You are here

class OgAccess in Organic groups 8

The service that determines if users have access to groups and group content.


Expanded class hierarchy of OgAccess

11 files declare their use of OgAccess
GroupLevelAccessTest.php in tests/src/Kernel/Access/GroupLevelAccessTest.php
og.api.php in ./og.api.php
OgAccessTestBase.php in tests/src/Unit/OgAccessTestBase.php
OgAdminRoutesEvent.php in src/Event/OgAdminRoutesEvent.php
OgEventSubscriber.php in src/EventSubscriber/OgEventSubscriber.php

... See full list

1 string reference to 'OgAccess' in ./
1 service uses OgAccess
og.access in ./


src/OgAccess.php, line 24


View source
class OgAccess implements OgAccessInterface {

   * Group level permission that grants full access to the group.
   * Not to be confused with the 'administer organic groups' global permission
   * which is intended for site builders and gives full access to _all_ groups.
  const ADMINISTER_GROUP_PERMISSION = 'administer group';

   * Group level permission that allows the user to delete the group entity.
  const DELETE_GROUP_PERMISSION = 'delete group';

   * Group level permission that allows the user to update the group entity.
  const UPDATE_GROUP_PERMISSION = 'update group';

   * Maps entity operations performed on groups to group level permissions.
    'delete' => self::DELETE_GROUP_PERMISSION,
    'update' => self::UPDATE_GROUP_PERMISSION,

   * The config factory.
   * @var \Drupal\Core\Config\ConfigFactoryInterface
  protected $configFactory;

   * The service that contains the current active user.
   * @var \Drupal\Core\Session\AccountProxyInterface
  protected $accountProxy;

   * The module handler.
   * @var \Drupal\Core\Extension\ModuleHandlerInterface
  protected $moduleHandler;

   * The group manager.
   * @var \Drupal\og\GroupTypeManagerInterface
  protected $groupTypeManager;

   * The OG permission manager.
   * @var \Drupal\og\PermissionManagerInterface
  protected $permissionManager;

   * The group membership manager.
   * @var \Drupal\og\MembershipManagerInterface
  protected $membershipManager;

   * The event dispatcher.
   * @var \Symfony\Component\EventDispatcher\EventDispatcherInterface
  protected $dispatcher;

   * Constructs the OgAccess service.
   * @param \Drupal\Core\Config\ConfigFactoryInterface $config_factory
   *   The config factory.
   * @param \Drupal\Core\Session\AccountProxyInterface $account_proxy
   *   The service that contains the current active user.
   * @param \Drupal\Core\Extension\ModuleHandlerInterface $module_handler
   *   The module handler.
   * @param \Drupal\og\GroupTypeManagerInterface $group_manager
   *   The group manager.
   * @param \Drupal\og\PermissionManagerInterface $permission_manager
   *   The permission manager.
   * @param \Drupal\og\MembershipManagerInterface $membership_manager
   *   The group membership manager.
   * @param \Symfony\Component\EventDispatcher\EventDispatcherInterface $dispatcher
   *   The event dispatcher.
  public function __construct(ConfigFactoryInterface $config_factory, AccountProxyInterface $account_proxy, ModuleHandlerInterface $module_handler, GroupTypeManagerInterface $group_manager, PermissionManagerInterface $permission_manager, MembershipManagerInterface $membership_manager, EventDispatcherInterface $dispatcher) {
    $this->configFactory = $config_factory;
    $this->accountProxy = $account_proxy;
    $this->moduleHandler = $module_handler;
    $this->groupTypeManager = $group_manager;
    $this->permissionManager = $permission_manager;
    $this->membershipManager = $membership_manager;
    $this->dispatcher = $dispatcher;

   * {@inheritdoc}
  public function userAccess(EntityInterface $group, string $permission, ?AccountInterface $user = NULL, bool $skip_alter = FALSE) : AccessResultInterface {
    $group_type_id = $group
    $bundle = $group

