Use a restricted permission for specifying binary paths

Created on 21 May 2025, about 2 months ago

Problem/Motivation

Users with the "administer image optimize pipelines" permission can specify arbitrary paths to binaries, that can later be triggered to execute on demand when an image variant is requested. This permission is not marked as restricted, but allowing an unprivileged user to run arbitrary binaries on the filesystem could be unexpected and dangerous in some cases.

This project is not covered by the Drupal security team, discussed with @mcdruid and we agreed to open this issue in the public queue.

Steps to reproduce

Proposed resolution

Mark "administer image optimize pipelines" as restricted or add a new restricted permission for configuring binary paths.

Remaining tasks

User interface changes

API changes

Data model changes

📌 Task
Status

Active

Version

1.0

Component

Code

Created by

🇬🇧United Kingdom longwave UK

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024