Skip to header Skip to main navigation Skip to main content Skip to footer
Cookies UI
Site branding
Alaa Haddad - Drupal Expert
Consultant • Architect • Developer • Themer - Expert Drupal Solutions
Main navigation
Alaa Haddad Offers Exceptional Drupal Custom Theming and Modules in Austin TX Alaa Haddad - Drupal Expert
  • Professional Profile
  • Drupal Services
    • Drupal Development
    • Drupal Developer
    • Drupal Themer
    • Drupal Architect
    • Drupal Consultant
  • My Drupal Modules & Themes
      • Cloudflare Purge
      • Solo Copy Blocks
      • W3CSS Paragraphs
      • Paragraphs Bundles
      • Acquia Purge Varnish
      • Reference Blocked Users
      • Module Matrix
      • Paragraphs Bundles Import
      • Selectify
      • Solo Utilities
      • Utilikit
      • Solo
      • Amun
      • Anhur
      • Amunet
      • W3CSS Theme
      • 3D Carousel
      • 3D FlipBox
      • Accordion
      • Carousel
      • Hero
      • Lightbox
      • Parallax
      • Reveal
      • Slideshow
      • Tabs
  • Blog
  • Videos
  • Contact
  • Hire Me (opens in new tab)

Reference Blocked Users (Drupal Module)

Breadcrumbs

Breadcrumb

  • Home
  • Drupal Modules
  • Reference Blocked Users (Drupal Module)

Main page content

Alaa Haddad, professional Drupal developer based in Austin, TX   Alaa Haddad
  11:00 PM CDT, Sun September 13, 2026
Share

Reference Blocked Users adds one permission that lets an editor reference blocked accounts, not just active ones, in the "Authored by" field and in any custom entity reference field that points at users. It requires Drupal 11.3 or 12 and has no other module dependencies.

The gap it closes

Drupal core's user reference widget quietly filters blocked accounts out of the autocomplete unless the person doing the searching holds Administer users — a permission that also grants far more than reference access, which is exactly why most sites will not hand it to a content editor. The practical result: an editor trying to set "Authored by" to a former employee's account, or attribute a historical piece to a writer who has since been blocked, cannot find that user at all.

There is an open core issue for adding a configuration option to custom reference fields, but the "Authored by" field ships with no configuration form to attach one to — the core issue explains why. This module sidesteps the gap with a single permission that applies to both cases at once.

Requirements

Requirements, from reference_blocked_users.info.yml
RequirementValue
Drupal core^11.3 || ^12
Other modulesNone declared

Version 2 rebuilt the selection plugin around the modern #[EntityReferenceSelection] PHP attribute rather than the old annotation — the discovery mechanism Drupal 12 dropped support for entirely — so it installs cleanly on 12 without the "no longer supported" fatal that hits modules still carrying only an annotation. Sites still on Drupal 9 or 10 need the project's 1.x branch — this is a branch-support note from the project record, not something the code itself can confirm.

How the permission behaves

The module registers a selection plugin, default:reference_blocked_users, that extends Drupal core's own UserSelection rather than replacing it. It only changes behavior for one specific combination: a user who does not hold Administer users but does hold the new Reference blocked users permission. Everyone else — including anyone who already has Administer users — gets exactly Drupal core's stock behavior, unchanged.

What the widened query actually returns

For a user with the new permission, the plugin builds its own entity query instead of delegating to core: every account regardless of blocked status, filtered only by whatever role restriction the field's own configuration specifies, with the anonymous user excluded unless the field is explicitly configured to include it.

Searching by email, not just username

This is the one behavior change in version 2.0: the autocomplete now matches the typed text against the user's email address as well as their username, using an OR condition across both columns. Drupal core's own selection handler only ever matches the username, so an editor who remembers a contributor by their email rather than their login name previously had no way to find them at all.

Setting it up

composer require drupal/reference_blocked_users
drush en reference_blocked_users -y

Then grant the Reference blocked users permission to whichever role should see blocked accounts in reference fields — typically an editor or content-manager role, not the roles that already carry Administer users. There is no separate configuration screen; the permission is the entire interface.

