diff --git a/core/includes/menu.inc b/core/includes/menu.inc
index 66afab8..1d9cc29 100644
--- a/core/includes/menu.inc
+++ b/core/includes/menu.inc
@@ -970,6 +970,7 @@ function _menu_link_translate(&$item, $translate = FALSE) {
function menu_item_route_access(Route $route, $href, &$map) {
$request = Request::create('/' . $href);
$request->attributes->set('_system_path', $href);
+ $request->attributes->set('_account', Drupal::request()->attributes->get('_account'));
// Attempt to match this path to provide a fully built request to the
// access checker.
try {
diff --git a/core/modules/contact/contact.module b/core/modules/contact/contact.module
index d8984e8..2544e64 100644
--- a/core/modules/contact/contact.module
+++ b/core/modules/contact/contact.module
@@ -86,31 +86,21 @@ function contact_menu() {
$items['contact'] = array(
'title' => 'Contact',
- 'page callback' => 'contact_site_page',
- 'access arguments' => array('access site-wide contact form'),
+ 'route_name' => 'contact_site_page',
'menu_name' => 'footer',
- 'type' => MENU_SUGGESTED_ITEM,
- 'file' => 'contact.pages.inc',
);
$items['contact/%contact_category'] = array(
'title' => 'Contact category form',
'title callback' => 'entity_page_label',
'title arguments' => array(1),
- 'page callback' => 'contact_site_page',
- 'page arguments' => array(1),
- 'access arguments' => array('access site-wide contact form'),
+ 'route_name' => 'contact_site_page_category',
'type' => MENU_VISIBLE_IN_BREADCRUMB,
- 'file' => 'contact.pages.inc',
);
$items['user/%user/contact'] = array(
'title' => 'Contact',
- 'page callback' => 'contact_personal_page',
- 'page arguments' => array(1),
+ 'route_name' => 'contact_personal_page',
'type' => MENU_LOCAL_TASK,
- 'access callback' => '_contact_personal_tab_access',
- 'access arguments' => array(1),
'weight' => 2,
- 'file' => 'contact.pages.inc',
);
return $items;
}
diff --git a/core/modules/contact/contact.pages.inc b/core/modules/contact/contact.pages.inc
deleted file mode 100644
index 52afd28..0000000
--- a/core/modules/contact/contact.pages.inc
+++ /dev/null
@@ -1,106 +0,0 @@
-get('default_category');
- if (isset($categories[$default_category])) {
- $category = $categories[$default_category];
- }
- // If there are no categories, do not display the form.
- else {
- if (user_access('administer contact forms')) {
- drupal_set_message(t('The contact form has not been configured. Add one or more categories to the form.', array('@add' => url('admin/structure/contact/add'))), 'error');
- return array();
- }
- else {
- throw new NotFoundHttpException();
- }
- }
- }
- else if ($category->id() == 'personal') {
- throw new NotFoundHttpException();
- }
- $message = entity_create('contact_message', array(
- 'category' => $category->id(),
- ));
- return Drupal::entityManager()->getForm($message);
-}
-
-/**
- * Page callback: Form constructor for the personal contact form.
- *
- * @param $recipient
- * The account for which a personal contact form should be generated.
- *
- * @throws \Symfony\Component\HttpKernel\Exception\AccessDeniedHttpException
- *
- * @see contact_menu()
- * @see contact_personal_form_submit()
- *
- * @ingroup forms
- */
-function contact_personal_page($recipient) {
- global $user;
-
- // Check if flood control has been activated for sending e-mails.
- if (!user_access('administer contact forms') && !user_access('administer users')) {
- contact_flood_control();
- }
-
- drupal_set_title(t('Contact @username', array('@username' => user_format_name($recipient))), PASS_THROUGH);
-
- $message = entity_create('contact_message', array(
- 'recipient' => $recipient,
- 'category' => 'personal',
- ));
- return Drupal::entityManager()->getForm($message);
-}
-
-/**
- * Throws an exception if the current user is not allowed to submit a contact form.
