user.module

Same filename and directory in other branches
  1. 10 core/modules/user/user.module
  2. 9 core/modules/user/user.module
  3. 8.9.x core/modules/user/user.module
  4. 7.x modules/user/user.module
  5. main core/modules/user/user.module

File

core/modules/user/user.module

View source
<?php


/**
 * @file
 */

use Drupal\Core\Render\BubbleableMetadata;
use Drupal\Core\Session\AccountInterface;
use Drupal\user\AccountCancellation;
use Drupal\user\Hook\UserThemeHooks;
use Drupal\user\LoginFinalizer;
use Drupal\user\LogoutFinalizer;
use Drupal\user\OneTimeAuthentication;
use Drupal\user\UserInterface;

/**
 * Returns whether this site supports the default user picture feature.
 *
 * This approach preserves compatibility with node/comment templates. Alternate
 * user picture implementations (e.g., Gravatar) should provide their own
 * add/edit/delete forms and populate the 'picture' variable during the
 * preprocess stage.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. There
 *   is no replacement, check the definition directly.
 *
 * @see https://www.drupal.org/node/3619932
 */
function user_picture_enabled() {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. There is no replacement, check the definition directly. See https://www.drupal.org/node/3619932', E_USER_DEPRECATED);
  $field_definitions = \Drupal::service('entity_field.manager')->getFieldDefinitions('user', 'user');
  return isset($field_definitions['user_picture']);
}

/**
 * Fetches a user object by email address.
 *
 * @param string $mail
 *   String with the account's email address.
 *
 * @return \Drupal\user\UserInterface|false
 *   A fully-loaded $user object upon successful user load or FALSE if user
 *   cannot be loaded.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0.
 *   Use \Drupal::entityTypeManager()->getStorage('user')->loadByProperties()
 *   instead.
 *
 * @see https://www.drupal.org/node/3555936
 */
function user_load_by_mail($mail) {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use entityTypeManager()->getStorage("user")->loadByProperties() instead. See https://www.drupal.org/node/3555936', E_USER_DEPRECATED);
  $users = \Drupal::entityTypeManager()->getStorage('user')
    ->loadByProperties([
    'mail' => $mail,
  ]);
  return $users ? reset($users) : FALSE;
}

/**
 * Fetches a user object by account name.
 *
 * @param string $name
 *   String with the account's user name.
 *
 * @return \Drupal\user\UserInterface|false
 *   A fully-loaded $user object upon successful user load or FALSE if user
 *   cannot be loaded.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0.
 *   Use \Drupal::entityTypeManager()->getStorage('user')->loadByProperties()
 *   instead.
 *
 * @see https://www.drupal.org/node/3555936
 */
function user_load_by_name($name) {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use entityTypeManager()->getStorage("user")->loadByProperties() instead. See https://www.drupal.org/node/3555936', E_USER_DEPRECATED);
  $users = \Drupal::entityTypeManager()->getStorage('user')
    ->loadByProperties([
    'name' => $name,
  ]);
  return $users ? reset($users) : FALSE;
}

/**
 * Verify the syntax of the given name.
 *
 * @param string $name
 *   The user name to validate.
 *
 * @return string|null
 *   A translated violation message if the name is invalid or NULL if the name
 *   is valid.
 *
 * @deprecated in drupal:10.3.0 and is removed from drupal:12.0.0. Use
 *   \Drupal\user\UserNameValidator::validateName() instead.
 *
 * @see https://www.drupal.org/node/3431205
 */
function user_validate_name($name) {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:10.3.0 and is removed from drupal:12.0.0. Use \\Drupal\\user\\UserNameValidator::validateName() instead. See https://www.drupal.org/node/3431205', E_USER_DEPRECATED);
  $violations = \Drupal::service('user.name_validator')->validateName($name);
  if (count($violations) > 0) {
    return $violations[0]->getMessage();
  }
}

