Creating a Node View Which Bypasses Access Restrictions
First of all a disclaimer, part of the intention of this blog post is to see if anyone else has a better solution. This is something I came up with but I'm not entirely happy with the solution as it involves running the sql query twice. :(
Recently I was working on a site which had some subscription content, where basically only members of the site were allowed to view specific content types. However in order to encourage site visitors to register we wanted to display a teaser listing of the 5 most recent articles. We created a node view to display the listing, but the Views module, appropriately, only displays nodes which the user has access to. As the subscription content is only available to logged in users, this defeated the purpose of our teaser listing for site visitors.
To overcome the node access checks, I implemented hook_views_pre_render()
. This is a Views hook which is invoked after the SQL query has been run, but before the view has been rendered. It checks that the view it is modifying is called 'myviewname' and that the display is 'block_1' - you'd need to change these as appropriate for your view. The following code essentially rebuilds the SQL query and reruns it a second time, but this time without the db_rewrite_sql()
call that causes the node permissions to be checked.
<span style="color: #000000"><span style="color: #0000BB"><?php<br></span><span style="color: #FF8000">/**<br> * Implements hook_views_pre_render().<br> */<br></span><span style="color: #007700">function </span><span style="color: #0000BB">mymodule_views_pre_render</span><span style="color: #007700">(&</span><span style="color: #0000BB">$view</span><span style="color: #007700">) {<br><br> </span><span style="color: #FF8000">// For myviewname, bypass node access checks.<br> </span><span style="color: #007700">if (</span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">name </span><span style="color: #007700">== </span><span style="color: #DD0000">'myviewname' </span><span style="color: #007700">&& </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">current_display </span><span style="color: #007700">== </span><span style="color: #DD0000">'block_1' </span><span style="color: #007700">&& empty(</span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">result</span><span style="color: #007700">)) {<br> </span><span style="color: #FF8000">// This does the views token replacements.<br> </span><span style="color: #0000BB">$replacements </span><span style="color: #007700">= </span><span style="color: #0000BB">module_invoke_all</span><span style="color: #007700">(</span><span style="color: #DD0000">'views_query_substitutions'</span><span style="color: #007700">, </span><span style="color: #0000BB">$view</span><span style="color: #007700">);<br> </span><span style="color: #0000BB">$query </span><span style="color: #007700">= </span><span style="color: #0000BB">str_replace</span><span style="color: #007700">(</span><span style="color: #0000BB">array_keys</span><span style="color: #007700">(</span><span style="color: #0000BB">$replacements</span><span style="color: #007700">), </span><span style="color: #0000BB">$replacements</span><span style="color: #007700">, </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">build_info</span><span style="color: #007700">[</span><span style="color: #DD0000">'query'</span><span style="color: #007700">]);<br> </span><span style="color: #0000BB">$args </span><span style="color: #007700">= </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">build_info</span><span style="color: #007700">[</span><span style="color: #DD0000">'query_args'</span><span style="color: #007700">];<br> </span><span style="color: #0000BB">$offset </span><span style="color: #007700">= </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">pager</span><span style="color: #007700">[</span><span style="color: #DD0000">'current_page'</span><span style="color: #007700">] * </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">pager</span><span style="color: #007700">[</span><span style="color: #DD0000">'items_per_page'</span><span style="color: #007700">] + </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">pager</span><span style="color: #007700">[</span><span style="color: #DD0000">'offset'</span><span style="color: #007700">];<br> </span><span style="color: #FF8000">// Runs the query a second time.<br> </span><span style="color: #0000BB">$result </span><span style="color: #007700">= </span><span style="color: #0000BB">db_query_range</span><span style="color: #007700">(</span><span style="color: #0000BB">$query</span><span style="color: #007700">, </span><span style="color: #0000BB">$args</span><span style="color: #007700">, </span><span style="color: #0000BB">$offset</span><span style="color: #007700">, </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">pager</span><span style="color: #007700">[</span><span style="color: #DD0000">'items_per_page'</span><span style="color: #007700">]);<br> </span><span style="color: #FF8000">// Overwrites the default empty result set with the results from our 2nd sql query.<br> </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">result </span><span style="color: #007700">= array();<br> while (</span><span style="color: #0000BB">$item </span><span style="color: #007700">= </span><span style="color: #0000BB">db_fetch_object</span><span style="color: #007700">(</span><span style="color: #0000BB">$result</span><span style="color: #007700">)) {<br> </span><span style="color: #0000BB">$view</span><span style="color: #007700">-></span><span style="color: #0000BB">result</span><span style="color: #007700">[] = </span><span style="color: #0000BB">$item</span><span style="color: #007700">;<br> }<br> }<br>}<br></span><span style="color: #0000BB">?></span></span>
While the above solution works, I would be interested in learning if there is a better way that avoids running the query a second time and without creating the listing in a custom module that is.