- *
- * @throws \Symfony\Component\HttpKernel\Exception\AccessDeniedHttpException
- *
- * @see contact_site_page()
- * @see contact_personal_page()
- */
-function contact_flood_control() {
- $config = config('contact.settings');
- $limit = $config->get('flood.limit');
- $interval = $config->get('flood.interval');
- if (!Drupal::service('flood')->isAllowed('contact', $limit, $interval)) {
- drupal_set_message(t("You cannot send more than %limit messages in @interval. Try again later.", array(
- '%limit' => $limit,
- '@interval' => format_interval($interval),
- )), 'error');
- throw new AccessDeniedHttpException();
- }
-}
diff --git a/core/modules/contact/contact.routing.yml b/core/modules/contact/contact.routing.yml
index ba47a6a..ed18b20 100644
--- a/core/modules/contact/contact.routing.yml
+++ b/core/modules/contact/contact.routing.yml
@@ -1,9 +1,9 @@
contact_category_delete:
pattern: 'admin/structure/contact/manage/{contact_category}/delete'
defaults:
- _entity_form: contact_category.delete
+ _entity_form: 'contact_category.delete'
requirements:
- _entity_access: contact_category.delete
+ _entity_access: 'contact_category.delete'
contact_category_list:
pattern: '/admin/structure/contact'
@@ -15,13 +15,34 @@ contact_category_list:
contact_category_add:
pattern: '/admin/structure/contact/add'
defaults:
- _entity_form: contact_category.add
+ _entity_form: 'contact_category.add'
requirements:
_permission: 'administer contact forms'
contact_category_edit:
pattern: '/admin/structure/contact/manage/{contact_category}'
defaults:
- _entity_form: contact_category.edit
+ _entity_form: 'contact_category.edit'
requirements:
- _entity_access: contact_category.update
+ _entity_access: 'contact_category.update'
+
+contact_site_page:
+ pattern: 'contact'
+ defaults:
+ _content: '\Drupal\contact\Controller\ContactPageController::contactSitePage'
+ requirements:
+ _permission: 'access site-wide contact form'
+
+contact_site_page_category:
+ pattern: 'contact/{contact_category}'
+ defaults:
+ _content: '\Drupal\contact\Controller\ContactPageController::contactSitePage'
+ requirements:
+ _entity_access: 'contact_category.page'
+
+contact_personal_page:
+ pattern: 'user/{user}/contact'
+ defaults:
+ _content: '\Drupal\contact\Controller\ContactPageController::contactPersonalPage'
+ requirements:
+ _access_contact_personal_tab: 'TRUE'
diff --git a/core/modules/contact/contact.services.yml b/core/modules/contact/contact.services.yml
new file mode 100644
index 0000000..cccd1fd
--- /dev/null
+++ b/core/modules/contact/contact.services.yml
@@ -0,0 +1,6 @@
+services:
+ access_check.contact_personal:
+ class: Drupal\contact\Access\ContactPageAccess
+ tags:
+ - { name: access_check }
+ arguments: ['@config.factory', '@user.data']
diff --git a/core/modules/contact/lib/Drupal/contact/Access/ContactPageAccess.php b/core/modules/contact/lib/Drupal/contact/Access/ContactPageAccess.php
new file mode 100644
index 0000000..367d206
--- /dev/null
+++ b/core/modules/contact/lib/Drupal/contact/Access/ContactPageAccess.php
@@ -0,0 +1,99 @@
+config = $config_factory->get('contact.settings');
+ $this->userData = $user_data;
+ }
+
+ /**
+ * {@inheritdoc}
+ */
+ public function appliesTo() {
+ // @see contact.routing.yml
+ return array('_access_contact_personal_tab');
+ }
+
+ /**
+ * {@inheritdoc}
+ */
+ public function access(Route $route, Request $request) {
+ $contact_account = $request->attributes->get('user');
+
+ // Anonymous users cannot have contact forms.
+ if ($contact_account->isAnonymous()) {
+ return static::DENY;
+ }
+
+ $current_account = $request->attributes->get('_account');;
+
+ // Users may not contact themselves.
+ if ($current_account->id() == $contact_account->id()) {
+ return static::DENY;
+ }
+
+ // User administrators should always have access to personal contact forms.
