Vocabulary Tree access check needs to be implemented

Created on 3 April 2024, 9 months ago

Problem/Motivation

Just found this TODO in 5.x:

  /**
   * {@inheritdoc}
   */
  /*public function processRoute(Route $route) {
  // @todo Check perms of taxonomy vocabulary access.
  //$route->setRequirement('_entity_access', $this->getDerivativeId() .'.view');
  }*/

in class VocabularyTreeGet
(https://git.drupalcode.org/project/services/-/blob/5.x/src/Plugin/Servic...)

Leaving this issue as reminder to implement it for security.

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

📌 Task
Status

Active

Version

5.0

Component

Code

Created by

🇩🇪Germany Anybody Porta Westfalica

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024