Webform REST
An ordinary account on the site could view form fields and submissions without the right access rights. They could read personal details submitted by other people. They could not edit or delete those submissions.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Webform REST to 4.2.1.
For developers: what the fix changed
Adds access checks to `WebformCompleteSubmissionResource`, `WebformElementsResource`, and `WebformFieldsResource` to ensure the current user has permission to view the webform and its submissions.
Also in this release Fixed PHPCS warnings, updated GitLab CI configuration, corrected typos in error messages, and made REST GET endpoints cacheable by replacing ModifiedResourceResponse with ResourceResponse.
.gitlab-ci.yml+20 −3src/Event/WebformSubmitReturnEvent.php+13 −2src/Form/WebformRestForm.php+8 −35src/Plugin/rest/resource/WebformCompleteSubmissionResource.php+58 −13 fixsrc/Plugin/rest/resource/WebformElementsResource.php+32 −6 fixsrc/Plugin/rest/resource/WebformFieldsResource.php+24 −8 fixsrc/Plugin/rest/resource/WebformSubmissionResource.php+22 −21src/Plugin/rest/resource/WebformSubmitResource.php+21 −23webform_rest.install+3 −2webform_rest.permissions.yml+1 −1webform_rest.routing.yml+1 −1