Forward-port non-security-parts of SA-CORE-2014-003 file access bypass fixes to Drupal 8

Created on 30 March 2015, about 10 years ago
Updated 7 May 2025, 3 days ago

The security fixes for the file bypass access issues in SA-CORE-2014-003 β†’ wound up being very different between Drupal 7 and Drupal 8.

In Drupal 7, there was:

In Drupal 8, there was:

Security-wise they both work and Drupal 8 does not appear to have any functional regressions either but there are a couple things from the various Drupal 7 commits that would be good to add to Drupal 8:

  1. Something comparable to file_download_access(), which looks like a useful API function to me for Drupal 8 too.
  2. The tests that were added in http://cgit.drupalcode.org/drupal/commit/?id=b90a53201d7c3ce0dc3a240d537... (although the regression was never present in Drupal 8, it still would probably be good to have the tests).
πŸ“Œ Task
Status

Postponed: needs info

Version

11.0 πŸ”₯

Component

file system

Created by

πŸ‡ΊπŸ‡ΈUnited States David_Rothstein

Live updates comments and jobs are added and updated live.
  • stale-issue-cleanup

    To track issues in the developing policy for closing stale issues, [Policy, no patch] closing older issues

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • πŸ‡ΊπŸ‡ΈUnited States smustgrave

    Thank you for creating this issue to improve Drupal.

    We are working to decide if this task is still relevant to a currently supported version of Drupal. There hasn't been any discussion here for over 8 years which suggests that this has either been implemented or is no longer relevant. Your thoughts on this will allow a decision to be made.

    Since we need more information to move forward with this issue, the status is now Postponed (maintainer needs more info). If we don't receive additional information to help with the issue, it may be closed after three months.

Production build 0.71.5 2024