Proving it works on your own site

  1. Create a role without Administer users, grant it Reference blocked users, and assign it to a test account.
  2. On the Article content type, add a plain entity reference field targeting users, alongside the built-in Authored by field.
  3. Block one of your test user accounts.
  4. Log in as the role you just built and open the article edit form.
  5. Both the Authored by field and your custom field should now offer the blocked account in autocomplete — and typing part of its email address should find it too.

If the blocked account still does not appear, check that the role genuinely lacks Administer users — that permission takes the core code path, not this module's, and core's default query already shows blocked accounts to administrators, which can make the module look inactive when it is simply not the plugin doing the work.

Common questions

Does this weaken user privacy or security in any way?

No new data is exposed. Blocked accounts already exist in the system and are visible to anyone with Administer users; this permission only extends who can pick them from a reference field's autocomplete, and it is a separate, narrowly scoped permission an administrator assigns deliberately.

Will it work with fields other than "Authored by"?

Yes. Any entity reference field configured to target the user entity type picks up the widened selection once the field's reference method uses the default selection plugin and the viewing user holds the permission.

Do I need to configure anything on the field itself?

No. The behavior change lives entirely in the selection plugin and the permission — there is nothing to toggle on the field's own reference settings.

What happens on Drupal 10?

This 2.x line requires 11.3 or 12 and will refuse to install below that. The project maintains a 1.x branch for older cores.

Need a hand with a Drupal permissions or access problem?

Reference Blocked Users is free, like the rest of my contributed work on drupal.org. If your project has a messier access-control problem than one permission can solve, that is the kind of work I take on directly.

Read about my Drupal services, see what a Drupal developer actually does day to day, or get in touch.

Reference Blocked Users
Slide 1 of 27
Acquia Purge Varnish - API V2 (Drupal Module)
Slide 2 of 27
Amun - W3CSS Sub-Theme (Drupal Theme)
Slide 3 of 27
Amunet - W3CSS Sub-Theme (Drupal Theme)
Slide 4 of 27
Anhur - W3CSS Sub-Theme (Drupal Theme)
Slide 5 of 27
Cloudflare Purge (Drupal Module)
Slide 6 of 27
Module Matrix (Drupal Module)
Slide 7 of 27
Paragraphs Bundles (Drupal Module)
Slide 8 of 27
Paragraphs Bundles Import (Drupal Module)
Slide 9 of 27
Reference Blocked Users (Drupal Module)
Slide 10 of 27
Selectify (Drupal Module)
Slide 11 of 27
Solo (Drupal Theme)
Slide 12 of 27
Solo Copy Blocks (Drupal Module)
Slide 13 of 27
Solo Utilities (Drupal Module)
Slide 14 of 27
Utilikit (Drupal Module)
Slide 15 of 27
Views 3D Carousel (Drupal Module)
Slide 16 of 27
Views 3D FlipBox (Drupal Module)
Slide 17 of 27
Views Accordion (Drupal Module)
Slide 18 of 27
Views Carousel (Drupal Module)
Slide 19 of 27
Views Hero (Drupal Module)
Slide 20 of 27
Views Lightbox (Drupal Module)
Slide 21 of 27
Views Parallax (Drupal Module)
Slide 22 of 27
Views Reveal (Drupal Module)
Slide 23 of 27
Views Slideshow (Drupal Module)
Slide 24 of 27
Views Tabs (Drupal Module)
Slide 25 of 27
VVJ Core (Drupal Module)
Slide 26 of 27
W3CSS Paragraphs (Drupal Module)
Slide 27 of 27
W3CSS Theme (Drupal Theme)
1 of 27

Our mission is to make Drupal more accessible and user-friendly, empowering businesses of all sizes, especially small enterprises with powerful tools that streamline content customization and enhance digital experiences.

Need help with your Drupal project? Hire Me through Flash Web Center, LLC.