+ if ($current_account->hasPermission('administer users')) {
+ return static::ALLOW;
+ }
+
+ // If requested user has been blocked, do not allow users to contact them.
+ if ($contact_account->isBlocked()) {
+ return static::DENY;
+ }
+
+ // If the requested user has disabled their contact form, do not allow users
+ // to contact them.
+ $account_data = $this->userData->get('contact', $contact_account->id(), 'enabled');
+ if (isset($account_data) && empty($account_data)) {
+ return static::DENY;
+ }
+ // If the requested user did not save a preference yet, deny access if the
+ // configured default is disabled.
+ elseif (!$this->config->get('user_default_enabled')) {
+ return static::DENY;
+ }
+
+ return $current_account->hasPermission('access user contact forms');
+ }
+
+}
diff --git a/core/modules/contact/lib/Drupal/contact/CategoryAccessController.php b/core/modules/contact/lib/Drupal/contact/CategoryAccessController.php
index ca6ca90..af7ae55 100644
--- a/core/modules/contact/lib/Drupal/contact/CategoryAccessController.php
+++ b/core/modules/contact/lib/Drupal/contact/CategoryAccessController.php
@@ -23,10 +23,14 @@ class CategoryAccessController extends EntityAccessController {
public function checkAccess(EntityInterface $entity, $operation, $langcode, AccountInterface $account) {
if ($operation == 'delete' || $operation == 'update') {
// Do not allow delete 'personal' category used for personal contact form.
- return user_access('administer contact forms', $account) && $entity->id() !== 'personal';
+ return $account->hasPermission('administer contact forms') && $entity->id() !== 'personal';
+ }
+ elseif ($operation == 'page') {
+ // Do not allow access personal category via site-wide route.
+ return $account->hasPermission('access site-wide contact form') && $entity->id() !== 'personal';
}
else {
- return user_access('administer contact forms', $account);
+ return $account->hasPermission('administer contact forms');
}
}
diff --git a/core/modules/contact/lib/Drupal/contact/Controller/ContactPageController.php b/core/modules/contact/lib/Drupal/contact/Controller/ContactPageController.php
new file mode 100644
index 0000000..41a045d
--- /dev/null
+++ b/core/modules/contact/lib/Drupal/contact/Controller/ContactPageController.php
@@ -0,0 +1,181 @@
+flood = $flood;
+ $this->configFactory = $config_factory;
+ $this->entityManager = $entity_manager;
+ $this->translator = $translator;
+ }
+
+ /**
+ * {@inheritdoc}
+ */
+ public static function create(ContainerInterface $container) {
+ return new static(
+ $container->get('flood'),
+ $container->get('config.factory'),
+ $container->get('plugin.manager.entity'),
+ $container->get('string_translation')
+ );
+ }
+
+ /**
+ * Presents the site-wide contact form.
+ *
+ * @param \Drupal\Core\Session\AccountInterface $_account
+ * The current account.
+ * @param \Drupal\contact\Plugin\Core\Entity\Category $contact_category
+ * The contact category to use.
+ *
+ * @return array
+ * The form as render array as expected by drupal_render().
+ *
+ * @throws \Symfony\Component\HttpKernel\Exception\NotFoundHttpException
+ * Exception is thrown when user tries to access non existing contact
+ * category form.
+ */
+ public function contactSitePage(AccountInterface $_account, Category $contact_category = NULL) {
+ // Check if flood control has been activated for sending e-mails.
+ if (!$_account->hasPermission('administer contact forms')) {
+ $this->contactFloodControl();
+ }
+
+ // Use the default category if no category has been passed.
+ if (empty($contact_category)) {
+ $default_category = $this->configFactory->get('contact.settings')->get('default_category');
+ $contact_category = $this->entityManager
+ ->getStorageController('contact_category')
+ ->load($default_category);
+ // If there are no categories, do not display the form.