/**
 * Checks for usernames blocked by user administration.
 *
 * @param string $name
 *   A string containing a name of the user.
 *
 * @return bool
 *   TRUE if the user is blocked, FALSE otherwise.
 *
 * @deprecated in drupal:11.0.0 and is removed from drupal:12.0.0. Use
 * Drupal\user\UserInterface::isBlocked() instead.
 * @see https://www.drupal.org/node/3411040
 */
function user_is_blocked($name) {
  @trigger_error('user_is_blocked() is deprecated in drupal:11.0.0 and is removed from drupal:12.0.0. Use \\Drupal\\user\\UserInterface::isBlocked() instead. See https://www.drupal.org/node/3411040', E_USER_DEPRECATED);
  return (bool) \Drupal::entityQuery('user')->accessCheck(FALSE)
    ->condition('name', $name)
    ->condition('status', 0)
    ->execute();
}

/**
 * Prepares variables for username templates.
 *
 * Default template: username.html.twig.
 *
 * Modules that make any changes to variables like 'name' or 'extra' must ensure
 * that the final string is safe.
 *
 * @param array $variables
 *   An associative array containing:
 *   - account: The user account (\Drupal\Core\Session\AccountInterface).
 *
 * @deprecated in drupal:11.3.0 and is removed from drupal:12.0.0. Initial
 *    template_preprocess functions are registered directly in hook_theme().
 *
 * @see https://www.drupal.org/node/3504125
 */
function template_preprocess_username(&$variables) : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.3.0 and is removed from drupal:12.0.0. Initial template_preprocess functions are registered directly in hook_theme(). See https://www.drupal.org/node/3504125', E_USER_DEPRECATED);
  \Drupal::service(UserThemeHooks::class)->preprocessUsername($variables);
}

/**
 * Finalizes the login process and logs in a user.
 *
 * The function logs in the user, records a watchdog message about the new
 * session, saves the login timestamp, calls hook_user_login(), and generates a
 * new session.
 *
 * The current user is replaced with the passed in account.
 *
 * @param \Drupal\user\UserInterface $account
 *   The account to log in.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *    \Drupal\user\LoginFinalizer::finalizeLogin() instead.
 *
 * @see https://www.drupal.org/node/3379194
 * @see \Drupal\user\Authentication\Provider\Cookie
 * @see hook_user_login()
 */
function user_login_finalize(UserInterface $account) : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\LoginFinalizer::finalizeLogin() instead. See https://www.drupal.org/node/3379194', E_USER_DEPRECATED);
  \Drupal::service(LoginFinalizer::class)->finalizeLogin($account);
}

/**
 * Generates a unique URL for a user to log in and reset their password.
 *
 * @param \Drupal\user\UserInterface $account
 *   An object containing the user account.
 * @param array $options
 *   (optional) A keyed array of settings. Supported options are:
 *   - langcode: A language code to be used when generating locale-sensitive
 *    URLs. If langcode is NULL the users preferred language is used.
 *
 * @return string
 *   A unique URL that provides a one-time log in for the user, from which
 *   they can change their password.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\OneTimeAuthentication::generateOneTimeLoginUrl() instead.
 * @see https://www.drupal.org/node/3581062
 */
function user_pass_reset_url($account, $options = []) {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\OneTimeAuthentication::generateOneTimeLoginUrl() instead. See https://www.drupal.org/node/3581062', E_USER_DEPRECATED);
  return \Drupal::service(OneTimeAuthentication::class)->generateOneTimeLoginUrl($account, $options)
    ->toString();
}

