diff --git a/core/lib/Drupal/Core/Theme/AjaxBasePageNegotiator.php b/core/lib/Drupal/Core/Theme/AjaxBasePageNegotiator.php index 1cd883b..5cd2ee3 100644 --- a/core/lib/Drupal/Core/Theme/AjaxBasePageNegotiator.php +++ b/core/lib/Drupal/Core/Theme/AjaxBasePageNegotiator.php @@ -73,18 +73,17 @@ public function applies(RouteMatchInterface $route_match) { * {@inheritdoc} */ public function determineActiveTheme(RouteMatchInterface $route_match) { - if ($ajax_page_state = $this->requestStack->getCurrentRequest()->request->get('ajax_page_state')) { - $theme = $ajax_page_state['theme']; - $token = $ajax_page_state['theme_token']; + $ajax_page_state = $this->requestStack->getCurrentRequest()->request->get('ajax_page_state'); + $theme = $ajax_page_state['theme']; + $token = $ajax_page_state['theme_token']; - // Prevent a request forgery from giving a person access to a theme they - // shouldn't be otherwise allowed to see. However, since everyone is - // allowed to see the default theme, token validation isn't required for - // that, and bypassing it allows most use-cases to work even when accessed - // from the page cache. - if ($theme === $this->configFactory->get('system.theme')->get('default') || $this->csrfGenerator->validate($token, $theme)) { - return $theme; - } + // Prevent a request forgery from giving a person access to a theme they + // shouldn't be otherwise allowed to see. However, since everyone is + // allowed to see the default theme, token validation isn't required for + // that, and bypassing it allows most use-cases to work even when accessed + // from the page cache. + if ($theme === $this->configFactory->get('system.theme')->get('default') || $this->csrfGenerator->validate($token, $theme)) { + return $theme; } } diff --git a/core/tests/Drupal/FunctionalJavascriptTests/Ajax/AjaxThemeTest.php b/core/tests/Drupal/FunctionalJavascriptTests/Ajax/AjaxThemeTest.php index c536fe8..819c430 100644 --- a/core/tests/Drupal/FunctionalJavascriptTests/Ajax/AjaxThemeTest.php +++ b/core/tests/Drupal/FunctionalJavascriptTests/Ajax/AjaxThemeTest.php @@ -32,7 +32,7 @@ public function testAjaxWithAdminRoute() { $assert = $this->assertSession(); $assert->pageTextContains('Current theme: seven'); - // Now + // Now click the modal, which should use also use the admin theme. $this->drupalGet('ajax-test/dialog'); $assert->pageTextNotContains('Current theme: stable'); $this->clickLink('Link 8 (ajax)');