+ if (empty($contact_category)) {
+ if ($_account->hasPermission('administer contact forms')) {
+ drupal_set_message($this->translator->translate('The contact form has not been configured. Add one or more categories to the form.', array('@add' => url('admin/structure/contact/add'))), 'error');
+ return array();
+ }
+ else {
+ throw new NotFoundHttpException();
+ }
+ }
+ }
+
+ $message = $this->entityManager
+ ->getStorageController('contact_message')
+ ->create(array(
+ 'category' => $contact_category->id(),
+ ));
+
+ return $this->entityManager->getForm($message);
+ }
+
+ /**
+ * Form constructor for the personal contact form.
+ *
+ * @param \Drupal\user\UserInterface $user
+ * The account for which a personal contact form should be generated.
+ * @param \Drupal\Core\Session\AccountInterface $_account
+ * The current user.
+ *
+ * @return array
+ * The personal contact form as render array as expected by drupal_render().
+ */
+ public function contactPersonalPage(UserInterface $user, AccountInterface $_account) {
+ // Check if flood control has been activated for sending e-mails.
+ if (!$_account->hasPermission('administer contact forms') && !$_account->hasPermission('administer users')) {
+ $this->contactFloodControl();
+ }
+
+ drupal_set_title($this->translator->translate('Contact @username', array('@username' => $user->getUsername())), PASS_THROUGH);
+
+ $message = $this->entityManager
+ ->getStorageController('contact_message')
+ ->create(array(
+ 'category' => 'personal',
+ 'recipient' => $user->id(),
+ ));
+
+ return $this->entityManager->getForm($message);
+ }
+
+ /**
+ * Throws an exception if the current user triggers flood control.
+ *
+ * @throws \Symfony\Component\HttpKernel\Exception\AccessDeniedHttpException
+ */
+ protected function contactFloodControl() {
+ $contact_settings = $this->configFactory->get('contact.settings');
+ $limit = $contact_settings->get('flood.limit');
+ $interval = $contact_settings->get('flood.interval');
+ if (!$this->flood->isAllowed('contact', $limit, $interval)) {
+ drupal_set_message($this->translator->translate('You cannot send more than %limit messages in @interval. Try again later.', array(
+ '%limit' => $limit,
+ '@interval' => format_interval($interval),
+ )), 'error');
+ throw new AccessDeniedHttpException();
+ }
+ }
+
+}
diff --git a/core/modules/contact/lib/Drupal/contact/Tests/ContactSitewideTest.php b/core/modules/contact/lib/Drupal/contact/Tests/ContactSitewideTest.php
index 42f4423..924dbb2 100644
--- a/core/modules/contact/lib/Drupal/contact/Tests/ContactSitewideTest.php
+++ b/core/modules/contact/lib/Drupal/contact/Tests/ContactSitewideTest.php
@@ -44,7 +44,8 @@ function testSiteWideContact() {
$this->drupalLogin($admin_user);
$flood_limit = 3;
- config('contact.settings')
+ $this->container->get('config.factory')
+ ->get('contact.settings')
->set('flood.limit', $flood_limit)
->set('flood.interval', 600)
->save();
@@ -110,7 +111,8 @@ function testSiteWideContact() {
$this->assertRaw(t('Category %label has been added.', array('%label' => $label)));
// Check that the category was created in site default language.
- $langcode = config('contact.category.' . $id)->get('langcode');
+ $langcode = $this->container->get('config.factory')
+ ->get('contact.category.' . $id)->get('langcode');
$default_langcode = language_default()->id;
$this->assertEqual($langcode, $default_langcode);
@@ -119,7 +121,8 @@ function testSiteWideContact() {
// Test update contact form category.
$this->updateCategory($id, $label = $this->randomName(16), $recipients_str = implode(',', array($recipients[0], $recipients[1])), $reply = $this->randomName(30), FALSE);
- $config = config('contact.category.' . $id)->get();
+ $config = $this->container->get('config.factory')
+ ->get('contact.category.' . $id)->get();
$this->assertEqual($config['label'], $label);
$this->assertEqual($config['recipients'], array($recipients[0], $recipients[1]));
$this->assertEqual($config['reply'], $reply);
@@ -127,7 +130,10 @@ function testSiteWideContact() {
$this->assertRaw(t('Category %label has been updated.', array('%label' => $label)));
// Reset the category back to be the default category.
