Currently when an anonymous user clicks on the modal link nothing happens and "access denied" is reported in the log.

This is due to the _csfr_token check failing for users without an active session. The solution for now is to remove that access check as the route also uses _custom_access.

See: #2730351: CSRF check always fails for users without a session

Comments

imclean created an issue. See original summary.

imclean’s picture

Status: Active » Needs review
StatusFileSize
new485 bytes
imclean’s picture

  • archnode committed b45669f on 8.x-1.x
    Issue #3082971: Add csrf token requirement to route.
    
archnode’s picture

Status: Needs review » Fixed

Sorry that this took so long!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.