Search

The Drupal 11 Module and Theme Stack, With Versions Checked

ARIA Live Regions in Drupal 11: What Core Does, What You Add

Drupal Architect: The Decisions Expensive to Reverse

Drupal Services: Development, Theming, Upgrades | Austin TX

Paragraphs Bundles

Drupal Module - Paragraphs Bundles

Drupal Theme - Solo

Drupal Theme - Solo

Drupal Work List - Drupal Work

Reference Blocked Users (Drupal Module)

Solo Utilities (Drupal Module)

Views Hero (Drupal Module)

Solo (Drupal Theme)

Paragraphs Bundles Import (Drupal Module)

Drupal Theme - W3CSS Theme

Drupal Theme - W3CSS Theme

Drupal Module - W3CSS Paragraphs

Drupal Module - W3CSS Paragraphs

Inspiration

Inspiration is the fuel that powers our creative engine, often coming from our surroundings, experiences, or the works of others. It's that magical moment when something clicks inside your brain, and you suddenly see a path forward that you hadn't noticed before. Inspiration can strike at any time, providing the motivation and energy needed to explore new possibilities and bring your ideas to life.

Unique Ideas

Unique Ideas

Unique ideas are the seeds of innovation, representing original thoughts or concepts that stand out from the usual. They're the sparks that ignite the process of creating something new and different, often leading to unexpected and groundbreaking solutions or products. Whether in art, science, business, or technology, unique ideas challenge the status quo and pave the way for progress.

Brainstorming

Brainstorming

Brainstorming is a creative group activity designed to generate a large number of ideas or solutions to a problem. It's a free-flowing and open-ended discussion where every suggestion is welcomed and considered, no matter how outlandish it may seem. Brainstorming encourages thinking outside the box, fostering an environment where creativity and collaboration lead to innovative solutions.

Planning

Planning

Planning is the blueprint for turning your ideas into reality. It involves setting goals, outlining steps, and organizing resources in a way that makes achieving your objectives possible. Good planning considers potential challenges and opportunities, making it easier to navigate the journey from concept to completion. It's about preparing the groundwork so that your projects can grow and flourish.

Drupal Developer

A Drupal Developer stands as the technical powerhouse behind dynamic websites, wielding expertise in PHP, custom module development, and Drupal's sophisticated API ecosystem. This role transforms business requirements into functional, secure, and scalable web solutions that power everything from small business sites to enterprise platforms serving millions of users. A Drupal Developer's expertise spans the entire development lifecycle—from architecting custom modules and integrating third-party services to optimizing performance and ensuring security compliance. Discover the complete guide to Drupal Developer skills, career paths, and hiring strategies.

Drupal Themer

A Drupal Themer serves as the artistic craftsperson who transforms wireframes and design mockups into pixel-perfect, accessible, and responsive user experiences using Twig templates, CSS, and JavaScript. This specialized role bridges the gap between design vision and technical implementation, ensuring every website not only looks exceptional but performs flawlessly across all devices and meets WCAG accessibility standards. A Drupal Themer's work encompasses the entire front-end ecosystem—from creating custom theme architectures and optimizing Core Web Vitals to implementing complex responsive designs and ensuring seamless integration with Drupal's rendering system. Explore the comprehensive guide to Drupal Themer expertise, theming best practices, and career advancement.

Drupal Architect

A Drupal Architect emerges as the strategic visionary of web construction, armed with encyclopedic knowledge of enterprise architecture patterns, infrastructure design, and Drupal's extensive technological ecosystem. This senior role operates at the highest technical level, making critical decisions that determine whether complex implementations scale successfully or collapse under real-world demands. A Drupal Architect's responsibilities begin long before development starts—during strategic planning phases where the foundation for secure, performant, and maintainable systems is established through careful evaluation of technology stacks, integration strategies, and scalability requirements. Learn about Drupal Architect skills, enterprise architecture strategies, and career progression to principal roles.

Footer menu

  • Contact
  • Professional Resume
  • Resume Summary
  • Technical Skills
  • Privacy Policy
  • Terms & Conditions
  • Search
  • Login
  • Sitemap

Copyright © 2026 Flash Web Center, LLC - All rights reserved

Developed & Designed by Alaa Haddad