Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

Entity Access by Reference Field

Security covered

Part of the Entity ecosystem · 235 projects

View on drupal.org

Feature Overview

Allows to control access to entities based on entity reference fields.
With this module, you can define access conditions on entity reference fields for the host entity.

Configurable examples:

  • If a user is allowed to view the referenced entity, he is also allowed to view the host entity.
  • If a user is allowed to edit the referenced entity, he is also allowed to edit the host entity.
  • If a user is allowed to delete the referenced entity, he is also allowed to delete the host entity.
  • If a user is allowed to edit the referenced entity, he is also allowed to edit or delete the host entity.
  • If a user is the referenced entity, he is allowed to edit the host entity.

The fallback behavior (allow, neutral, deny) and the empty behaviour (if a host entity does not have a referenced entity set) is also defined per field.

Note, that this module uses third party settings on the field storage, meaning multiple field instances of the same field will share the settings!

Currently supported access checks:

  • View
  • View Unpublished
  • Edit
  • Delete
  • Is User (referenced user entity only)

Views support

This module implements hook_entity_access() to dynamically calculate entity access permissions. Due to the complex logic it doesn't implement hook_query_TAG_alter().
So Views may display entities, which are "Access denied" for the users! Take care, in some combination this may lead to information disclosure for such Views contents (e.g. seeing the label you should not see).

Until the core issue (#777578: Add an entity query access API and deprecate hook_query_ENTITY_TYPE_access_alter()) is fixed, you may try the views_entity_access_check module if you're running into such cases:
https://www.drupal.org/project/views_entity_access_check
And please help to push a core solution in the linked issue.

Future plans (if community helps):

If the community helps to develop the functionality or development is sponsored, there are further ideas that might be added here, like

  • Condition: Current user created the referenced entity

... any other ideas? Please create an issue and help to develop the functionality.

History & reasons for this module

This module was born, as we already had experience and a good starting point with our Entity Access by Role Field module.
In Drupal 7 we loved to use Node access node reference and Node access user reference which have no Drupal 8+ release.
We tried Access by Reference module, but it didn't work really well. https://www.drupal.org/project/reference_access does similar things, just the other way around (referencing from the user page).

As we didn't find a good (enough) alternative, we decided to create this module based on our existing Entity Access by Role Field code and knowledge.

Debugging permissions / entity access

For debugging permissions on entities, the following modules can be helpful:

  1. Devel
  2. Web Profiler
  3. Drush Tools
  4. Masquerade

Similar modules & alternatives

You may want to have a look at these alternatives, before making the choice:

For Drupal 7 there were some more helpful modules like:

For other use-cases:

Need to select roles instead (per entitiy)

If you need to grant access (CRUD) to single entities by selecting roles instead in a flexible way, instead have a look at Entity Access by Role Field Module instead, which provides such functionality on role reference fields.

Supporting this module

Support DROWL's ♥ FOSS work on this module on OpenCollective!

Drupal and this module are FOSS. However, it takes dedicated people to develop and maintain. And they need YOU to give back!

We're committed to building and maintaining Drupal modules that benefit the entire community.

Supporting us on OpenCollective helps us continue to improve, innovate and contribute to Drupal's future. Every pledge makes a difference!

If this module has helped you, we would be very grateful for your donation to support its further development and maintenance.

Support our FOSS development ♥️

You can also speed up the development of features or bugfixes you'd love to see, by sponsoring and giving back!

Sponsor a feature or bugfix 🚀

Let's make Drupal even better, together!

Development proudly sponsored by German Drupal Friends & Companies:

webks: websolutions kept simple (https://www.webks.de)
and
DROWL: Drupalbasierte Lösungen aus Ostwestfalen-Lippe (OWL), Germany (https://www.drowl.de)

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
9
Tracked since
Apr 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Release Timeline

Releases

Version Type Core Release date
1.1.0 Stable Jan 22, 2024
1.0.2 Stable Jan 22, 2024
1.0.1 Stable Aug 3, 2023
1.0.0 Stable May 11, 2023
1.0.0-beta2 Pre-release May 9, 2023
1.0.0-beta1 Pre-release Apr 14, 2023
1.0.0-alpha2 Pre-release Apr 14, 2023
1.0.0-alpha1 Pre-release Apr 13, 2023
1.x-dev Dev Apr 6, 2023