- config('contact.settings')->set('default_category', $id)->save();
+ $this->container->get('config.factory')
+ ->get('contact.settings')
+ ->set('default_category', $id)
+ ->save();
// Ensure that the contact form is shown without a category selection input.
user_role_grant_permissions(DRUPAL_ANONYMOUS_RID, array('access site-wide contact form'));
@@ -181,8 +187,23 @@ function testSiteWideContact() {
$this->submitContact($this->randomName(16), $recipients[0], $this->randomName(16), $id, '');
$this->assertText(t('Message field is required.'));
+ // Submit contact form with correct values and check flood interval.
+ for ($i = 0; $i < $flood_limit; $i++) {
+ $this->submitContact($this->randomName(16), $recipients[0], $this->randomName(16), $id, $this->randomName(64));
+ $this->assertText(t('Your message has been sent.'));
+ }
+ // Submit contact form one over limit.
+ $this->drupalGet('contact');
+ $this->assertResponse(403);
+ $this->assertRaw(t('You cannot send more than %number messages in @interval. Try again later.', array(
+ '%number' => $this->container->get('config.factory')->get('contact.settings')->get('flood.limit'),
+ '@interval' => format_interval(600))
+ ));
+
+ $this->container->get('flood')->clear('contact');
// Test contact form with no default category selected.
- config('contact.settings')
+ $this->container->get('config.factory')
+ ->get('contact.settings')
->set('default_category', '')
->save();
$this->drupalGet('contact');
@@ -194,20 +215,21 @@ function testSiteWideContact() {
$this->drupalGet('contact/' . $this->randomName());
$this->assertResponse(404);
- // Submit contact form with correct values and check flood interval.
- for ($i = 0; $i < $flood_limit; $i++) {
- $this->submitContact($this->randomName(16), $recipients[0], $this->randomName(16), $id, $this->randomName(64));
- $this->assertText(t('Your message has been sent.'));
- }
- // Submit contact form one over limit.
- $this->drupalGet('contact');
- $this->assertResponse(403);
- $this->assertRaw(t('You cannot send more than %number messages in @interval. Try again later.', array('%number' => config('contact.settings')->get('flood.limit'), '@interval' => format_interval(600))));
-
// Test listing controller.
$this->drupalLogin($admin_user);
$this->deleteCategories();
+ // Test contact form with unknown category selected for admin.
+ $this->container->get('config.factory')
+ ->get('contact.settings')
+ ->set('default_category', drupal_strtolower($this->randomName(16)))
+ ->save();
+ $this->drupalGet('contact');
+ $this->assertResponse(200);
+ $this->assertRaw(
+ t('The contact form has not been configured. Add one or more categories to the form.', array('@add' => url('admin/structure/contact/add'))),
+ 'Admin error found'
+ );
$label = $this->randomName(16);
$recipients = implode(',', array($recipients[0], $recipients[1], $recipients[2]));
@@ -376,7 +398,7 @@ function submitContact($name, $mail, $subject, $id, $message) {
$edit['mail'] = $mail;
$edit['subject'] = $subject;
$edit['message'] = $message;
- if ($id == config('contact.settings')->get('default_category')) {
+ if ($id == $this->container->get('config.factory')->get('contact.settings')->get('default_category')) {
$this->drupalPost('contact', $edit, t('Send message'));
}
else {
diff --git a/core/modules/contact/lib/Drupal/contact/Tests/MessageEntityTest.php b/core/modules/contact/lib/Drupal/contact/Tests/MessageEntityTest.php
index c9e2e5d..9bc3cfb 100644
--- a/core/modules/contact/lib/Drupal/contact/Tests/MessageEntityTest.php
+++ b/core/modules/contact/lib/Drupal/contact/Tests/MessageEntityTest.php
@@ -21,7 +21,7 @@ class MessageEntityTest extends DrupalUnitTestBase {
*
* @var array
*/
- public static $modules = array('system', 'contact');
+ public static $modules = array('system', 'user', 'contact');
public static function getInfo() {
return array(