You are here

public function NodeAuthlinkGroupContentAccessControlHandler::entityAccess in Node authorize link 8

Checks access to an operation on the entity.

Parameters

\Drupal\Core\Entity\EntityInterface $entity: The entity for which to check access.

string $operation: The operation access should be checked for. Usually one of "view", "update" or "delete".

\Drupal\Core\Session\AccountInterface $account: The user session for which to check access.

bool $return_as_object: (optional) Defaults to FALSE.

Return value

bool|\Drupal\Core\Access\AccessResultInterface The access result. Returns a boolean if $return_as_object is FALSE (this is the default) and otherwise an AccessResultInterface object. When a boolean is returned, the result of AccessInterface::isAllowed() is returned, i.e. TRUE means access is explicitly allowed, FALSE means access is either explicitly forbidden or "no opinion".

Overrides GroupContentAccessControlHandler::entityAccess

File

src/Access/NodeAuthlinkGroupContentAccessControlHandler.php, line 21

Class

NodeAuthlinkGroupContentAccessControlHandler
Class NodeAuthlinkGroupContentAccessControlHandler.

Namespace

Drupal\node_authlink\Plugin

Code

public function entityAccess(EntityInterface $entity, $operation, AccountInterface $account, $return_as_object = FALSE) {
  $authkey = \Drupal::request()
    ->get('authkey');

  // TODO: generalize to any content entity.
  if (!empty($authkey) && $entity instanceof NodeInterface) {
    if (node_authlink_check_authlink($entity, $operation, $account)) {
      return $return_as_object ? AccessResult::allowed()
        ->addCacheContexts([
        'url.query_args:authkey',
      ]) : TRUE;
    }
  }
  return parent::entityAccess($entity, $operation, $account, $return_as_object);
}