Permissions by Term
It restricts view access to single pieces of content using categories.
A visitor could view restricted content through data feeds if it was linked to a deleted category. They could read this hidden information. They could not alter or add any data on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses permission mode, has references to a deleted category, and is accessed via a data feed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Permissions by Term to 3.1.41.
For developers: what the fix changed
The fix updates the node access hook to return an explicit access result object and modifies the access check service to return neutral or forbidden access results instead of void.
Also in this release The release updates the Axios library to a secure version, fixes typos in comments and configures ignore paths for the spell checker.
.gitlab-ci.yml+2 −0js/README.md+5 −5js/package-lock.json+5 −4js/package.json+1 −1js/webpack-dist/bundle.js+0 −0js/webpack-dist/bundle.js.LICENSE.txt+1 −1permissions_by_term.install+2 −2permissions_by_term.module+2 −2 fixsrc/Commands/CreateFixtureNodesForTestingCommands.php+1 −1src/Commands/PermissionsByTermRebuildCommands.php+1 −1src/Listener/KernelEventListener.php+1 −1src/Service/AccessCheck.php+5 −3 fix