Drupal团队管理:三级用户权限配置方案求助(非编程新手)
Hey there! Since you’ve got programming experience under your belt, building this team-based permission system in Drupal should be totally doable. Let’s skip the Organic Groups route (since it’s not a fit for your use case) and walk through practical solutions tailored to your needs:
Start by creating the three roles you need at /admin/people/roles:
- Administrator: Keep the default full permissions for this role—no changes needed here.
- Team Lead: This will be your "intermediate" user with access to edit their own content and their team members’ content.
- Team Member: Your regular user, limited to editing only their own content.
You need a way to associate Team Leads with their subordinates. Pick one of these methods:
Option A: Direct User Reference Fields
- Add a multi-value User Reference field to the user entity (name it
field_team_members), and restrict its visibility only to the Team Lead role. This lets each lead directly select their team members. - Add a single-value User Reference field (name it
field_team_lead) to all users, so each Team Member can be linked to their direct lead.
Option B: Taxonomy-Based Teams
- Create a new taxonomy vocabulary called
Teams, where each term represents a single team. - Add a Taxonomy Reference field (name it
field_team) to the user entity, so every user can be assigned to a team. - Add a User Reference field (name it
field_team_lead) to the taxonomy terms, to designate which Team Lead owns each team.
Drupal’s default permissions can’t handle the "edit own + team members’ content" logic out of the box, so you’ve got two paths here:
Option 1: Module Combo (Minimal Code)
Use existing modules to avoid building everything from scratch:
- Content Access: Lets you set granular permissions on content items. Pair it with the Rules module to automate permission assignments:
- Create a rule that adds edit permissions for the Team Lead and their members whenever a lead creates content.
- Create another rule that gives edit access only to the user themselves and their Team Lead when a regular member creates content.
- Permissions by Entity: Lets you assign permissions based on entity fields (like the team field you set up). For example, you can set a rule that "Team Leads can edit content created by users in their assigned team".
Option 2: Custom Code (Full Flexibility)
Since you have programming experience, a custom module gives you full control. Use hook_node_access() to intercept content edit requests:
/** * Implements hook_node_access(). */ function my_custom_team_module_node_access($node, $op, $account) { // Administrators get full access if (in_array('administrator', $account->getRoles())) { return AccessResult::allowed(); } // Only handle edit permissions here; let Drupal handle other operations if ($op !== 'update') { return AccessResult::neutral(); } // Team Members can only edit their own content if (in_array('team_member', $account->getRoles())) { return ($node->getOwnerId() === $account->id()) ? AccessResult::allowed() : AccessResult::forbidden(); } // Team Leads can edit their own content AND their subordinates' content if (in_array('team_lead', $account->getRoles())) { // Allow editing their own content if ($node->getOwnerId() === $account->id()) { return AccessResult::allowed(); } // Check if the content author is the lead's subordinate (using field_team_lead) $content_author = $node->getOwner(); $author_lead_id = $content_author->get('field_team_lead')->target_id; if ($author_lead_id === $account->id()) { return AccessResult::allowed(); } // If using taxonomy teams: uncomment this block and remove the above check // $author_team_id = $content_author->get('field_team')->target_id; // $current_user_team_id = $account->get('field_team')->target_id; // $current_user_is_team_lead = ($account->get('field_team_lead')->target_id === $account->id()); // if ($current_user_is_team_lead && $author_team_id === $current_user_team_id) { // return AccessResult::allowed(); // } // Deny access to all other content return AccessResult::forbidden(); } // Fallback to Drupal's default permission checks return AccessResult::neutral(); }
Drop this code into a custom module (e.g., my_custom_team_module.module), enable the module, and you’re set.
Don’t skip this step! Create test users for each role, assign teams/subordinates, and verify:
- Administrators can edit all content.
- Team Leads can edit their own content and their team members’ content (but NOT content from other teams or other leads).
- Team Members can only edit their own content.
内容的提问来源于stack exchange,提问作者Susana Santos

