# Fill roles\[\] (UserInterface) after authenticate (oauth2)

**URL:** <https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546>\
**Category:** Mezzio\
**Tags:** mezzio-authorization, mezzio-authentication\
**Created:** [October 15, 2021, 6:27pm UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546 "2021-10-15T18:27:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [October 15, 2021, 6:27pm UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/1 "2021-10-15T18:27:53Z")

</div>

Hi all,

mezzio-authentication return a DefaultUser immutable for security reasons. I use it with mezzio-authentication-oauth2 and oauth2 do not use the roles[] attribute (UserInterface) but i need it to use mezzio-authorization-rbac or mezzio-authorization-acl to protect my api routes.

Because DefaultUser is immutable i cannot create my own middleware to alter the current psr-7 DefaultUser (db request to find the role of the identity and fill the roles[] attribute) just after Authentication\AuthenticationMiddleware::class in my route.

I’m stuck on it… How can i proceed in my case?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [October 20, 2021, 10:05am UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/2 "2021-10-20T10:05:52Z")

</div>

maybe @matthew, @froschdesign or someone else can give me a advice with my problematic above? The goal is to use the default authorization modules provided with mezzio and to not reinvent the wheel. Thanks!

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [October 20, 2021, 10:26am UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/3 "2021-10-20T10:26:20Z")

</div>

> [@MichaelB](#):
>
> Because DefaultUser is immutable i cannot create my own middleware to alter the current psr-7 DefaultUser (db request to find the role of the identity and fill the roles attribute)…

Why do you want to change the `Mezzio\Authentication\DefaultUser::class`? Set everything on creation.

---

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [October 20, 2021, 11:37am UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/4 "2021-10-20T11:37:01Z")

</div>

Thanks for your answer @froschdesign. I probably miss or not understand something but in OAuth2Adapter.php (mezzio-authentication-oauth2) the roles attribute is not filled by default in authenticate method (line 65).

```auto
return ($this->userFactory)(
                    $userId,
                    [], <---- HERE
                    [
                        'oauth_user_id' => $userId,
                        'oauth_client_id' => $clientId,
                        'oauth_access_token_id' => $result->getAttribute('oauth_access_token_id', null),
                        'oauth_scopes' => $result->getAttribute('oauth_scopes', null)
                    ]
                );

```

The documentation confirm this behavior. That’s ok because oauth2 do not use role.

**The `getRoles()` method of the user instance always returns an empty array.** (found in the docs)

But `Mezzio\Authentication\DefaultUser::class` is created here and i cannot alter this class later because is immutable. Right? My idea was to add a new middleware after `Authentication\AuthenticationMiddleware::class` in my routes to alter the DefaultUser::class and fill the roles array from a database request.

Am I completely wrong?

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [October 20, 2021, 11:47am UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/5 "2021-10-20T11:47:29Z")

</div>

> [@MichaelB](#):
>
> **The `getRoles()` method of the user instance always returns an empty array.** (found in the docs)

And right below you will find the following section: “[Customize the user instance](https://docs.mezzio.dev/mezzio-authentication-oauth2/v1/authenticated-user/#customize-the-user-instance)”  
Which means to replace the default user entity with your own implementation.

---

<div class="post-metadata">

**Author:** ![MichaelB](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@MichaelB](https://discourse.laminas.dev/u/MichaelB)\
**Post date:** [October 20, 2021, 12:07pm UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/6 "2021-10-20T12:07:37Z")

</div>

Don’t know why i haven’t seen this… 😅. Sorry and thank you @froschdesign !

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [October 20, 2021, 12:15pm UTC](https://discourse.laminas.dev/t/fill-roles-userinterface-after-authenticate-oauth2/2546/7 "2021-10-20T12:15:32Z")

</div>

Thanks for the feedback and I hope it works for you now!