/**
 * Generates a URL to confirm an account cancellation request.
 *
 * @param \Drupal\user\UserInterface $account
 *   The user account object.
 * @param array $options
 *   (optional) A keyed array of settings. Supported options are:
 *   - langcode: A language code to be used when generating locale-sensitive
 *     URLs. If langcode is NULL the users preferred language is used.
 *
 * @return string
 *   A unique URL that may be used to confirm the cancellation of the user
 *   account.
 *
 * @see \Drupal\user\OneTimeAuthentication::tokens()
 * @see \Drupal\user\Controller\UserController::confirmCancel()
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\OneTimeAuthentication::generateCancelConfirmUrl() instead.
 * @see https://www.drupal.org/node/3581062
 */
function user_cancel_url(UserInterface $account, $options = []) {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\OneTimeAuthentication::generateCancelConfirmUrl() instead. See https://www.drupal.org/node/3581062', E_USER_DEPRECATED);
  return \Drupal::service(OneTimeAuthentication::class)->generateCancelConfirmUrl($account, $options)
    ->toString();
}

/**
 * Creates a unique hash value for use in time-dependent per-user URLs.
 *
 * This hash is normally used to build a unique and secure URL that is sent to
 * the user by email for purposes such as resetting the user's password. In
 * order to validate the URL, the same hash can be generated again, from the
 * same information, and compared to the hash value from the URL. The hash
 * contains the time stamp, the user's last login time, the numeric user ID,
 * and the user's email address.
 * For a usage example, see
 * \Drupal\user\OneTimeAuthentication::generateCancelConfirmUrl() and
 * \Drupal\user\Controller\UserController::confirmCancel().
 *
 * @param \Drupal\user\UserInterface $account
 *   An object containing the user account.
 * @param int $timestamp
 *   A UNIX timestamp, typically \Drupal::time()->getRequestTime().
 *
 * @return string
 *   A string that is safe for use in URLs and SQL statements.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\OneTimeAuthentication::generateHmac() instead.
 * @see https://www.drupal.org/node/3581062
 */
function user_pass_rehash(UserInterface $account, $timestamp) {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\OneTimeAuthentication::generateHmac() instead. See https://www.drupal.org/node/3581062', E_USER_DEPRECATED);
  return \Drupal::service(OneTimeAuthentication::class)->generateHmac($account, $timestamp);
}

/**
 * Cancel a user account.
 *
 * Since the user cancellation process needs to be run in a batch, either
 * Form API will invoke it, or batch_process() needs to be invoked after calling
 * this function and should define the path to redirect to.
 *
 * @param array $edit
 *   An array of submitted form values.
 * @param int $uid
 *   The user ID of the user account to cancel.
 * @param string $method
 *   The account cancellation method to use.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal::service(AccountCancellation::class)->cancel() instead.
 *
 * @see https://www.drupal.org/node/3620934
 * @see AccountCancellation::cancelAccount()
 */
function user_cancel($edit, $uid, $method) : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal::service(AccountCancellation::class)->cancel() instead. See https://www.drupal.org/node/3620934', E_USER_DEPRECATED);
  \Drupal::service(AccountCancellation::class)->cancel($edit, $uid, $method);
}

/**
 * Implements callback_batch_operation().
 *
 * Last step for cancelling a user account.
 *
 * Since batch and session API require a valid user account, the actual
 * cancellation of a user account needs to happen last.
 *
 * @param array $edit
 *   An array of submitted form values.
 * @param \Drupal\user\UserInterface $account
 *   The user ID of the user account to cancel.
 * @param string $method
 *   The account cancellation method to use.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal::service(AccountCancellation::class)->cancelAccount() instead.
 *
 * @see https://www.drupal.org/node/3620934
 * @see AccountCancellation::cancel()
 */
function _user_cancel($edit, $account, $method) : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal::service(AccountCancellation::class)->cancelAccount() instead. See https://www.drupal.org/node/3620934', E_USER_DEPRECATED);
  \Drupal::service(AccountCancellation::class)->cancelAccount($edit, $account, $method);
}

