When editing an unpublished node with an expired token and then clicking on "renew" I get presented with a list of tokens from other nodes.

This is not a security issue, the user is allowed to see those nodes, but an inconvenience, as the list can be very long.

See screenshot.

Comments

killes@www.drop.org created an issue. See original summary.

chr.fritsch’s picture

Status: Active » Needs review
StatusFileSize
new634 bytes

I could reproduce it. The attached patch fixes it

  • chr.fritsch committed 8125ad2 on 8.x-1.x
    Issue #3129220 by chr.fritsch, killes@www.drop.org: Shows list of other...
chr.fritsch’s picture

Status: Needs review » Fixed

Done

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.