Clarify security implications of granting "View any Product product" permission

Created on 8 October 2011, over 12 years ago
Updated 7 February 2023, over 1 year ago

Hey Ryan and all,

A quick Drupal Commerce permission question just came up: What are the security implications of granting all users (both anonymous and authenticated) the "View any Product product" permission? There is a security warning on that permission, but I can't seem to find anything particularly bad if all users are granted this permission.

The use case I've got is that if I want fields attached to a product to display in a view--and if that view is placed in a panel that is overriding a node--I can't get the product fields to show up for the user unless I grant the user the "View any Product product" permission.

Thoughts?

Thanks,
Ben

πŸ“Œ Task
Status

RTBC

Version

1.0

Component

Product

Created by

πŸ‡ΊπŸ‡ΈUnited States BenK

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡©πŸ‡ͺGermany gngn

    I added a version of #75 for current 7.x-1.x-dev (26 February 2010).

    No changes to #75 (i.e. just the diff line numbers).

Production build 0.69.0 2024