/**
 * Implements callback_batch_finished().
 *
 * Finished batch processing callback for cancelling a user account.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\AccountCancellation::regenerateSession() instead.
 *
 * @see https://www.drupal.org/node/3620934
 * @see AccountCancellation::cancel()
 */
function _user_cancel_session_regenerate() : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\AccountCancellation::regenerateSession() instead. See https://www.drupal.org/node/3620934', E_USER_DEPRECATED);
  \Drupal::service(AccountCancellation::class)->regenerateSession();
}

/**
 * Helper function to return available account cancellation methods.
 *
 * See documentation of hook_user_cancel_methods_alter().
 *
 * @return array
 *   An array containing all account cancellation methods as form elements.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\AccountCancellation::cancelMethods() instead.
 *
 * @see https://www.drupal.org/node/3620934
 * @see hook_user_cancel_methods_alter()
 * @see user_admin_settings()
 */
function user_cancel_methods() : array {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\AccountCancellation::cancelMethods() instead. See https://www.drupal.org/node/3620934', E_USER_DEPRECATED);
  return \Drupal::service(AccountCancellation::class)->cancelMethods();
}

/**
 * Token callback to add unsafe tokens for user mails.
 *
 * This function is used by \Drupal\Core\Utility\Token::replace() to set up
 * some additional tokens that can be used in email messages generated by
 * user_mail().
 *
 * @param array $replacements
 *   An associative array variable containing mappings from token names to
 *   values (for use with strtr()).
 * @param array $data
 *   An associative array of token replacement values. If the 'user' element
 *   exists, it must contain a user account object with the following
 *   properties:
 *   - login: The UNIX timestamp of the user's last login.
 *   - pass: The hashed account login password.
 * @param array $options
 *   A keyed array of settings and flags to control the token replacement
 *   process. See \Drupal\Core\Utility\Token::replace().
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\OneTimeAuthentication::tokens() instead.
 * @see https://www.drupal.org/node/3581062
 */
function user_mail_tokens(&$replacements, $data, $options) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\OneTimeAuthentication::tokens() instead. See https://www.drupal.org/node/3581062', E_USER_DEPRECATED);
  $bubbleableMetadata = new BubbleableMetadata();
  \Drupal::service(OneTimeAuthentication::class)->tokens($replacements, $data, $options, $bubbleableMetadata);
}

/**
 * Change permissions for a user role.
 *
 * This function may be used to grant and revoke multiple permissions at once.
 * For example, when a form exposes checkboxes to configure permissions for a
 * role, the form submit handler may directly pass the submitted values for the
 * checkboxes form element to this function.
 *
 * @param mixed $rid
 *   The ID of a user role to alter.
 * @param array $permissions
 *   (optional) An associative array, where the key holds the permission name
 *   and the value determines whether to grant or revoke that permission. Any
 *   value that evaluates to TRUE will cause the permission to be granted.
 *   Any value that evaluates to FALSE will cause the permission to be
 *   revoked.
 *   @code
 *     [
 *       'administer nodes' => 0,                // Revoke 'administer nodes'
 *       'administer blocks' => FALSE,           // Revoke 'administer blocks'
 *       'access user profiles' => 1,            // Grant 'access user profiles'
 *       'access content' => TRUE,               // Grant 'access content'
 *       'access comments' => 'access comments', // Grant 'access comments'
 *     ]
 *   @endcode
 *   Existing permissions are not changed, unless specified in $permissions.
 *
 * @see RoleInterface::grantPermissions()
 * @see RoleInterface::revokePermissions()
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\RoleInterface::changePermissions() instead.
 * @see https://www.drupal.org/node/3348027
 */
function user_role_change_permissions($rid, array $permissions = []) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\RoleInterface::changePermissions() instead. See https://www.drupal.org/node/3348027', E_USER_DEPRECATED);
  $role_storage = \Drupal::entityTypeManager()->getStorage('user_role');
  $role = $role_storage->loadOverrideFree($rid);
  $role?->changePermissions($permissions);
  $role?->save();
}

