-
Notifications
You must be signed in to change notification settings - Fork 168
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Change access validation from User Information view page
- Loading branch information
1 parent
2667c3c
commit c578657
Showing
6 changed files
with
203 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10 changes: 10 additions & 0 deletions
10
modules/social_features/social_profile/config/update/social_profile_update_130004.yml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
views.view.user_information: | ||
expected_config: { } | ||
update_actions: | ||
change: | ||
display: | ||
default: | ||
display_options: | ||
access: | ||
type: profile_pages_access | ||
options: { } |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
83 changes: 83 additions & 0 deletions
83
modules/social_features/social_profile/src/Plugin/views/access/SocialProfilePagesAccess.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,83 @@ | ||
<?php | ||
|
||
namespace Drupal\social_profile\Plugin\views\access; | ||
|
||
use Drupal\Core\Entity\EntityTypeManagerInterface; | ||
use Drupal\Core\Session\AccountInterface; | ||
use Drupal\Core\Session\AccountProxyInterface; | ||
use Drupal\profile\Entity\ProfileInterface; | ||
use Drupal\profile\ProfileStorageInterface; | ||
use Drupal\views\Plugin\views\access\AccessPluginBase; | ||
use Symfony\Component\DependencyInjection\ContainerInterface; | ||
use Symfony\Component\Routing\Route; | ||
|
||
/** | ||
* Access plugin that provides access control to user information page. | ||
* | ||
* @ingroup views_access_plugins | ||
* | ||
* @ViewsAccess( | ||
* id = "profile_pages_access", | ||
* title = @Translation("Profile pages access"), | ||
* help = @Translation("Access to any profile page."), | ||
* ) | ||
*/ | ||
class SocialProfilePagesAccess extends AccessPluginBase { | ||
|
||
/** | ||
* The entity type manager. | ||
* | ||
* @var \Drupal\Core\Entity\EntityTypeManagerInterface | ||
*/ | ||
protected EntityTypeManagerInterface $entityTypeManager; | ||
|
||
/** | ||
* {@inheritdoc} | ||
*/ | ||
public function __construct(array $configuration, $plugin_id, $plugin_definition, EntityTypeManagerInterface $entity_type_manager) { | ||
parent::__construct($configuration, $plugin_id, $plugin_definition); | ||
|
||
$this->entityTypeManager = $entity_type_manager; | ||
} | ||
|
||
/** | ||
* {@inheritdoc} | ||
*/ | ||
public static function create(ContainerInterface $container, array $configuration, $plugin_id, $plugin_definition): self { | ||
return new static( | ||
$configuration, | ||
$plugin_id, | ||
$plugin_definition, | ||
$container->get('entity_type.manager') | ||
); | ||
} | ||
|
||
/** | ||
* {@inheritdoc} | ||
*/ | ||
public function access(AccountInterface $account): bool { | ||
// Get user from view context. | ||
$user = $this->view->getUser(); | ||
if (!$user instanceof AccountProxyInterface) { | ||
return FALSE; | ||
} | ||
|
||
// Load profile from user and check the access for logged user. | ||
/** @var ProfileStorageInterface $profile_storage */ | ||
$profile_storage = $this->entityTypeManager->getStorage('profile'); | ||
$profile = $profile_storage->loadByUser($user->getAccount(), 'profile'); | ||
if (!$profile instanceof ProfileInterface) { | ||
return FALSE; | ||
} | ||
|
||
return $profile->access('view', $account); | ||
} | ||
|
||
/** | ||
* {@inheritdoc} | ||
*/ | ||
public function alterRouteDefinition(Route $route): void { | ||
$route->setRequirement('_custom_access', '\Drupal\social_profile\Service\SocialProfileAccessService::access'); | ||
} | ||
|
||
} |
98 changes: 98 additions & 0 deletions
98
modules/social_features/social_profile/src/Service/SocialProfileAccessService.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,98 @@ | ||
<?php | ||
|
||
namespace Drupal\social_profile\Service; | ||
|
||
use Drupal\Core\Access\AccessResult; | ||
use Drupal\Core\Access\AccessResultInterface; | ||
use Drupal\Core\DependencyInjection\ContainerInjectionInterface; | ||
use Drupal\Core\Entity\EntityTypeManagerInterface; | ||
use Drupal\Core\Routing\RouteMatchInterface; | ||
use Drupal\Core\Session\AccountInterface; | ||
use Drupal\profile\Entity\ProfileInterface; | ||
use Drupal\profile\ProfileStorageInterface; | ||
use Drupal\user\UserInterface; | ||
use Symfony\Component\DependencyInjection\ContainerInterface; | ||
|
||
/** | ||
* Provide a service for Profile Access service. | ||
* | ||
* @package Drupal\social_profile\Service | ||
*/ | ||
class SocialProfileAccessService implements ContainerInjectionInterface { | ||
|
||
/** | ||
* The current route match. | ||
* | ||
* @var \Drupal\Core\Routing\RouteMatchInterface | ||
*/ | ||
protected RouteMatchInterface $routeMatch; | ||
|
||
/** | ||
* The entity type manager. | ||
* | ||
* @var \Drupal\Core\Entity\EntityTypeManagerInterface | ||
*/ | ||
protected EntityTypeManagerInterface $entityTypeManager; | ||
|
||
/** | ||
* SocialProfileAccessService constructor. | ||
* | ||
* @param \Drupal\Core\Routing\RouteMatchInterface $route_match | ||
* The current route match. | ||
* @param \Drupal\Core\Entity\EntityTypeManagerInterface $entity_type_manager | ||
* The entity type manager. | ||
*/ | ||
public function __construct(RouteMatchInterface $route_match, EntityTypeManagerInterface $entity_type_manager) { | ||
$this->routeMatch = $route_match; | ||
$this->entityTypeManager = $entity_type_manager; | ||
} | ||
|
||
/** | ||
* {@inheritdoc} | ||
*/ | ||
public static function create(ContainerInterface $container): self { | ||
return new static( | ||
$container->get('current_route_match'), | ||
$container->get('entity_type.manager') | ||
); | ||
} | ||
|
||
/** | ||
* Validation permission for profile pages. | ||
* | ||
* @param \Drupal\Core\Session\AccountInterface $account | ||
* Logged user. | ||
* | ||
* @return \Drupal\Core\Access\AccessResultInterface | ||
* Return TRUE when user has access. | ||
* | ||
* @throws \Drupal\Component\Plugin\Exception\InvalidPluginDefinitionException | ||
* @throws \Drupal\Component\Plugin\Exception\PluginNotFoundException | ||
*/ | ||
public function access(AccountInterface $account): AccessResultInterface { | ||
// Load the user entity. | ||
$user_id = $this->routeMatch->getRawParameter('user'); | ||
$user = $this->entityTypeManager | ||
->getStorage('user') | ||
->load($user_id); | ||
if (!$user instanceof UserInterface) { | ||
return AccessResult::forbidden(); | ||
} | ||
|
||
// If user is blocked, check special permission. | ||
if ($user->isBlocked()) { | ||
return AccessResult::allowedIfHasPermissions($account, ['view blocked user']); | ||
} | ||
|
||
// Load the profile to check access. | ||
/** @var ProfileStorageInterface $profile_storage */ | ||
$profile_storage = $this->entityTypeManager->getStorage('profile'); | ||
$profile = $profile_storage->loadByUser($user, 'profile'); | ||
if (!$profile instanceof ProfileInterface) { | ||
return AccessResult::forbidden(); | ||
} | ||
|
||
return $profile->access('view', $account, TRUE); | ||
} | ||
|
||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters