Weight field access is not checked

Created on 14 April 2023, over 1 year ago
Updated 28 April 2023, over 1 year ago

Problem/Motivation

The AJAX endpoint access handler only checks full entity update access, not field-level field access. This means that if a user has node edit access, but access to the weight field was restricted using e.g. the Field Permissions module , the field will still be updated.

Steps to reproduce

Restrict access to the weight field using the Field Permissions module and try to re-order entities.

Proposed resolution

Add a field-level access check.

🐛 Bug report
Status

Fixed

Version

1.0

Component

Code

Created by

🇧🇪Belgium dieterholvoet Brussels

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024