Loading src/Access/SchedulerRouteAccess.php +4 −4 Changes for src/Access/SchedulerRouteAccess.php: 4 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -17,10 +17,10 @@ class SchedulerRouteAccess { * * A user is given access if either of the following conditions are met: * - they are viewing their own page and they have the permission to schedule * content of the required type. * content or view scheduled content of the required type. * - they are viewing another user's page and they have permission to view * user profiles and view scheduled content, and the user they are viewing has * permission to schedule content (otherwise the list would always be empty). * permission to schedule content or view scheduled content. * * @param \Drupal\Core\Session\AccountInterface $account * The currently logged in account. Loading @@ -38,12 +38,12 @@ class SchedulerRouteAccess { $viewing_permission_name = $scheduler_manager->permissionName($entityTypeId, 'view'); $scheduling_permission_name = $scheduler_manager->permissionName($entityTypeId, 'schedule'); if ($viewing_own_page && $account->hasPermission($scheduling_permission_name)) { if ($viewing_own_page && ($account->hasPermission($viewing_permission_name) || $account->hasPermission($scheduling_permission_name))) { return AccessResult::allowed(); } if (!$viewing_own_page && $account->hasPermission($viewing_permission_name) && $account->hasPermission('access user profiles')) { $other_user = User::load($user_being_viewed); if ($other_user && $other_user->hasPermission($scheduling_permission_name)) { if ($other_user && ($other_user->hasPermission($viewing_permission_name) || $other_user->hasPermission($scheduling_permission_name))) { return AccessResult::allowed(); } } Loading tests/src/Functional/SchedulerViewsAccessTest.php +14 −6 Changes for tests/src/Functional/SchedulerViewsAccessTest.php: 14 added lines, 6 removed lines. Original line number Diff line number Diff line Loading @@ -110,11 +110,14 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase { // Try to access a user's own scheduled content tab when that user only has // 'view scheduled {type}' and not 'schedule publishing of {type}'. This is // not allowed and the tab will not be availbale as that view will always be // empty because the user will never have any scheduled content. // allowed and should give "200 OK" and show the users scheduled items. $this->drupalLogin($this->schedulerViewer); $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end"); $assert->statusCodeEquals(403); $assert->statusCodeEquals(200); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing"); // Access another user's scheduled content tab. This should not be possible // and will give "403 Access Denied". Loading @@ -132,10 +135,15 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase { $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for unpublishing"); // Try to access the scheduled tab for a user who cannot schedule content. // No tab will be shown and access is denied as it will always be empty. // Try to access the scheduled tab for a user who cannot schedule content // themselves but can view their scheduled content if scheduled by someone // else. This should give "200 OK" and the scheduled items will be shown. $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end"); $assert->statusCodeEquals(403); $assert->statusCodeEquals(200); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing"); } /** Loading Loading
src/Access/SchedulerRouteAccess.php +4 −4 Changes for src/Access/SchedulerRouteAccess.php: 4 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -17,10 +17,10 @@ class SchedulerRouteAccess { * * A user is given access if either of the following conditions are met: * - they are viewing their own page and they have the permission to schedule * content of the required type. * content or view scheduled content of the required type. * - they are viewing another user's page and they have permission to view * user profiles and view scheduled content, and the user they are viewing has * permission to schedule content (otherwise the list would always be empty). * permission to schedule content or view scheduled content. * * @param \Drupal\Core\Session\AccountInterface $account * The currently logged in account. Loading @@ -38,12 +38,12 @@ class SchedulerRouteAccess { $viewing_permission_name = $scheduler_manager->permissionName($entityTypeId, 'view'); $scheduling_permission_name = $scheduler_manager->permissionName($entityTypeId, 'schedule'); if ($viewing_own_page && $account->hasPermission($scheduling_permission_name)) { if ($viewing_own_page && ($account->hasPermission($viewing_permission_name) || $account->hasPermission($scheduling_permission_name))) { return AccessResult::allowed(); } if (!$viewing_own_page && $account->hasPermission($viewing_permission_name) && $account->hasPermission('access user profiles')) { $other_user = User::load($user_being_viewed); if ($other_user && $other_user->hasPermission($scheduling_permission_name)) { if ($other_user && ($other_user->hasPermission($viewing_permission_name) || $other_user->hasPermission($scheduling_permission_name))) { return AccessResult::allowed(); } } Loading
tests/src/Functional/SchedulerViewsAccessTest.php +14 −6 Changes for tests/src/Functional/SchedulerViewsAccessTest.php: 14 added lines, 6 removed lines. Original line number Diff line number Diff line Loading @@ -110,11 +110,14 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase { // Try to access a user's own scheduled content tab when that user only has // 'view scheduled {type}' and not 'schedule publishing of {type}'. This is // not allowed and the tab will not be availbale as that view will always be // empty because the user will never have any scheduled content. // allowed and should give "200 OK" and show the users scheduled items. $this->drupalLogin($this->schedulerViewer); $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end"); $assert->statusCodeEquals(403); $assert->statusCodeEquals(200); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing"); // Access another user's scheduled content tab. This should not be possible // and will give "403 Access Denied". Loading @@ -132,10 +135,15 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase { $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for unpublishing"); // Try to access the scheduled tab for a user who cannot schedule content. // No tab will be shown and access is denied as it will always be empty. // Try to access the scheduled tab for a user who cannot schedule content // themselves but can view their scheduled content if scheduled by someone // else. This should give "200 OK" and the scheduled items will be shown. $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end"); $assert->statusCodeEquals(403); $assert->statusCodeEquals(200); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing"); $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing"); $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing"); } /** Loading