| Versionen | |
|---|---|
| drupal6 – drupal7 | node_access($op, $node, $account = NULL) |
Determine whether the current user may perform the given operation on the specified node.
$op The operation to be performed on the node. Possible values are:
$node The node object (or node array) on which the operation is to be performed, or node type (e.g. 'forum') for "create" operation.
$account Optional, a user object representing the user for whom the operation is to be performed. Determines access for a user other than the current user.
TRUE if the operation may be performed.
modules/
<?php
function node_access($op, $node, $account = NULL) {
global $user;
if (!$node || !in_array($op, array('view', 'update', 'delete', 'create'), TRUE)) {
// If there was no node to check against, or the $op was not one of the
// supported ones, we return access denied.
return FALSE;
}
// Convert the node to an object if necessary:
if ($op != 'create') {
$node = (object) $node;
}
// If no user object is supplied, the access check is for the current user.
if (empty($account)) {
$account = $user;
}
// If the node is in a restricted format, disallow editing.
if ($op == 'update' && !filter_access($node->format)) {
return FALSE;
}
if (user_access('bypass node access', $account)) {
return TRUE;
}
if (!user_access('access content', $account)) {
return FALSE;
}
// Can't use node_invoke('access', $node), because the access hook takes the
// $op parameter before the $node parameter.
$base = node_get_types('base', $node);
$access = module_invoke($base, 'access', $op, $node, $account);
if (!is_null($access)) {
return $access;
}
// If the module did not override the access rights, use those set in the
// node_access table.
if ($op != 'create' && $node->nid && $node->status) {
$query = db_select('node_access');
$query->addExpression('COUNT(*)');
$query
->condition(db_or()
->condition('nid', 0)
->condition('nid', $node->nid)
)
->condition('grant_' . $op, 1, '>=');
$grants = db_or();
foreach (node_access_grants($op, $account) as $realm => $gids) {
foreach ($gids as $gid) {
$grants->condition(db_and()
->condition('gid', $gid)
->condition('realm', $realm)
);
}
}
if (count($grants) > 0 ) {
$query->condition($grants);
}
return $query
->execute()
->fetchField();
}
// Let authors view their own nodes.
if ($op == 'view' && $account->uid == $node->uid && $account->uid != 0) {
return TRUE;
}
return FALSE;
}
?>
Kommentare
Kommentar hinzufügen