Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Menu Link Attributes 8.x-1.9 — Minor update available for module menu_link_attributes (8.x-1.9). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Search API attachments 10.0.13 — Minor update available for module search_api_attachments (10.0.13). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Mismatched entity and/or field definitions 1.2.1 — Minor update available for module meaofd (1.2.1). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Content Access Restriction

No security coverage Drupal 10–11
View on drupal.org

The Content Access Restriction module provides configurable access control for Drupal content. It allows site administrators to restrict individual content items by user role or specific users, configure which content types support restrictions, and control how restricted content is handled.

The module is useful for Drupal websites and portals where certain content should only be accessible to selected audiences while remaining published and manageable through the normal Drupal content workflow.

Features

The Content Access Restriction module provides a flexible way to control access to individual Drupal content items.

Key features include:

  • Content type configuration: Administrators can choose which content types are allowed to use access restrictions. This prevents restriction controls from appearing on content types where they are not required.
  • Role-based restrictions: Administrators can restrict individual content items from selected Drupal user roles.
  • User-based restrictions: Administrators can restrict individual content items from specific users in addition to role-based restrictions.
  • User autocomplete: The specific-user field provides autocomplete suggestions while entering a username or User ID (UID). Administrators can search using either value and select the corresponding user.
  • Multiple users: Multiple specific users can be configured for the same content item.
  • Configurable restriction response: Administrators can choose whether restricted users receive a 403 Access Denied or 404 Page Not Found response.
  • Administrator bypass: An optional bypass allows users with the Administrator role to access restricted content when administrative access is required.
  • Restricted content listing: A centralized administration page provides a list of restricted content and displays relevant restriction information, including restricted roles and users.
  • Content workflow integration: Restriction settings are available directly while creating or editing supported content, so administrators do not need to manage restrictions through a separate content workflow.

When would you use this module?

This module is useful when a Drupal site needs to keep content published but limit who can access it.

Typical use cases include:

  • Restricting internal documentation to selected user roles.
  • Restricting specific content from particular users.
  • Protecting role-specific or audience-specific portal content.
  • Restricting selected content types while leaving other content types unrestricted.
  • Providing different access behavior for different audiences.
  • Returning a 404 response when restricted content should not appear to exist for unauthorized users.
  • Returning a 403 response when the site should explicitly indicate that access is denied.
  • Giving administrators a centralized view of content that currently has access restrictions.

Post-Installation

After installing and enabling the module, configure it from:

Configuration → Content → Content Access Restriction

The configuration area allows administrators to select the content types for which access restrictions should be available.

Once a content type is enabled:

  1. Create or edit content of the configured content type.
  2. Open the Content Access Restriction section in the content form.
  3. Select the user roles that should be restricted, if role-based restriction is required.
  4. Enter or select specific users when user-based restriction is required. The field provides autocomplete suggestions for usernames and User IDs.
  5. Select the required restriction response: 403 Access Denied or 404 Page Not Found.
  6. Optionally enable the Administrator bypass.
  7. Save the content.

The restriction is applied when a user accesses the restricted content through its canonical Drupal node URL.

A Restricted Content administration page is also available for reviewing content that has access restrictions configured.

Additional Requirements

This module does not require any contributed Drupal modules or external libraries.

Requirements:

  • Drupal 10 or Drupal 11
  • Drupal Core Node module

The module uses Drupal core functionality for entities, user roles, permissions, configuration, routing, forms, and event handling.

No additional modules or external libraries are required.

The module is designed to work with Drupal Core functionality and does not require a third-party JavaScript or PHP library.

Other Drupal modules that provide user or role management may complement this module, but they are not required for it to function.

Similar projects

Drupal provides several approaches to controlling access to content, including Drupal Core permissions and contributed access-control solutions.

The Content Access Restriction module focuses specifically on providing a configurable restriction workflow at the content-item level, with support for:

  • Restricting content by user role.
  • Restricting content from specific users.
  • Configuring which content types support restrictions.
  • Searching for specific users by username or User ID through autocomplete.
  • Choosing between 403 and 404 responses.
  • Optionally bypassing restrictions for administrators.
  • Reviewing restricted content through a centralized administration listing.

The module is intended for projects that need these capabilities as part of their Drupal content management workflow and want a focused, reusable access-restriction component.

Supporting this Module

This module is maintained as a reusable Drupal component.

If you find the module useful, consider contributing feedback, reporting issues, submitting improvements, or helping with documentation and testing through the Drupal.org project issue queue.

Community Documentation

Documentation and examples can be provided through the Drupal.org project documentation and issue queue.

Community members are encouraged to share implementation experiences, configuration guidance, use cases, and improvements through the project issue queue.

Access Restriction Behavior

A restriction can be configured using one or both of the following mechanisms:

  • Roles: Restrict access for selected Drupal user roles.
  • Specific users: Restrict access for selected users using username or User ID autocomplete.

If a user matches a configured restriction, the module applies the configured response for that content item.

The response can be configured as:

  • 403 Access Denied: The user is informed that they do not have permission to access the content.
  • 404 Page Not Found: The request is handled as though the content cannot be found.

The Administrator bypass can be enabled when administrators need to retain access to content that is restricted for other users.

Permissions

The module provides dedicated permissions for managing the feature, including permissions for accessing the Content Access Restriction administration area, managing settings, and viewing the Restricted Content listing.

Permissions can be assigned through:

People → Permissions

Configuration Overview

The module uses Drupal configuration to determine which content types support restrictions. Restriction settings are stored with the individual content item, allowing each piece of content to have its own access-control configuration.

This makes the module suitable for Drupal websites where access requirements vary between individual content items rather than applying a single global access rule.

Depends on

Dependencies of the latest stable release

  • node Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Oct 2026
Latest release
2 hours ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.0.0 Stable 10–11 Oct 8, 2026