Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 303327

Base entity fields using 'standard' plugin added via EntityViewsData to not respect field level access

$
0
0

Problem/Motivation

Views uses EntityViewsData and sub-classes to generate views data for entity base fields.
The bulk of these use the 'standard' plugin which extends from HandlerBase.
HandlerBase::access does not respect field level access.
As a result no field level-access is applied for entity base when used in views.
Patch demonstrates that comment's hostname field level access isn't respected.

Proposed resolution

Make the 'standard' plugin defer to the relevant entity access controller.

Remaining tasks

Patch
Review

User interface changes

none

API changes

none

Beta phase evaluation

Reference: https://www.drupal.org/core/beta-changes
Issue categoryBug because if you implement an access plugin to define field level access, you'd expect views to respect it
Issue priorityCritical because security

Viewing all articles
Browse latest Browse all 303327

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>