UserAccessControlHandler.php in Drupal 10
File
core/modules/user/src/UserAccessControlHandler.php
View source
<?php
namespace Drupal\user;
use Drupal\Core\Access\AccessResult;
use Drupal\Core\Access\AccessResultNeutral;
use Drupal\Core\Access\AccessResultReasonInterface;
use Drupal\Core\Entity\EntityInterface;
use Drupal\Core\Entity\EntityAccessControlHandler;
use Drupal\Core\Field\FieldDefinitionInterface;
use Drupal\Core\Field\FieldItemListInterface;
use Drupal\Core\Session\AccountInterface;
class UserAccessControlHandler extends EntityAccessControlHandler {
protected $viewLabelOperation = TRUE;
protected function checkAccess(EntityInterface $entity, $operation, AccountInterface $account) {
if ($operation === 'view label') {
return AccessResult::allowed();
}
if ($entity
->isAnonymous()) {
return AccessResult::forbidden();
}
if ($account
->hasPermission('administer users')) {
return AccessResult::allowed()
->cachePerPermissions();
}
switch ($operation) {
case 'view':
if ($account
->hasPermission('access user profiles') && $entity
->isActive()) {
return AccessResult::allowed()
->cachePerPermissions()
->addCacheableDependency($entity);
}
elseif ($account
->id() == $entity
->id()) {
return AccessResult::allowed()
->cachePerUser();
}
else {
return AccessResultNeutral::neutral("The 'access user profiles' permission is required and the user must be active.")
->cachePerPermissions()
->addCacheableDependency($entity);
}
break;
case 'update':
$access_result = AccessResult::allowedIf($account
->id() == $entity
->id())
->cachePerUser();
if (!$access_result
->isAllowed() && $access_result instanceof AccessResultReasonInterface) {
$access_result
->setReason("Users can only update their own account, unless they have the 'administer users' permission.");
}
return $access_result;
case 'delete':
return AccessResult::allowedIfHasPermission($account, 'cancel account')
->andIf(AccessResult::allowedIf($account
->id() == $entity
->id())
->cachePerUser());
}
return AccessResult::neutral();
}
protected function checkFieldAccess($operation, FieldDefinitionInterface $field_definition, AccountInterface $account, FieldItemListInterface $items = NULL) {
$explicit_check_fields = [
'pass',
];
if (!in_array($field_definition
->getName(), $explicit_check_fields) && $account
->hasPermission('administer users')) {
return AccessResult::allowed()
->cachePerPermissions();
}
$is_own_account = $items ? $items
->getEntity()
->id() == $account
->id() : FALSE;
switch ($field_definition
->getName()) {
case 'name':
if ($operation == 'view' || $items && $items
->getEntity()
->isAnonymous()) {
return AccessResult::allowed()
->cachePerPermissions();
}
if ($is_own_account && $account
->hasPermission('change own username')) {
return AccessResult::allowed()
->cachePerPermissions()
->cachePerUser();
}
else {
return AccessResult::neutral();
}
case 'mail':
if ($operation == 'view' && $account
->hasPermission('view user email addresses')) {
return AccessResult::allowed()
->cachePerPermissions();
}
case 'preferred_langcode':
case 'preferred_admin_langcode':
case 'timezone':
if ($operation == 'view') {
return AccessResult::allowedIf($is_own_account)
->cachePerUser();
}
return AccessResult::allowed()
->cachePerPermissions();
case 'pass':
return $operation == 'edit' ? AccessResult::allowed() : AccessResult::forbidden();
case 'created':
return $operation == 'view' ? AccessResult::allowed() : AccessResult::neutral();
case 'roles':
case 'status':
case 'access':
case 'login':
case 'init':
return AccessResult::neutral();
}
return parent::checkFieldAccess($operation, $field_definition, $account, $items);
}
}