/**
 * Grant permissions to a user role.
 *
 * @param mixed $rid
 *   The ID of a user role to alter.
 * @param array $permissions
 *   (optional) A list of permission names to grant.
 *
 * @see RoleInterface::changePermissions()
 * @see RoleInterface::revokePermissions()
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\RoleInterface::grantPermissions() instead.
 * @see https://www.drupal.org/node/3348027
 */
function user_role_grant_permissions($rid, array $permissions = []) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\RoleInterface::grantPermissions() instead. See https://www.drupal.org/node/3348027', E_USER_DEPRECATED);
  $role_storage = \Drupal::entityTypeManager()->getStorage('user_role');
  if ($role = $role_storage->loadOverrideFree($rid)) {
    $role->grantPermissions($permissions);
    $role->save();
  }
}

/**
 * Revoke permissions from a user role.
 *
 * @param mixed $rid
 *   The ID of a user role to alter.
 * @param array $permissions
 *   (optional) A list of permission names to revoke.
 *
 * @see RoleInterface::changePermissions()
 * @see RoleInterface::grantPermissions()
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\RoleInterface::revokePermissions() instead.
 * @see https://www.drupal.org/node/3348027
 */
function user_role_revoke_permissions($rid, array $permissions = []) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\RoleInterface::revokePermissions() instead. See https://www.drupal.org/node/3348027', E_USER_DEPRECATED);
  $role_storage = \Drupal::entityTypeManager()->getStorage('user_role');
  $role = $role_storage->loadOverrideFree($rid);
  $role->revokePermissions($permissions);
  $role->save();
}

/**
 * Creates and sends a notification email following a change to a user account.
 *
 * @param string $op
 *   The operation being performed on the account. Possible values:
 *   - 'register_admin_created': Welcome message for user created by the admin.
 *   - 'register_no_approval_required': Welcome message when user
 *     self-registers.
 *   - 'register_pending_approval': Welcome message, user pending admin
 *     approval.
 *   - 'password_reset': Password recovery request.
 *   - 'status_activated': Account activated.
 *   - 'status_blocked': Account blocked.
 *   - 'cancel_confirm': Account cancellation request.
 *   - 'status_canceled': Account canceled.
 * @param \Drupal\Core\Session\AccountInterface $account
 *   The user object of the account being notified. Must contain at
 *   least the fields 'uid', 'name', and 'mail'.
 *
 * @return array|null
 *   An array containing various information about the message. See
 *   \Drupal\Core\Mail\MailManagerInterface::mail() for details. Or null if the
 *   account does not have an email address.
 *
 * @see \Drupal\user\OneTimeAuthentication::tokens()
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use the
 *   methods from Drupal\user\NotificationHandler service instead.
 *
 * @see https://www.drupal.org/node/3539363
 */
function _user_mail_notify($op, AccountInterface $account) {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use the methods from Drupal\\user\\NotificationHandler service instead. See https://www.drupal.org/node/3539363', E_USER_DEPRECATED);
  if (\Drupal::config('user.settings')->get('notify.' . $op)) {
    $params['account'] = $account;
    // Get the custom site notification email to use as the from email address
    // if it has been set.
    $site_mail = \Drupal::config('system.site')->get('mail_notification');
    // If the custom site notification email has not been set, we use the site
    // default for this.
    if (empty($site_mail)) {
      $site_mail = \Drupal::config('system.site')->get('mail');
    }
    if (empty($site_mail)) {
      $site_mail = ini_get('sendmail_from');
    }
    if ($account->getEmail()) {
      $mail = \Drupal::service('plugin.manager.mail')->mail('user', $op, $account->getEmail(), $account->getPreferredLangcode(), $params, $site_mail);
    }
    else {
      \Drupal::logger('user')->info('The User module could not send an email for the operation "%op" because the user account %account does not have an email address.', [
        '%op' => $op,
        '%account' => $account->getDisplayName(),
      ]);
    }
    if ($op == 'register_pending_approval') {
      // If a user registered requiring admin approval, notify the admin, too.
      // We use the site default language for this.
      \Drupal::service('plugin.manager.mail')->mail('user', 'register_pending_approval_admin', $site_mail, \Drupal::languageManager()->getDefaultLanguage()
        ->getId(), $params);
    }
  }
  return empty($mail) ? NULL : $mail['result'];
}

