Smart Content
Anyone without logging in could view restricted content blocks by asking the server for them directly. They could see hidden text meant for other users. They could not alter any information on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a site has placed a restricted block inside a display blocks reaction.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Smart Content to 3.2.1.
For developers: what the fix changed
The fix updates the `DisplayBlocks` reaction plugin to correctly call `isAllowed()` on the block access result object in `modules/smart_content_block/src/Plugin/smart_content/Reaction/DisplayBlocks.php`, rather than just checking if the object itself evaluates to true.
Also in this release The release also includes Drupal 11 compatibility updates and PHP 8.2 deprecation fixes.
modules/smart_content_block/smart_content_block.info.yml+1 −1modules/smart_content_block/src/EventSubscriber/LayoutBuilderComponentRenderArray.php+1 −1modules/smart_content_block/src/Plugin/smart_content/Reaction/DisplayBlocks.php+2 −1 fixmodules/smart_content_browser/smart_content_browser.info.yml+1 −1smart_content.info.yml+1 −1src/Condition/ConditionTypeConfigurableBase.php+2 −1src/Condition/ConditionsHelperTrait.php+1 −1src/Condition/Type/ConditionTypeBase.php+14 −0src/Condition/Type/ConditionTypeInterface.php+9 −0src/Decision/DecisionBase.php+1 −1src/Plugin/DataType/DecisionData.php+16 −0src/Plugin/Field/FieldType/DecisionItem.php+2 −1