Commit 2ca97d68 authored by Jonathan Smith's avatar Jonathan Smith
Browse files

Issue #3272548 by jonathan1055: Extended permission for user 'scheduled' tab

parent 6ba02f7e
Loading
Loading
Loading
Loading
+4 −4
Changes for src/Access/SchedulerRouteAccess.php: 4 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -17,10 +17,10 @@ class SchedulerRouteAccess {
   *
   * A user is given access if either of the following conditions are met:
   * - they are viewing their own page and they have the permission to schedule
   * content of the required type.
   * content or view scheduled content of the required type.
   * - they are viewing another user's page and they have permission to view
   * user profiles and view scheduled content, and the user they are viewing has
   * permission to schedule content (otherwise the list would always be empty).
   * permission to schedule content or view scheduled content.
   *
   * @param \Drupal\Core\Session\AccountInterface $account
   *   The currently logged in account.
@@ -38,12 +38,12 @@ class SchedulerRouteAccess {
    $viewing_permission_name = $scheduler_manager->permissionName($entityTypeId, 'view');
    $scheduling_permission_name = $scheduler_manager->permissionName($entityTypeId, 'schedule');

    if ($viewing_own_page && $account->hasPermission($scheduling_permission_name)) {
    if ($viewing_own_page && ($account->hasPermission($viewing_permission_name) || $account->hasPermission($scheduling_permission_name))) {
      return AccessResult::allowed();
    }
    if (!$viewing_own_page && $account->hasPermission($viewing_permission_name) && $account->hasPermission('access user profiles')) {
      $other_user = User::load($user_being_viewed);
      if ($other_user && $other_user->hasPermission($scheduling_permission_name)) {
      if ($other_user && ($other_user->hasPermission($viewing_permission_name) || $other_user->hasPermission($scheduling_permission_name))) {
        return AccessResult::allowed();
      }
    }
+14 −6
Changes for tests/src/Functional/SchedulerViewsAccessTest.php: 14 added lines, 6 removed lines.
Original line number Diff line number Diff line
@@ -110,11 +110,14 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase {

    // Try to access a user's own scheduled content tab when that user only has
    // 'view scheduled {type}' and not 'schedule publishing of {type}'. This is
    // not allowed and the tab will not be availbale as that view will always be
    // empty because the user will never have any scheduled content.
    // allowed and should give "200 OK" and show the users scheduled items.
    $this->drupalLogin($this->schedulerViewer);
    $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end");
    $assert->statusCodeEquals(403);
    $assert->statusCodeEquals(200);
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing");
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing");
    $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing");
    $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing");

    // Access another user's scheduled content tab. This should not be possible
    // and will give "403 Access Denied".
@@ -132,10 +135,15 @@ class SchedulerViewsAccessTest extends SchedulerBrowserTestBase {
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for publishing");
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Viewer for unpublishing");

    // Try to access the scheduled tab for a user who cannot schedule content.
    // No tab will be shown and access is denied as it will always be empty.
    // Try to access the scheduled tab for a user who cannot schedule content
    // themselves but can view their scheduled content if scheduled by someone
    // else. This should give "200 OK" and the scheduled items will be shown.
    $this->drupalGet("user/{$this->schedulerViewer->id()}/$url_end");
    $assert->statusCodeEquals(403);
    $assert->statusCodeEquals(200);
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for publishing");
    $assert->pageTextNotContains("$entityTypeId created by Scheduler Editor for unpublishing");
    $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for publishing");
    $assert->pageTextContains("$entityTypeId created by Scheduler Viewer for unpublishing");
  }

  /**