Problem/Motivation
Profiles are conditionally added to the user view page render array via a view, profiles. In a #pre_render callback, profile_views_add_title_pre_render(), the view title is set to the label of the corresponding profile type.
If the current user doesn't have view access, the profile data is not rendered. However, the title is still rendered.
Expected result: the title is not rendered for profiles that the current user lacks view access to.
Proposed resolution
One approach would be to edit the view to add validation criteria to the "Profile: Profile" contextual filter. If the user lacks access, hide the view.
Alternately, in profile_views_add_title_pre_render(), suppress the title if no rows returned.
Remaining tasks
User interface changes
API changes
Data model changes
Comments
Comment #2
jalpesh commentedAre you talking about removing $view->setTitle($element['#title']); from below function?
function profile_views_add_title_pre_render($element) {
/** @var \Drupal\views\ViewExecutable $view */
if (isset($element['#title'])) {
$view = $element['view_build']['#view'];
$view->setTitle($element['#title']);
}
return $element;
}
Comment #3
nedjoWe shouldn't just remove it, since that call is needed to set the view's title to the label of the profile type. But we could examine the view display and e.g. conditionally suppress the title or block access to the display.
Comment #4
estoyausenteIt seems easy. I fixed as the proposal solution: adding permission check in profile contextual filter and added an extra check when title is being override.
Comment #7
estoyausenteI don't know why the patch doesn't pass the tess. I test it in simplytest.me and the module is installed correctly and the view is changed.
Any know why the patch doesn't pass the test?
This is the test restult:
Comment #8
jalpesh commentedYes, you are right. I am able to apply successfully on my local machine. may be because of patch name, don't know just a guess... :)
Comment #9
nedjoThanks for the draft patch!
Testing, I tried:
Comment #10
nedjoIf we had a profile argument (which we don't), we could validate that a user has access to a profile. But a profile type isn't viewed, so we shouldn't add the view access validation.
Comment #11
nedjoAttached patch adds an access test on the profile being rendered. If the current user doesn't have access to the profile, the result won't be rendered, so skip setting the title.
Comment #12
mglamanThanks! Could we also get a test on this?
Comment #13
mglamanComment #14
mglamanWouldn't the results be empty if the user didn't have view access, anyways?
Comment #15
nedjoHere's the same patch with tests.
AFAIK what happens is the results are loaded but not rendered because an entity access check is done prior to rendering.
Comment #19
mglamanThanks, nedjo! Especially for failing patch w/ test then patch with test+fix :)