/**
 * Form element process handler for client-side password validation.
 *
 * This #process handler is automatically invoked for 'password_confirm' form
 * elements to add the JavaScript and string translations for dynamic password
 * validation.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use
 *   UserThemeHooks::processPasswordConfirm() instead.
 *
 * @see https://www.drupal.org/node/3582107
 * @see Drupal\user\Hook\UserThemeHooks::processPasswordConfirm()
 */
function user_form_process_password_confirm($element) {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. Use UserThemeHooks::processPasswordConfirm() instead. See https://www.drupal.org/node/3582107', E_USER_DEPRECATED);
  return \Drupal::service(UserThemeHooks::class)->processPasswordConfirm($element);
}

/**
 * Saves visitor information as a cookie so it can be reused.
 *
 * @param array $values
 *   An array of key/value pairs to be saved into a cookie.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. There is no
 *   replacement.
 *
 * @see https://www.drupal.org/node/3581570
 */
function user_cookie_save(array $values) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. There is no replacement. See https://www.drupal.org/node/3581570', E_USER_DEPRECATED);
  $request_time = \Drupal::time()->getRequestTime();
  foreach ($values as $field => $value) {
    // Set cookie for 365 days.
    setrawcookie('Drupal.visitor.' . $field, rawurlencode($value), $request_time + 31536000, '/');
  }
}

/**
 * Delete a visitor information cookie.
 *
 * @param string $cookie_name
 *   A cookie name such as 'homepage'.
 *
 * @deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. There is no
 *   replacement.
 *
 * @see https://www.drupal.org/node/3581570
 */
function user_cookie_delete($cookie_name) : void {
  @trigger_error(__METHOD__ . '() is deprecated in drupal:11.4.0 and is removed from drupal:13.0.0. There is no replacement. See https://www.drupal.org/node/3581570', E_USER_DEPRECATED);
  setrawcookie('Drupal.visitor.' . $cookie_name, '', \Drupal::time()->getRequestTime() - 3600, '/');
}

/**
 * Logs the current user out.
 *
 * @deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use
 *   \Drupal\user\LogoutFinalizer::finalizeLogout() instead.
 *
 * @see https://www.drupal.org/node/3379194
 */
function user_logout() : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.5.0 and is removed from drupal:13.0.0. Use \\Drupal\\user\\LogoutFinalizer::finalizeLogout() instead. See https://www.drupal.org/node/3379194', E_USER_DEPRECATED);
  \Drupal::service(LogoutFinalizer::class)->finalizeLogout();
}

/**
 * Prepares variables for user templates.
 *
 * Default template: user.html.twig.
 *
 * @param array $variables
 *   An associative array containing:
 *   - elements: An associative array containing the user information and any
 *     fields attached to the user. Properties used:
 *     - #user: A \Drupal\user\Entity\User object. The user account of the
 *       profile being viewed.
 *   - attributes: HTML attributes for the containing element.
 *
 * @deprecated in drupal:11.3.0 and is removed from drupal:12.0.0. Initial
 *    template_preprocess functions are registered directly in hook_theme().
 *
 * @see https://www.drupal.org/node/3504125
 */
function template_preprocess_user(&$variables) : void {
  @trigger_error(__FUNCTION__ . '() is deprecated in drupal:11.3.0 and is removed from drupal:12.0.0. Initial template_preprocess functions are registered directly in hook_theme(). See https://www.drupal.org/node/3504125', E_USER_DEPRECATED);
  \Drupal::service(UserThemeHooks::class)->preprocessUser($variables);
}

Functions

Title Deprecated Summary
template_preprocess_user

in drupal:11.3.0 and is removed from drupal:12.0.0. Initial template_preprocess functions are registered directly in hook_theme().

