Problem/Motivation
There have been numerous issues reported in relation to the event subscriber system.
While event subscribers are a great and standard industry pattern, event subscribers are not a good thing to base your security model upon.
This meta will track child issues related to security in the event subscriber realm.
Proposed resolution
- Audit the event subscriber system
- Track child issues here
Remaining tasks
- Add child issues already existing
- Audit more of the event subscriber system
User interface changes
- to be seen
API changes
- to be seen
Comments
Comment #1
fabianx commentedComment #2
dawehnerJust curios, can this be closed now?
Comment #3
mgiffordI don't think it has been formally done, so we certainly can't mark it fixed. Maybe it's a won't fix, but I don't think so.
Comment #17
smustgrave commentedThank you for creating this issue to improve Drupal.
We are working to decide if this task is still relevant to a currently supported version of Drupal. There hasn't been any discussion here for over 8 years which suggests that this has either been implemented or is no longer relevant. Your thoughts on this will allow a decision to be made.
Since we need more information to move forward with this issue, the status is now Postponed (maintainer needs more info). If we don't receive additional information to help with the issue, it may be closed after three months.
Thanks!
Comment #18
smustgrave commentedWanted to bump this 1 more time before closing.
Comment #19
longwaveThe two child issue have long been closed and I am not aware of any other security issues in the event system. Given we have been running with this for over ten years and there have been no new child issues I don't think this meta is really useful any more.