    // As Og::isGroup depends on this config, we retrieve it here and set it as
    // the minimal caching data.
    $config = $this->configFactory
    $cacheable_metadata = (new CacheableMetadata())
    if (!$this->groupTypeManager
      ->isGroup($group_type_id, $bundle)) {

      // Not a group.
      return AccessResult::neutral()
    if (!isset($user)) {
      $user = $this->accountProxy

    // From this point on, every result also depends on the user so check
    // whether it is the current. See
    // @todo This doesn't really vary by user but by the user's roles inside of
    //   the group. We should create a cache context for OgRole entities.
    // @see
    if ($user
      ->id() == $this->accountProxy
      ->id()) {

    // User ID 1 has all privileges.
    if ($user
      ->id() == 1) {
      return AccessResult::allowed()

    // Check if the user has a global permission to administer all groups. This
    // gives full access.
    $user_access = AccessResult::allowedIfHasPermission($user, 'administer organic groups');
    if ($user_access
      ->isAllowed()) {
      return $user_access
    if ($config
      ->get('group_manager_full_access') && $user
      ->isAuthenticated() && $group instanceof EntityOwnerInterface) {
      if ($group
        ->getOwnerId() == $user
        ->id()) {
        return AccessResult::allowed()
    $permissions = [];
    $user_is_group_admin = FALSE;
    if ($membership = $this->membershipManager
      ->getMembership($group, $user
      ->id())) {
      foreach ($membership
        ->getRoles() as $role) {

        // Check for the is_admin flag.
        if ($role
          ->isAdmin()) {
          $user_is_group_admin = TRUE;
        $permissions = array_merge($permissions, $role
    elseif (!$this->membershipManager
      ->isMember($group, $user
      ->id(), [
    ])) {

      // User is a non-member or has a pending membership.

      /** @var \Drupal\og\Entity\OgRole $role */
      $role = OgRole::loadByGroupAndName($group, OgRoleInterface::ANONYMOUS);
      $permissions = $role
    $permissions = array_unique($permissions);
    if (!$skip_alter && !in_array($permission, $permissions)) {

      // Let modules alter the permissions.
      $context = [
        'permission' => $permission,
        'group' => $group,
        'user' => $user,
        ->alter('og_user_access', $permissions, $cacheable_metadata, $context);

    // Check if the user is a group admin and who has access to all the group
    // permissions.
    // @todo It should be possible for modules to alter the permissions even if
    //   the user is a group admin, UID 1 or has 'administer group' permission.
    if ($user_is_group_admin || in_array($permission, $permissions)) {

      // User is a group admin, and we do not ignore this special permission
      // that grants access to all the group permissions.
      return AccessResult::allowed()
    return AccessResult::neutral()

   * {@inheritdoc}
  public function userAccessEntity(string $permission, EntityInterface $entity, ?AccountInterface $user = NULL) : AccessResultInterface {
    $result = AccessResult::neutral();
    $entity_type = $entity
    $entity_type_id = $entity_type
    $bundle = $entity
    if ($this->groupTypeManager
      ->isGroup($entity_type_id, $bundle)) {

      // An entity can be a group and group content in the same time. If the
      // group returns a neutral result the user still might have access to
      // the permission in group content context. So if we get a neutral result
      // we will continue with the group content access check below.
      $result = $this
        ->userAccess($entity, $permission, $user);
      if (!$result
        ->isNeutral()) {
        return $result;
    if ($this->groupTypeManager
      ->isGroupContent($entity_type_id, $bundle)) {

      // The entity might be a user or a non-user entity.
      $groups = $entity instanceof UserInterface ? $this->membershipManager
        ->id()) : $this->membershipManager
      if ($groups) {
        foreach ($groups as $entity_groups) {
          foreach ($entity_groups as $group) {
            $result = $result
              ->userAccess($group, $permission, $user));
    return $result;

