eca_config_action denies access in boolean form and has no test coverage

Problem/Motivation

Comprehensive ECA 3.1.x code review (2026-08-17) found that ConfigAction::access() always reports denied.

modules/config/src/Plugin/Action/ConfigAction.php:80:

return $return_as_object ? $result->cachePerPermissions() : FALSE;

When $return_as_object is FALSE (the default), the method returns literal FALSE regardless of the actual authorization result. ECA's own executor passes TRUE, so ECA runtime is unaffected, but any consumer using the boolean form (core action UI, PreConfiguredAction, other non-ECA callers) sees a spurious denial. execute() still performs the operation, so the two are inconsistent.

The plugin has zero tests in modules/config/tests, which is why this slipped through.

Proposed resolution

  • Fix access() to return $result->isAllowed() in the boolean branch (and consider cachePerPermissions() on the initial forbidden()).
  • Add a unit/kernel test covering ConfigAction::access() in both forms (boolean and object) for the allowed and denied cases.