Unverified Commit a54ef47f authored by Alex Pott's avatar Alex Pott
Browse files

Issue #3021247 by jeqq, alexpott, amateescu: Bypass workspace access...

Issue #3021247 by jeqq, alexpott, amateescu: Bypass workspace access permission is not working as expected

(cherry picked from commit 62538991)
parent f10c52b7
Loading
Loading
Loading
Loading
+4 −2
Changes for core/modules/workspaces/src/EntityAccess.php: 4 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -124,8 +124,10 @@ protected function bypassAccessResult(AccountInterface $account) {
    // to ALL THE THINGS! That's why this is a dangerous permission.
    $active_workspace = $this->workspaceManager->getActiveWorkspace();

    return AccessResult::allowedIf($active_workspace->getOwnerId() == $account->id())->cachePerUser()->addCacheableDependency($active_workspace)
      ->andIf(AccessResult::allowedIfHasPermission($account, 'bypass entity access own workspace'));
    $owner_has_access = AccessResult::allowedIf($active_workspace->getOwnerId() == $account->id())
      ->cachePerUser()->addCacheableDependency($active_workspace);
    $access_bypass = AccessResult::allowedIfHasPermission($account, 'bypass entity access own workspace');
    return $owner_has_access->orIf($access_bypass);
  }

}
+3 −3
Changes for core/modules/workspaces/tests/src/Functional/WorkspaceBypassTest.php: 3 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -55,10 +55,10 @@ public function testBypassOwnWorkspace() {
    $this->drupalLogin($lombardi);
    $this->switchToWorkspace($bears);

    // Because editor 2 has the bypass permission, he should be able to create
    // and edit any node.
    // Editor 2 should be able to create and edit any node because of the
    // assigned bypass permission.
    $this->drupalGet('/node/' . $ditka_bears_node_id . '/edit');
    $this->assertSession()->statusCodeEquals(403);
    $this->assertSession()->statusCodeEquals(200);
  }

}