Prepares variables for user templates.
template_preprocess_username

in drupal:11.3.0 and is removed from drupal:12.0.0. Initial template_preprocess functions are registered directly in hook_theme().

Prepares variables for username templates.
user_cancel

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal::service(AccountCancellation::class)->cancel() instead.

Cancel a user account.
user_cancel_methods

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\AccountCancellation::cancelMethods() instead.

Helper function to return available account cancellation methods.
user_cancel_url

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal\user\OneTimeAuthentication::generateCancelConfirmUrl() instead.

Generates a URL to confirm an account cancellation request.
user_cookie_delete

in drupal:11.4.0 and is removed from drupal:13.0.0. There is no replacement.

Delete a visitor information cookie.
user_cookie_save

in drupal:11.4.0 and is removed from drupal:13.0.0. There is no replacement.

Saves visitor information as a cookie so it can be reused.
user_form_process_password_confirm

in drupal:11.4.0 and is removed from drupal:13.0.0. Use UserThemeHooks::processPasswordConfirm() instead.

Form element process handler for client-side password validation.
user_is_blocked

in drupal:11.0.0 and is removed from drupal:12.0.0. Use Drupal\user\UserInterface::isBlocked() instead.

Checks for usernames blocked by user administration.
user_load_by_mail

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal::entityTypeManager()->getStorage('user')->loadByProperties() instead.

Fetches a user object by email address.
user_load_by_name

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal::entityTypeManager()->getStorage('user')->loadByProperties() instead.

Fetches a user object by account name.
user_login_finalize

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\LoginFinalizer::finalizeLogin() instead.

Finalizes the login process and logs in a user.
user_logout

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\LogoutFinalizer::finalizeLogout() instead.

Logs the current user out.
user_mail_tokens

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal\user\OneTimeAuthentication::tokens() instead.

Token callback to add unsafe tokens for user mails.
user_pass_rehash

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal\user\OneTimeAuthentication::generateHmac() instead.

Creates a unique hash value for use in time-dependent per-user URLs.
user_pass_reset_url

in drupal:11.4.0 and is removed from drupal:13.0.0. Use \Drupal\user\OneTimeAuthentication::generateOneTimeLoginUrl() instead.

Generates a unique URL for a user to log in and reset their password.
user_picture_enabled

in drupal:11.5.0 and is removed from drupal:13.0.0. There is no replacement, check the definition directly.

Returns whether this site supports the default user picture feature.
user_role_change_permissions

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\RoleInterface::changePermissions() instead.

Change permissions for a user role.
user_role_grant_permissions

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\RoleInterface::grantPermissions() instead.

Grant permissions to a user role.
user_role_revoke_permissions

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\RoleInterface::revokePermissions() instead.

Revoke permissions from a user role.
user_validate_name

in drupal:10.3.0 and is removed from drupal:12.0.0. Use \Drupal\user\UserNameValidator::validateName() instead.

Verify the syntax of the given name.
_user_cancel

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal::service(AccountCancellation::class)->cancelAccount() instead.

Implements callback_batch_operation().
_user_cancel_session_regenerate

in drupal:11.5.0 and is removed from drupal:13.0.0. Use \Drupal\user\AccountCancellation::regenerateSession() instead.

Implements callback_batch_finished().
_user_mail_notify

in drupal:11.5.0 and is removed from drupal:13.0.0. Use the methods from Drupal\user\NotificationHandler service instead.

Creates and sends a notification email following a change to a user account.

Buggy or inaccurate documentation? Please file an issue. Need support? Need help programming? Connect with the Drupal community.