eca_config_action denies access in boolean form and has no test coverage
Problem/Motivation
Comprehensive ECA 3.1.x code review (2026-08-17) found that ConfigAction::access() always reports denied.
modules/config/src/Plugin/Action/ConfigAction.php:80:
return $return_as_object ? $result->cachePerPermissions() : FALSE;When $return_as_object is FALSE (the default), the method returns literal FALSE regardless of the actual authorization result. ECA's own executor passes TRUE, so ECA runtime is unaffected, but any consumer using the boolean form (core action UI, PreConfiguredAction, other non-ECA callers) sees a spurious denial. execute() still performs the operation, so the two are inconsistent.
The plugin has zero tests in modules/config/tests, which is why this slipped through.
Proposed resolution
- Fix
access()to return$result->isAllowed()in the boolean branch (and considercachePerPermissions()on the initialforbidden()). - Add a unit/kernel test covering
ConfigAction::access()in both forms (boolean and object) for the allowed and denied cases.