UserAccessControlHandler.php in Drupal 10        
                          
                  
                        
  
  
  
  
File
  core/modules/user/src/UserAccessControlHandler.php
  
    View source  
  <?php
namespace Drupal\user;
use Drupal\Core\Access\AccessResult;
use Drupal\Core\Access\AccessResultNeutral;
use Drupal\Core\Access\AccessResultReasonInterface;
use Drupal\Core\Entity\EntityInterface;
use Drupal\Core\Entity\EntityAccessControlHandler;
use Drupal\Core\Field\FieldDefinitionInterface;
use Drupal\Core\Field\FieldItemListInterface;
use Drupal\Core\Session\AccountInterface;
class UserAccessControlHandler extends EntityAccessControlHandler {
  
  protected $viewLabelOperation = TRUE;
  
  protected function checkAccess(EntityInterface $entity, $operation, AccountInterface $account) {
    
    
    if ($operation === 'view label') {
      return AccessResult::allowed();
    }
    
    if ($entity
      ->isAnonymous()) {
      return AccessResult::forbidden();
    }
    
    if ($account
      ->hasPermission('administer users')) {
      return AccessResult::allowed()
        ->cachePerPermissions();
    }
    switch ($operation) {
      case 'view':
        
        if ($account
          ->hasPermission('access user profiles') && $entity
          ->isActive()) {
          return AccessResult::allowed()
            ->cachePerPermissions()
            ->addCacheableDependency($entity);
        }
        elseif ($account
          ->id() == $entity
          ->id()) {
          return AccessResult::allowed()
            ->cachePerUser();
        }
        else {
          return AccessResultNeutral::neutral("The 'access user profiles' permission is required and the user must be active.")
            ->cachePerPermissions()
            ->addCacheableDependency($entity);
        }
        break;
      case 'update':
        
        $access_result = AccessResult::allowedIf($account
          ->id() == $entity
          ->id())
          ->cachePerUser();
        if (!$access_result
          ->isAllowed() && $access_result instanceof AccessResultReasonInterface) {
          $access_result
            ->setReason("Users can only update their own account, unless they have the 'administer users' permission.");
        }
        return $access_result;
      case 'delete':
        
        return AccessResult::allowedIfHasPermission($account, 'cancel account')
          ->andIf(AccessResult::allowedIf($account
          ->id() == $entity
          ->id())
          ->cachePerUser());
    }
    
    return AccessResult::neutral();
  }
  
  protected function checkFieldAccess($operation, FieldDefinitionInterface $field_definition, AccountInterface $account, FieldItemListInterface $items = NULL) {
    
    $explicit_check_fields = [
      'pass',
    ];
    
    if (!in_array($field_definition
      ->getName(), $explicit_check_fields) && $account
      ->hasPermission('administer users')) {
      return AccessResult::allowed()
        ->cachePerPermissions();
    }
    
    $is_own_account = $items ? $items
      ->getEntity()
      ->id() == $account
      ->id() : FALSE;
    switch ($field_definition
      ->getName()) {
      case 'name':
        
        if ($operation == 'view' || $items && $items
          ->getEntity()
          ->isAnonymous()) {
          return AccessResult::allowed()
            ->cachePerPermissions();
        }
        
        if ($is_own_account && $account
          ->hasPermission('change own username')) {
          return AccessResult::allowed()
            ->cachePerPermissions()
            ->cachePerUser();
        }
        else {
          return AccessResult::neutral();
        }
      case 'mail':
        
        if ($operation == 'view' && $account
          ->hasPermission('view user email addresses')) {
          return AccessResult::allowed()
            ->cachePerPermissions();
        }
      case 'preferred_langcode':
      case 'preferred_admin_langcode':
      case 'timezone':
        
        if ($operation == 'view') {
          return AccessResult::allowedIf($is_own_account)
            ->cachePerUser();
        }
        
        return AccessResult::allowed()
          ->cachePerPermissions();
      case 'pass':
        
        return $operation == 'edit' ? AccessResult::allowed() : AccessResult::forbidden();
      case 'created':
        
        return $operation == 'view' ? AccessResult::allowed() : AccessResult::neutral();
      case 'roles':
      case 'status':
      case 'access':
      case 'login':
      case 'init':
        return AccessResult::neutral();
    }
    return parent::checkFieldAccess($operation, $field_definition, $account, $items);
  }
}