Order uri callback returns the path to the orders admin page even if user doesn't have access to it.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

anrikun’s picture

Status: Active » Needs review
FileSize
663 bytes
rszrama’s picture

mglaman’s picture

Status: Needs review » Reviewed & tested by the community

Applies and makes sense to check if user passes same access checks the menu path has before returning it.

rszrama’s picture

Agreed. Compared against other entities in Commerce core and we're following a similar pattenr. Committing.

  • rszrama committed 3d89816 on 7.x-1.x authored by anrikun
    Issue #2321205 by anrikun, rszrama, mglaman: check the proper access...
rszrama’s picture

Status: Reviewed & tested by the community » Fixed

Committed.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.