- Issue created by @uditrawat
- First commit to issue fork.
- Status changed to Needs review
11 months ago 6:19pm 3 January 2024 - 🇺🇸United States greggles Denver, Colorado, USA
longwave → credited greggles → .
- 🇬🇧United Kingdom longwave UK
Saving issue credits based on the triage done over on security.drupal.org.
- Status changed to Needs work
11 months ago 6:45pm 3 January 2024 - 🇺🇸United States smustgrave
seems to be failing a number of rest tests. Should they be updated or the solution relooked at?
- Assigned to larowlan
- Issue was unassigned.
- Status changed to Needs review
11 months ago 10:02pm 3 January 2024 - 🇦🇺Australia larowlan 🇦🇺🏝.au GMT+10
Addressed failure, which was also asserting that revision info was available to non admin users 🙃
- 🇦🇺Australia larowlan 🇦🇺🏝.au GMT+10
Clarifying title, because whilst they can view the list and published revisions, they can't interact with the revision UI (e.g. revert revisions, delete revisions etc)
- 🇧🇪Belgium wim leers Ghent 🇧🇪🇪🇺
I think this should be reviewed by >=1 media system maintainer?
- Status changed to RTBC
11 months ago 9:45am 4 January 2024 - 🇬🇧United Kingdom catch
I was concerned that we were opening up a new information disclosure bug by removing the entity access checks with the original fix here, turns out we were, but @larowlan added extra test coverage and restored some of that logic (in a place that actually works correctly).
For me this is RTBC now, I've also pinged the media system maintainers for a review in slack per #19.
- 🇬🇧United Kingdom alexpott 🇪🇺🌍
Committed and pushed 8f3f374984 to 11.x and 8a4467d55e to 10.2.x. Thanks!
-
alexpott →
committed 8a4467d5 on 10.2.x
Issue #3411837 by larowlan, longwave, catch, uditrawat, marcoscano,...
-
alexpott →
committed 8a4467d5 on 10.2.x
- Status changed to Fixed
11 months ago 10:54am 4 January 2024 -
alexpott →
committed 8f3f3749 on 11.x
Issue #3411837 by larowlan, longwave, catch, uditrawat, marcoscano,...
-
alexpott →
committed 8f3f3749 on 11.x
Automatically closed - issue fixed for 2 weeks with no activity.