[ //使用ComopositeAuth混合认证 'class' => CompositeAuth::className(), 'optional' => [ 'info',//无需access-token的action ], 'authMethods' => [ HttpBasicAuth::className(), HttpBearerAuth::className(), [ 'class' => QueryParamAuth::className(), 'tokenParam' => 'access-token', ] ] ], 'verbs' => [ 'class' => VerbFilter::className(), 'actions' => [ 'info' => ['GET'], ], ], ]); } public function actionInfo(){ return ["我是user无需token可以访问的info"]; } }