// src/Security/PostVoter.php
namespace App\Security;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Authorization\Voter\Voter;
class OrganisationVoter extends Voter
// these strings are just invented: you can use anything
const READ= 'READ';
const EDIT = 'EDIT ';
protected function supports($attribute, $subject); bool //todo
protected function voteOnAttribute($attribute, $subject, TokenInterface $token)
// [...] check class like documentation
$organisation= $subject;
switch ($attribute) {
case self::READ:
return $this->canView($organisation, $user);
case self::EDIT:
return $this->canEdit($organisation, $user);
private function canView(Organisation $organisation, User $user)
//here your logic if your user has the same organisation
private function canEdit(Organisation $organisation, User $user)
//here your logic if your user has the same organisation than the one in parameter and the good level of right (admin, root)
if ($this->security->isGranted(OrganisationVoter::EDIT, $organisation)) {
return true;