Unpublished Node Permissions
This module creates access rights for each type of content to control who can see unpublished pieces of content.
A visitor without an account could see translated pieces of content that are not yet published. They could read the text of these translations. They could not change or delete the content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Unpublished Node Permissions to 8.x-1.7.
For developers: what the fix changed
The fix updates unpublished_node_permissions_node_access_records in unpublished_node_permissions.module to iterate over all translation languages of a node and apply the unpublished node access grants per translation, including the language code in the grant. It also adds an update hook in unpublished_node_permissions.install to rebuild node access grants.
unpublished_node_permissions.install+7 −0 fixunpublished_node_permissions.module+45 −24 fix