Pending changes leaking entities that user might have no access to

Created on 10 July 2025, 2 days ago

Overview

Pending changes leaking entities that user might have no access to.

Our access controls prevents that we can publish those changes, but the editor would still see the content label and that it's changed.

Proposed resolution

Access checks on ApiAutoSaveController::get

User interface changes

Editors won't see content on the publish panel they don't have access to.

πŸ› Bug report
Status

Active

Version

0.0

Component

Internal HTTP API

Created by

πŸ‡ͺπŸ‡ΈSpain penyaskito Seville πŸ’ƒ, Spain πŸ‡ͺπŸ‡Έ, UTC+2 πŸ‡ͺπŸ‡Ί

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024