Module forbidding the 'edit' operation on the User entity's 'pass' field would prevent editing security-sensitive base fields

Created on 12 December 2017, over 6 years ago
Updated 11 February 2023, over 1 year ago

Problem/Motivation

See #2824851-197: EntityResource::patch() makes an incorrect assumption about entity keys, hence results in incorrect behavior

Proposed resolution

Remaining tasks

Update issue summary
Review code.

User interface changes

API changes

Data model changes

🐛 Bug report
Status

Needs work

Version

10.1

Component
User module 

Last updated 1 day ago

Created by

🇧🇪Belgium Wim Leers Ghent 🇧🇪🇪🇺

Live updates comments and jobs are added and updated live.
  • Needs issue summary update

    Issue summaries save everyone time if they are kept up-to-date. See Update issue summary task instructions.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • The Needs Review Queue Bot tested this issue. It either no longer applies to Drupal core, or fails the Drupal core commit checks. Therefore, this issue status is now "Needs work".

    Apart from a re-roll or rebase, this issue may need more work to address feedback in the issue or MR comments. To progress an issue, incorporate this feedback as part of the process of updating the issue. This helps other contributors to know what is outstanding.

    Consult the Drupal Contributor Guide to find step-by-step guides for working with issues.

  • 🇮🇳India pooja saraah Chennai

    Fixed failed commands on #25
    Attached patch against Drupal 10.1.x

  • Status changed to Needs review over 1 year ago
  • Status changed to Needs work over 1 year ago
  • 🇺🇸United States smustgrave

    This issue is being reviewed by the kind folks in Slack, #needs-review-queue-initiative. We are working to keep the size of Needs Review queue [2700+ issues] to around 400 (1 month or less), following Review a patch or merge request as a guide.

    For the issue summary requested in #16.

    Fyi rerolls should not be put into review when there are outstanding issues.

Production build 0.71.5 2024