Entity access is ignoring in "Custom content list block" block type

Created on 6 February 2023, over 1 year ago
Updated 14 March 2023, over 1 year ago

Problem/Motivation

Anonymous users can see community secret flexible group teasers in "Custom content list block" block:

Should be:

Steps to reproduce

  1. Login as admin
  2. Create flexible groups with different visibilities: public, community, secret
  3. Create a "Custom content list block" on /block/add/custom_content_list
  4. Place block to any visible region on "Block layout" (for example, "Page title") to display created groups
  5. As anonymous user visit the page where this block appears

Proposed resolution

Add access check before entities view build.

Remaining tasks

n/a

User interface changes

n/a

API changes

n/a

Data model changes

n/a

🐛 Bug report
Status

Fixed

Version

11.6

Component

Code (back-end)

Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.69.0 2024