If the tag administerusersbyrole_edit_access tag is applied to a query which already uses the table alias "users_roles", the users_roles table is given a different unique alias, and the IS NULL condition is applied to the original query's users_roles table. This produces undesired results. For example, a view which filters users by role will join to the users_role table in the manner described above, and when administerusersbyrole applies its access tag to the view, the end result is that users without the Administer Users permission don't see any users.

Comments

andrew.lieffring created an issue. See original summary.

andrew.lieffring’s picture

StatusFileSize
new1.28 KB

Ensuring the table aliases are unique by using the module's name is a quick fix.

adamps’s picture

Status: Active » Needs work

Thanks for the bug report and patch.

I have checked the documentation at https://api.drupal.org/api/drupal/includes!database!select.inc/function/.... It says:

  • $alias: The alias for the table. In most cases this should be the first letter of the table, or the first letter of each "word" in the table.
  • Return value: The unique alias that was assigned for this table.

So it looks like the correct fix would be to actually check the return value and use that in the call to isNull. Once that's done, if I understand correctly, we can just use alias ur or stick with user_roles if we prefer (but don't need users_roles_2).

henrijs.seso’s picture

Any workaround?

adamps’s picture

Status: Needs work » Fixed

Modified patch as per #3 now checked in. Please test dev version (allow time for a new one to build).

  • AdamPS committed aa0caae on 7.x-2.x
    Issue #2773021 by andrew.lieffring, AdamPS: Query altering fails when...

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

adamps’s picture

Now merged into D8 also