Regardless of permissions, on the /admin/content screen, unpublished nodes are never displayed.

If I remove the "published or admin" filter, still nothing.
I noticed in the code there is a views filter to filter content by the permissions set from this module: it does not show up as filter in views backend...

If I delete the query rewriting, it works. But then it just shows all unpublished nodes, regardless of permissions from this module.

How can I get this to work?

Comments

weseze created an issue. See original summary.

weseze’s picture

Status: Active » Closed (works as designed)

Nevermind, seems to be a conflict with advanced access module. Not an issue with this module.

mkalbere’s picture

Status: Closed (works as designed) » Active

Hello,
Sorry but with my setup it absolutely does nort work has expected
(Using Drupal 8.6.7 , latest unpublished_node_permissions)

1) unpublished_node_permissions_views_data_alter is not always called (xdebug). It seems taht this hook has to be writen in a file name unpublished_node_permissions.views.inc (module root dir) (if you want to put it somewhere else cf https://drupal.stackexchange.com/questions/202202/when-do-hook-views-dat...

function unpublished_node_permissions_views_api($module = NULL, $api = NULL) {
  return array(
    'api' => '3.0',
    'path' => drupal_get_path('module', 'unpublished_node_permissions') . '/includes/views',
  );
}

)
2) hook_node_access solved only a couple of case, so I removed it and replaced it with :

function unpublished_node_permissions_node_access_records(\Drupal\node\NodeInterface $node) {
  if (!$node->isPublished()) {
    $grants = array();
      $type = $node->bundle();
      $grants[] = array(
        'realm' => "view $type unpublished content",
        'gid' => 1,
        'grant_view' => 1,
        'grant_update' => 0,
        'grant_delete' => 0,
        'priority' => 10,     // <==== This has to but updated, probably wrong
      );
      return $grants;
    }
    
}

function unpublished_node_permissions_node_grants(\Drupal\Core\Session\AccountInterface $account, $op) {
  $grants=array();
  $types=NodeType::loadMultiple();
  foreach ($types as $type_id=>$node_type) {
      if ($account->hasPermission("view $type_id unpublished content")) {
          $grants["view $type_id unpublished content"] = array(
      1,
    );
      }
  }
  return $grants;
}

3) not a problem ;-) , but just a comment: with the hook_grants approach, we could now also play with the "UPDATE" & "DELETE" $op

=> admin/content works !!

berenddeboer’s picture

This module does not work. Does do nothing for me. The code above should be submitted as patch as pasting it in does not work either.

slefevre@ccad.edu’s picture

From my testing, this module does not seem to work for me either. If this doesn't work, please take it down so that other people don't waste their time with it.

weseze’s picture

This module is working fine for us on 10+ sites. I think you have misconfiguration or maybe a conflicting module/configuration.

mikeohara’s picture

Works fine for me on Drupal 8.7.5. (With no other modules that affect publication permissions installed)

kunalkursija’s picture

This worked for me on Drupal 8.7.7
User having the desired permissions can access the unpublished nodes on the node view page and also on admin/content page.

anybody’s picture

Sadly I can also confirm that the content view doesn't show unpublished content to users with given permission if query rewriting is enabled. As a test I removed all filters, relations and all fields but "title" from the view, but with no luck.

I also rebuilt permissions before.
Accessing the node / edit form works perfectly so the problem only exists for views query rewriting. I guess the problem exists in certain combinations, perhaps with other modules.

Drupal Version is 8.7.7 and I used the dev version.

EDIT: We're using the "content access" module in that project, which may cause these problems! Is there a solution how to use both in combination?

anybody’s picture

Perhaps a note should be added on the module page, which links to this issue and informs the user that the view + query rewriting + addition access controlling modules doesn't work yet?

The modules reported to be NOT compatible yet are:

  • content_access (#9)
  • advanced_access (#2)

Best would be to find out the reason for the incompatibility and fix it of course. Dangerous workaround is to disable views query rewriting.
From my point of view in code the reason is, that these modules work with grants, but (by concept) don't add them for unpublished content. This module doesn't work with grants. So views checks that there is no grant for these nodes in query rewriting and denies access. As a result from my point of view this module has to add the grants for unpublished nodes for roles with permission?

Perhaps Durpal 8 Cores "Content Moderation" provides a better implementation, it provides a simplar option as you can see here: https://drupal.stackexchange.com/questions/259520/anonymous-user-can-vie...

There is already an issue for a soluton in core: #273595: Move permission "view any unpublished content" from Content Moderation to Node

sinn’s picture

If any module in your projects implements hook_node_grants then this module is useless for /admin/content. See implementation of node_query_node_access_alter().

As a workaround you can Disable SQL rewriting for the /admin/content view.

jonathanshaw’s picture

Title: Does not work on /admin/content » Does not work on views if another module implements node grants

#11 seems like the right explanation.

anybody’s picture

Does anyone know if https://www.drupal.org/project/view_unpublished has the same issue or if it works over there?

wells’s picture

@Anybody I have confirmed that https://www.drupal.org/project/view_unpublished works with other grant-based access implementations.

astonvictor’s picture

I implemented node grants in the issue - https://www.drupal.org/project/unpublished_node_permissions/issues/3401801
So, it should work now.

astonvictor’s picture

Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.