Digital Signage Framework
Anyone without logging in could pretend to be a display screen and ask the website for specific blocks of content. This would allow them to read information they were not meant to see. They could not change any of the content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Digital Signage Framework to 2.6.1.
For developers: what the fix changed
The fix replaces the generic 'access content' permission on the block API route with a custom access check in `BlockApi::access()` that verifies the requester is a known device or has preview permission. It also updates `BlockApi::request()` to verify that the requested block is a valid signage block using the new `isSignageBlock()` method, returning a 404 if it is not.
Also in this release The release introduces a `Regions` class to centralise region names and adds comprehensive tests for the block API route.
digital_signage_framework.routing.yml+1 −1 fixsrc/Controller/BlockApi.php+223 −6 fixsrc/EventSubscriber/Blocks.php+3 −2src/Hook/DigitalSignageFrameworkHooks.php+3 −2src/Regions.php+32 −0