   * {@inheritdoc}
  public function userAccessEntityOperation(string $operation, EntityInterface $entity, ?AccountInterface $user = NULL) : AccessResultInterface {
    $result = AccessResult::neutral();
    $entity_type = $entity
    $entity_type_id = $entity_type
    $bundle = $entity
    if ($this->groupTypeManager
      ->isGroup($entity_type_id, $bundle)) {

      // We are performing an entity operation on a group entity. Map the
      // operation to the corresponding group level permission.
      if (array_key_exists($operation, self::OPERATION_GROUP_PERMISSION_MAPPING)) {
        $permission = self::OPERATION_GROUP_PERMISSION_MAPPING[$operation];

        // An entity can be a group and group content in the same time. If the
        // group returns a neutral result the user still might have access to
        // the permission in group content context. So if we get a neutral
        // result we will continue with the group content access check below.
        $result = $this
          ->userAccess($entity, $permission, $user);
        if (!$result
          ->isNeutral()) {
          return $result;
    if ($this->groupTypeManager
      ->isGroupContent($entity_type_id, $bundle)) {

      // The entity might be a user or a non-user entity.
      $groups = $entity instanceof UserInterface ? $this->membershipManager
        ->id()) : $this->membershipManager
      if ($groups) {
        foreach ($groups as $entity_groups) {
          foreach ($entity_groups as $group) {
            $result = $result
              ->userAccessGroupContentEntityOperation($operation, $group, $entity, $user));
    return $result;

   * {@inheritdoc}
  public function userAccessGroupContentEntityOperation(string $operation, EntityInterface $group_entity, EntityInterface $group_content_entity, ?AccountInterface $user = NULL) : AccessResultInterface {

    // Default to the current user.
    $user = $user ?: $this->accountProxy
    $event = new GroupContentEntityOperationAccessEvent($operation, $group_entity, $group_content_entity, $user);

    // @todo This doesn't really vary by user but by the user's roles inside of
    //   the group. We should create a cache context for OgRole entities.
    // @see
    if ($user
      ->id() == $this->accountProxy
      ->id()) {
      ->dispatch(GroupContentEntityOperationAccessEvent::EVENT_NAME, $event);
    return $event

   * {@inheritdoc}
  public function reset() : void {
    trigger_error('OgAccessInterface::reset() is deprecated in og:8.1.0-alpha6 and is removed from og:8.1.0-beta1. The static cache has been removed and this method no longer serves any purpose. Any calls to this method can safely be removed. See', E_USER_DEPRECATED);



Namesort descending Modifiers Type Description Overrides
OgAccess::$accountProxy protected property The service that contains the current active user.
OgAccess::$configFactory protected property The config factory.
OgAccess::$dispatcher protected property The event dispatcher.
OgAccess::$groupTypeManager protected property The group manager.
OgAccess::$membershipManager protected property The group membership manager.
OgAccess::$moduleHandler protected property The module handler.
OgAccess::$permissionManager protected property The OG permission manager.
OgAccess::ADMINISTER_GROUP_PERMISSION constant Group level permission that grants full access to the group.
OgAccess::DELETE_GROUP_PERMISSION constant Group level permission that allows the user to delete the group entity.
OgAccess::OPERATION_GROUP_PERMISSION_MAPPING constant Maps entity operations performed on groups to group level permissions.
OgAccess::reset public function Resets the static cache. Overrides OgAccessInterface::reset
OgAccess::UPDATE_GROUP_PERMISSION constant Group level permission that allows the user to update the group entity.
OgAccess::userAccess public function Determines whether a user has a group permission in a given group. Overrides OgAccessInterface::userAccess
OgAccess::userAccessEntity public function Determines whether a user has a group permission in a given entity. Overrides OgAccessInterface::userAccessEntity
OgAccess::userAccessEntityOperation public function Checks whether a user can perform an operation on a given entity. Overrides OgAccessInterface::userAccessEntityOperation
OgAccess::userAccessGroupContentEntityOperation public function Checks access for entity operations on group content in a specific group. Overrides OgAccessInterface::userAccessGroupContentEntityOperation
OgAccess::__construct public function Constructs the OgAccess service.