Link field > Access to internal links is not checked on display.

Created on 21 June 2023, almost 2 years ago

Problem/Motivation

When a link field is displayed, the current user's access to the linked content isn't checked, so links to unpublished content are displayed to anonymous users. When they try to access this content, they get a 403 error.

Steps to reproduce

  1. Create a node with a link field.
  2. Insert an unpublished internal link
  3. Navigate through the page as an anonymous user. You'll see the link. When you click on it, you'll get a 403 error.

Proposed resolution

Hide all links where the linked entity is unpublished.

Feature request
Status

Active

Version

9.5

Component
Link 

Last updated 2 days ago

Created by

🇪🇸Spain orodicio

Live updates comments and jobs are added and updated live.
  • Needs tests

    The change is currently missing an automated test that fails when run with the original code, and succeeds when the bug has been fixed.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024