You are here

final class TeamAccessHandler in Apigee Edge 8

Access handler for Team entities.

Hierarchy

Expanded class hierarchy of TeamAccessHandler

File

modules/apigee_edge_teams/src/Entity/TeamAccessHandler.php, line 35

Namespace

Drupal\apigee_edge_teams\Entity
View source
final class TeamAccessHandler extends EntityAccessControlHandler implements EntityHandlerInterface {

  /**
   * The developer storage.
   *
   * @var \Drupal\apigee_edge\Entity\Storage\DeveloperStorageInterface
   */
  private $developerStorage;

  /**
   * TeamAccessHandler constructor.
   *
   * @param \Drupal\Core\Entity\EntityTypeInterface $entity_type
   *   The entity type definition.
   * @param \Drupal\Core\Entity\EntityTypeManagerInterface $entity_type_manager
   *   The entity type manager.
   */
  public function __construct(EntityTypeInterface $entity_type, EntityTypeManagerInterface $entity_type_manager) {
    parent::__construct($entity_type);
    $this->developerStorage = $entity_type_manager
      ->getStorage('developer');
  }

  /**
   * {@inheritdoc}
   */
  public static function createInstance(ContainerInterface $container, EntityTypeInterface $entity_type) {
    return new static($entity_type, $container
      ->get('entity_type.manager'));
  }

  /**
   * {@inheritdoc}
   */
  protected function checkAccess(EntityInterface $entity, $operation, AccountInterface $account) {

    /** @var \Drupal\Core\Access\AccessResult $result */
    $result = parent::checkAccess($entity, $operation, $account);
    if ($result
      ->isNeutral()) {
      $permissions = [
        "{$operation} any {$entity->getEntityTypeId()}",
      ];
      if ($this->entityType
        ->getAdminPermission()) {
        $permissions[] = $this->entityType
          ->getAdminPermission();
      }
      $result = AccessResult::allowedIfHasPermissions($account, $permissions, 'OR');
      if ($result
        ->isNeutral() && $operation === 'view') {
        if ($account
          ->isAuthenticated()) {

          // Grant access to the user if it is a member of the Team.
          // (Reminder, anonymous user can not be member of a team.

          /** @var \Drupal\apigee_edge\Entity\DeveloperInterface|null $developer */
          $developer = $this->developerStorage
            ->load($account
            ->getEmail());
          if ($developer && in_array($entity
            ->id(), $developer
            ->getCompanies())) {
            $result = AccessResult::allowed();

            // Ensure that access is evaluated again when the team or the
            // developer entity changes.
            $result
              ->addCacheableDependency($entity);
            $result
              ->addCacheableDependency($developer);
          }
        }
      }
    }
    return $result;
  }

  /**
   * {@inheritdoc}
   */
  protected function checkCreateAccess(AccountInterface $account, array $context, $entity_bundle = NULL) {
    $result = parent::checkCreateAccess($account, $context, $entity_bundle);
    if ($result
      ->isNeutral()) {
      $permissions = [
        "create {$this->entityType->id()}",
      ];
      if ($this->entityType
        ->getAdminPermission()) {
        $permissions[] = $this->entityType
          ->getAdminPermission();
      }
      $result = AccessResult::allowedIfHasPermissions($account, $permissions, 'OR');
    }
    return $result;
  }

}

Members

Namesort descending Modifiers Type Description Overrides
DependencySerializationTrait::$_entityStorages protected property An array of entity type IDs keyed by the property name of their storages.
DependencySerializationTrait::$_serviceIds protected property An array of service IDs keyed by property name used for serialization.
DependencySerializationTrait::__sleep public function 1
DependencySerializationTrait::__wakeup public function 2
EntityAccessControlHandler::$accessCache protected property Stores calculated access check results.
EntityAccessControlHandler::$entityType protected property Information about the entity type.
EntityAccessControlHandler::$entityTypeId protected property The entity type ID of the access control handler instance.
EntityAccessControlHandler::$viewLabelOperation protected property Allows to grant access to just the labels. 5
EntityAccessControlHandler::access public function Checks access to an operation on a given entity or entity translation. Overrides EntityAccessControlHandlerInterface::access 1
EntityAccessControlHandler::checkFieldAccess protected function Default field access as determined by this access control handler. 4
EntityAccessControlHandler::createAccess public function Checks access to create an entity. Overrides EntityAccessControlHandlerInterface::createAccess 1
EntityAccessControlHandler::fieldAccess public function Checks access to an operation on a given entity field. Overrides EntityAccessControlHandlerInterface::fieldAccess
EntityAccessControlHandler::getCache protected function Tries to retrieve a previously cached access value from the static cache.
EntityAccessControlHandler::prepareUser protected function Loads the current account object, if it does not exist yet.
EntityAccessControlHandler::processAccessHookResults protected function We grant access to the entity if both of these conditions are met:
EntityAccessControlHandler::resetCache public function Clears all cached access checks. Overrides EntityAccessControlHandlerInterface::resetCache
EntityAccessControlHandler::setCache protected function Statically caches whether the given user has access.
EntityHandlerBase::$moduleHandler protected property The module handler to invoke hooks on. 2
EntityHandlerBase::moduleHandler protected function Gets the module handler. 2
EntityHandlerBase::setModuleHandler public function Sets the module handler for this handler.
StringTranslationTrait::$stringTranslation protected property The string translation service. 1
StringTranslationTrait::formatPlural protected function Formats a string containing a count of items.
StringTranslationTrait::getNumberOfPlurals protected function Returns the number of plurals supported by a given language.
StringTranslationTrait::getStringTranslation protected function Gets the string translation service.
StringTranslationTrait::setStringTranslation public function Sets the string translation service to use. 2
StringTranslationTrait::t protected function Translates a string to the current language or to a given language.
TeamAccessHandler::$developerStorage private property The developer storage.
TeamAccessHandler::checkAccess protected function Performs access checks. Overrides EntityAccessControlHandler::checkAccess
TeamAccessHandler::checkCreateAccess protected function Performs create access checks. Overrides EntityAccessControlHandler::checkCreateAccess
TeamAccessHandler::createInstance public static function Instantiates a new instance of this entity handler. Overrides EntityHandlerInterface::createInstance
TeamAccessHandler::__construct public function TeamAccessHandler constructor. Overrides EntityAccessControlHandler::__construct