Change record status: 
Project: 
Introduced in branch: 
8.6.x
Introduced in version: 
8.6.8
Description: 

A security update included in 8.6.2 introduced a new method isTransitionValid() to \Drupal\content_moderation\StateTransitionValidationInterface. This new method did not provide enough context for some contributed modules to be able to make a decision on whether the transition was actually valid.

To that end, the content entity that the transition is happening on is now an (optional) argument that is available. This argument will become required in Drupal 9.

/**
   * Checks if a transition between two states if valid for the given user.
   *
   * @param \Drupal\workflows\WorkflowInterface $workflow
   *   The workflow entity.
   * @param \Drupal\workflows\StateInterface $original_state
   *   The original workflow state.
   * @param \Drupal\workflows\StateInterface $new_state
   *   The new workflow state.
   * @param \Drupal\Core\Session\AccountInterface $user
   *   The user to validate.
   * @param \Drupal\Core\Entity\ContentEntityInterface $entity
   *   (optional) The entity to be transitioned. Omitting this parameter is
   *   deprecated and will be required in Drupal 9.0.0.
   *
   * @return bool
   *   Returns TRUE if transition is valid, otherwise FALSE.
   */
  public function isTransitionValid(WorkflowInterface $workflow, StateInterface $original_state, StateInterface $new_state, AccountInterface $user, ContentEntityInterface $entity = NULL);
Impacts: 
Module developers