Xray Audit
It generates detailed technical reports about the content and configuration of a website.
A visitor could view unpublished content through a specific preview page. They could read hidden draft pages but not restricted details like user email addresses. They could not change or add anything on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Xray Audit to 2.0.4, 3.1.1 or 1.6.3, whichever branch you are on.
For developers: what the fix changed
The fix updates xray_audit.routing.yml to require the xray_audit access permission and enforce entity view access for the example route. It also modifies XrayAuditDisplayModeExampleController.php to upcast the entity parameter in the displayEntity method and verify view access before selecting candidate entities.
Also in this release The release includes an array key check in a preprocess hook to prevent errors and adds a test class.
src/Controller/XrayAuditDisplayModeExampleController.php+38 −19 fixxray_audit.module+7 −3xray_audit.routing.yml+6 −5 fix