sessionConfiguration = $session_configuration; $this->connection = $connection; } /** * {@inheritdoc} */ public function applies(Request $request) { return $request->hasSession() && $this->sessionConfiguration->hasSession($request); } /** * {@inheritdoc} */ public function authenticate(Request $request) { return $this->getUserFromSession($request->getSession()); } /** * Returns the UserSession object for the given session. * * @param \Symfony\Component\HttpFoundation\Session\SessionInterface $session * The session. * * @return \Drupal\Core\Session\AccountInterface|null * The UserSession object for the current user, or NULL if this is an * anonymous session. */ protected function getUserFromSession(SessionInterface $session) { if ($uid = $session->get('uid')) { // @todo Load the User entity in SessionHandler so we don't need queries. // @see https://www.drupal.org/node/2345611 $values = $this->connection ->query('SELECT * FROM {users_field_data} u WHERE u.uid = :uid AND u.default_langcode = 1', [':uid' => $uid]) ->fetchAssoc(); // Check if the user data was found and the user is active. if (!empty($values) && $values['status'] == 1) { // Add the user's roles. $rids = $this->connection ->query('SELECT roles_target_id FROM {user__roles} WHERE entity_id = :uid', [':uid' => $values['uid']]) ->fetchCol(); $values['roles'] = array_merge([AccountInterface::AUTHENTICATED_ROLE], $rids); return new UserSession($values); } } // This is an anonymous session. return NULL; } }