Problem/Motivation

block_example module doesn't demonstrate basic security best practices on its routes.

We need to change that.

In the routes.yml file, it currently says:

  requirements:
    _access: 'TRUE'

This allows anyone with access to the site to see the page, which opens up other possible security concerns.

Proposed resolution

  • Change the routes.yml file to say something like this:
      requirements:
        _permission: 'access content'
    
  • Update the tool menu test to reflect that this route is not visible to anonymous users, and *is* visible once a user with 'access content' permissions has been logged in.
  • Amend any tests which use these routes to log in a user who can access them.

Comments

Mile23 created an issue. See original summary.

mile23’s picture

Issue summary: View changes
mile23’s picture

Issue tags: +Novice
joshi.rohit100’s picture

Assigned: Unassigned » joshi.rohit100
joshi.rohit100’s picture

Status: Active » Needs review
StatusFileSize
new1.76 KB

Status: Needs review » Needs work

The last submitted patch, 5: 2569713-5.patch, failed testing.

joshi.rohit100’s picture

It seems like also need toolbar access permission, right ?

mile23’s picture

I think the toolbar will not show you things you shouldn't be able to see.

I also think we don't really need the tests; an authenticated user should have the 'access content' permission. So we can leave out the tests.

Also the way the permission works is to use _permission: 'access content' so that needs to change.

joshi.rohit100’s picture

Status: Needs work » Needs review
StatusFileSize
new451 bytes
new1.77 KB

As per #8

mile23’s picture

Status: Needs review » Needs work
mile23’s picture

Status: Needs work » Needs review
marvil07’s picture

Status: Needs review » Fixed

This has been already applied via commit 186d0809, I guess the message was a typo.
Closing.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.