I have a webform where anonymous users can register for a class, receive an email with a link to edit their submission (including the tokenized url), and thus edit their submission. This all works great.

When a user submits an edit to the webform, the edit occurs and the database is updated, but the user gets the message "You are not authorized to access this page."

The action argument of the form tag looks like /node/2113/submission/95737/edit?token=ecf5de5f0cf49f3127accb4292720ab5

but the user is redirected to http://pishposh.com/node/2113/submission/95737 which is missing the token in the url arguments, and thus is denied access.

The user is thus confused about whether or not the edit actually occurred.

Comments

exiteden created an issue. See original summary.

exiteden’s picture

Issue summary: View changes
danchadwick’s picture

Category: Bug report » Feature request
Status: Active » Fixed
StatusFileSize
new1.55 KB

This is really a feature request because token access was added as a tool for users to create their own link. It was never intended to provide comprehensive access.

Nonetheless, this patch provides session access for anonymous users who gained access to a submission by a token. This mean that the session will have the same access as if the submission were just created.

Committed to 7.x-4.x.

danchadwick’s picture

Version: 7.x-4.10 » 8.x-4.x-dev
Category: Feature request » Task
Status: Fixed » Patch (to be ported)

Needs D8 port.

  • DanChadwick committed a9bb592 on 7.x-4.x
    Issue #2555119 by DanChadwick: Provide session when any submission link...
safetypin’s picture

Status: Patch (to be ported) » Needs review
StatusFileSize
new1.21 KB

I manually applied the changes in patch #3 to the 8.x-4.x branch. I am currently unable to test, due to other errors preventing the module from functioning properly.

  • fenstrat committed 666a5aa on 8.x-4.x
    Issue #2555119 by DanChadwick: Provide session when any submission link...
fenstrat’s picture

Version: 8.x-4.x-dev » 7.x-4.x-dev
Category: Task » Feature request
Status: Needs review » Fixed

Committed and pushed to 8.x-4.x.

Thanks for #6 @safetypin, it was just off on the user object for the first check. Slowly working through the queue to try and get 8.x-4.x into some sort of installable state again.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.