diff --git a/core/includes/entity.api.php b/core/includes/entity.api.php index 190658b..d385088 100644 --- a/core/includes/entity.api.php +++ b/core/includes/entity.api.php @@ -540,6 +540,9 @@ function hook_entity_field_access($operation, $field, $account) { /** * Alters the default access behaviour for a given field. * + * Use this hook to override access grants from another module. Note that the + * default access flag is masked under the umbrella of the system module. + * * @param array $grants * An array of grants gathered by hook_entity_field_access(). The array is * keyed by the module that defines the field's access control; the values are @@ -554,7 +557,11 @@ function hook_entity_field_access($operation, $field, $account) { function hook_entity_field_access_alter(array &$grants, array $context) { $field = $context['field']; if ($field->getName() == 'field_of_interest' && $grants['node'] === FALSE) { - // Override node module's restriction to no opinion. + // Override node module's restriction to no opinion. We don't want to + // provide our own access hook, we only want to take out node module's part + // in the access handling of this field. We also don't want to switch node + // module's grant to TRUE, because the grants of other modules should still + // decide on their own if this field is accessible or not. $grants['node'] = NULL; } } diff --git a/core/lib/Drupal/Core/Entity/Field/Type/Field.php b/core/lib/Drupal/Core/Entity/Field/Type/Field.php index 260e1fd..39d4d2e 100644 --- a/core/lib/Drupal/Core/Entity/Field/Type/Field.php +++ b/core/lib/Drupal/Core/Entity/Field/Type/Field.php @@ -293,14 +293,16 @@ public function access($operation = 'view', User $account = NULL) { if (!isset($account) && $user->uid) { $account = user_load($user->uid); } + // Get the default access restriction that lives within this field. $access = $this->defaultAccess($operation, $account); - // Invoke hook and collect grants/denies for field access. Our default - // access flag is masked under the umbrella of the system module. + // Invoke hook and collect grants/denies for field access from other + // modules. Our default access flag is masked under the umbrella of the + // system module. $grants = array('system' => $access); foreach (module_implements('entity_field_access') as $module) { $grants = array_merge($grants, array($module => module_invoke($module, 'entity_field_access', $operation, $this, $account))); } - // Allow other modules to alter the returned grants/denies. + // Also allow modules to alter the returned grants/denies. $context = array( 'operation' => $operation, 'field' => $this, @@ -324,7 +326,9 @@ public function access($operation = 'view', User $account = NULL) { * Contains the default access logic of this field. * * See \Drupal\Core\TypedData\AccessibleInterface::access() for the parameter - * doucmentation. + * doucmentation. This method can be overriden by field sub classes to provide + * a different default access logic. That allows them to inherit the complete + * access() method which contains the access hook invocation logic. * * @return bool * TRUE if access to this field is allowed per default, FALSE otherwise.