Views relation bypasses field permission

Created on 2 May 2024, 9 months ago

Problem/Motivation

Views relation bypasses field permissions when field is used as relation.

Steps to reproduce

  1. Create user role which has permission to view users
  2. Create user reference field (field_user) with field permissions
  3. Remove field_user view permission from role created in step 1
  4. Create view where field_user is used as relation
  5. Add name field with relation to field_user to view
  6. Log in with user that doesn't have permission to view field_user and go to view.

Proposed resolution

Add permission handling for field relations.

🐛 Bug report
Status

Active

Version

1.0

Component

Code

Created by

🇫🇮Finland jviitamaki

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024