Data field
Anyone without logging in could use a data feed to ask for specific stored information. This would allow them to read unpublished content or other private details. They could not change any of the information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Data field to 2.0.13.
For developers: what the fix changed
The fix modifies `JsonController::json` to query and load entities using the entity storage with access checks (`$storage->getQuery()->accessCheck(TRUE)` and `$entity->access('view')`), rather than querying the database table directly.
Also in this release Added an export file name option for the data field table formatter, implemented plugin caching for performance improvements, and fixed minor typos.
config/schema/datafield.schema.yml+0 −0src/Controller/JsonController.php+60 −49 fixsrc/Plugin/DataFieldFormatterInterface.php+1 −1src/Plugin/DataFieldWidgetInterface.php+1 −1src/Plugin/Field/FieldFormatter/Base.php+8 −2src/Plugin/Field/FieldFormatter/DataFieldTable.php+32 −1src/Plugin/Field/FieldType/DataFieldItem.php+98 −82src/Plugin/Field/FieldWidget/Base.php+28 −16