Closed (fixed)
Project:
Webform
Version:
7.x-4.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
13 Apr 2015 at 22:24 UTC
Updated:
30 Apr 2015 at 17:34 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
liam morlandComment #2
liam morlandComment #4
liam morlandWrong core version.
I don't think the test failure is related to the patch.
Comment #6
liam morlandNote that only third hunk is specific to this issue. The other hunks just create webform_get_submission_access_token() and put it in use.
Comment #7
danchadwick commentedA few quibbles.
Comment #8
liam morlandThanks. Updated with your changes. I thought drupal_get_query_parameters() was the proper Drupal way of accessing query parameters.
Comment #9
danchadwick commentedDoesn't work because of type hint:
Need to get rid of the
objecttype hint.http://stackoverflow.com/questions/7839059/type-hinting-for-any-object
Also, I'm not sure I understand the need for the sid in the query. The access function already has the submission, so if the token access is being checked, the sid has already been established by the caller (e.g. via the menu path or some other means). Any reason to not remove that test? The token is only good for that one sid anyhow.
Comment #10
liam morlandThanks.
Comment #11
liam morlandWith sid check removed.
Comment #13
danchadwick commentedWhile I'm not completely clear about the use case where the $_SESSION isn't sufficient, I have no problem with this patch.
It makes it possible to share an anonymous submission with someone else.
#11 Committed to 7.x-4.x and 8.x.
Comment #14
liam morlandThanks.