sub-account counts to packages, add a max_sub_accounts field to your packages table. When a primary user tries to create a sub-account, check if they've reached their limit:
    $parent_package = $this->packages_model->get_active_package($parent_id);
    $sub_account_count = $this->db->where('parent_user_id', $parent_id)->count_all_results('users');
    
    if ($sub_account_count >= $parent_package->max_sub_accounts) {
        // Show error: "You've reached your sub-account limit for this package"
    }
    
  • Prevent Self-Modification: Ensure sub-accounts can't change their parent_user_id or upgrade/downgrade their own package (all changes must come from the parent or admin).
  • Logging: Add logs for sub-account creation/deletion, linked to the parent account's ID, for auditing purposes.

This approach is optimal because it leverages your existing Ion Auth setup with minimal changes, keeps the user experience intuitive, and ensures seamless privilege inheritance.

内容的提问来源于stack exchange,提问作者simba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:55:55