User without publish permissions can use entity-clone to publish nodes

Created on 31 July 2023, over 1 year ago

User with "clone content" permission, but without the permission to publish nodes, can create an unpublished node, tick the "clone as published" checkbox, and create a published version of the same node.

Seems like they should not be able to do this, but I'm not sure the best way to fix.

🐛 Bug report
Status

Active

Version

2.0

Component

Code

Created by

🇺🇸United States AaronBauman Philadelphia

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024