如何在CodeIgniter中通过Ion Auth实现会员子账户继承权限功能?
Hey there! Let's work through the optimal way to add sub-account functionality where child accounts inherit all parent privileges, building on your existing Ion Auth setup. This plan keeps changes minimal to your current system while meeting all your requirements:
Since you're using a modified Ion Auth users table, we just need to add a couple of fields to link parent and child accounts:
- Add
parent_user_id(INT, nullable, foreign key referencingusers.id): This marks which main account the sub-account belongs to. Set toNULLfor primary accounts. - Optional (but helpful): Add
is_sub_account(TINYINT, default 0): A quick flag to distinguish primary vs sub-accounts for faster queries.
You can run this SQL (adjust table prefix if needed):
ALTER TABLE `users` ADD COLUMN `parent_user_id` INT NULL AFTER `group_id`, ADD CONSTRAINT `fk_user_parent` FOREIGN KEY (`parent_user_id`) REFERENCES `users`(`id`) ON DELETE CASCADE; -- Optional flag for quick filtering ALTER TABLE `users` ADD COLUMN `is_sub_account` TINYINT(1) NOT NULL DEFAULT 0 AFTER `parent_user_id`;
Keep your existing primary account registration (package selection → form → payment) intact. For sub-accounts, build a separate flow tied to the primary user's dashboard:
- Entry Point: Add a "Create Sub-Account" button in the regular member's user dashboard. Restrict this button to users with
parent_user_id = NULL(primary accounts) only. - Simplified Form: Skip the package selection step entirely. The form only needs essential fields: email/username, password, display name (no package dropdown).
- Backend Logic: When the form submits:
- Grab the currently logged-in user's ID (the parent)
- Use Ion Auth's
create_user()method, but override/setparent_user_idto the parent's ID, andis_sub_account = 1(if using the flag) - Assign the sub-account to the same user group as the parent (since they inherit all privileges)
Example code snippet (PHP, assuming CodeIgniter/Ion Auth setup):
// In your user controller public function create_sub_account() { // Only primary members can create sub-accounts if (!$this->ion_auth->logged_in() || $this->ion_auth->user()->row()->parent_user_id !== NULL) { redirect('dashboard'); } $parent_id = $this->ion_auth->user()->row()->id; $data = [ 'email' => $this->input->post('email'), 'username' => $this->input->post('username'), 'password' => $this->input->post('password'), 'parent_user_id' => $parent_id, 'is_sub_account' => 1, // Inherit parent's user group 'group_id' => $this->ion_auth->get_users_groups($parent_id)->row()->id ]; $this->ion_auth->create_user($data); // Redirect to sub-account list or show success message }
The key here is to make sure sub-accounts pull their privileges from the parent account, not their own:
- Override Permission Checks: Modify your existing functions that check user packages/privileges to first check if the user is a sub-account. If yes, use the parent's package data instead.
Example for package validation:
function get_user_active_package($user_id) { $user = $this->ion_auth->user($user_id)->row(); // If it's a sub-account, fetch parent's package if ($user->parent_user_id) { $parent = $this->ion_auth->user($user->parent_user_id)->row(); return $this->packages_model->get_active_package($parent->id); } // Primary account uses their own package return $this->packages_model->get_active_package($user_id); }
- Real-Time Sync: Don't cache the parent's package status for sub-accounts. This ensures if the parent's package expires or changes, the sub-account's privileges update immediately.
No changes needed here! Your primary account flow (select package → form → payment) stays exactly as is. The sub-account flow is a separate, optional feature only accessible to logged-in primary members.
- Primary Member Controls: Let primary users view, edit, or delete their own sub-accounts from their dashboard. Add a "My Sub-Accounts" page that lists all accounts linked to their
parent_user_id. - Admin/Editor Controls: Extend your admin panel to show a hierarchy view (primary accounts → sub-accounts) so admins can manage all accounts. Add filters to sort by primary/sub-account status.
- Sub-Account Dashboard: When a sub-account logs in, show a note like "You are accessing this account as a sub-user of [Parent Name]" and restrict them from creating their own sub-accounts.
- Sub-Account Quantity Limits: If you want to tie sub-account counts to packages, add a
max_sub_accountsfield to yourpackagestable. When a primary user tries to create a sub-account, check if they've reached their limit:$parent_package = $this->packages_model->get_active_package($parent_id); $sub_account_count = $this->db->where('parent_user_id', $parent_id)->count_all_results('users'); if ($sub_account_count >= $parent_package->max_sub_accounts) { // Show error: "You've reached your sub-account limit for this package" } - Prevent Self-Modification: Ensure sub-accounts can't change their
parent_user_idor upgrade/downgrade their own package (all changes must come from the parent or admin). - Logging: Add logs for sub-account creation/deletion, linked to the parent account's ID, for auditing purposes.
This approach is optimal because it leverages your existing Ion Auth setup with minimal changes, keeps the user experience intuitive, and ensures seamless privilege inheritance.
内容的提问来源于stack exchange,提问作者simba

