- Issue created by @Juanjol
The Media Library views provided by Drupal core are based on the "View media" permission, which can be granted to various roles. However, access to the displays within the views is restricted via additional runtime logic that Xray does not detect. As a result, Xray reports these views as publicly accessible when they are not, leading to false positives in security audits.
None expected, unless an exception list or UI feedback is added to the Xray module.
Possibly extend Xrayβs internal APIs to support access override detection or exception registration.
None.
Active
1.0
Code