Link field > Access to internal links is not checked on display.

Created on 21 June 2023, about 1 year ago

Problem/Motivation

When a link field is displayed, the current user's access to the linked content isn't checked, so links to unpublished content are displayed to anonymous users. When they try to access this content, they get a 403 error.

Steps to reproduce

  1. Create a node with a link field.
  2. Insert an unpublished internal link
  3. Navigate through the page as an anonymous user. You'll see the link. When you click on it, you'll get a 403 error.

Proposed resolution

Hide all links where the linked entity is unpublished.

✨ Feature request
Status

Needs work

Version

11.0 πŸ”₯

Component
LinkΒ  β†’

Last updated 3 days ago

Created by

πŸ‡ͺπŸ‡ΈSpain orodicio

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024