Support for Drupal 7 is ending on 5 January 2025—it’s time to migrate to Drupal 10! Learn about the many benefits of Drupal 10 and find migration tools in our resource center.
Comment | File | Size | Author |
---|---|---|---|
#4 | 1425330-file.patch | 5.68 KB | swentel |
#3 | 1425330-aggregator.patch | 3.51 KB | swentel |
#3 | 1425330-file.patch | 6.59 KB | swentel |
#3 | 1425330-openid.patch | 10.45 KB | swentel |
#1 | 63469-17.file-field-access-bypass.patch | 6.52 KB | webchick |
Comments
Comment #1
webchickThanks, you beat me to it. ;)
Here are the 7.x patches. They need porting to 8.x.
IMPORTANT: Please do NOT credit me on commit for these! Credit should go to:
c960657 - OpenID
David_Rothstein, Berdir, dww = File field access bypass
Dave Reid - Aggregator XSRF
Comment #2
webchickComment #3
swentel CreditAttribution: swentel commentedHere are the patches for D8 - I had 2 patches which didn't apply cleanly (file and openid), so I hope I merged them ok.
Comment #4
swentel CreditAttribution: swentel commentedHere's another for the file patch - the file_download_access() apparently get the wrong data, however, isn't that wrong then also in D7 ?
Comment #5
scor CreditAttribution: scor commentedThis issue should probably only cover aggregator and openid since they are straight forward fixes.
the file access issue needs more discussion over at #1245220: file_file_download() passed bogus $field to field_access().
Comment #6
David_Rothstein CreditAttribution: David_Rothstein commentedComment #7
xjmSo, we currently just need to review the first and third patches in #3?
Comment #8
BerdirYes, the file stuff is dealt with in the other issue.
Aggregator patch looks good to me.
Comment #9
sunThe aggregator and openid patches look good to me.
Comment #10
webchickThanks a lot!
Committed and pushed to 8.x. I think this is ok, since I committed the 7.x patches already. :)
Comment #11
David_Rothstein CreditAttribution: David_Rothstein commentedWrong patch was committed?
Comment #12
webchickWOAH. How did that happen?!I fail at Git. :)Comment #13
webchickThere, I think I made it more betterer now. :)
Comment #14
David_Rothstein CreditAttribution: David_Rothstein commentedLooks good :)