Just stumbled on this code: in node.module in node_node_access, the switch case for 'create' just falls through to the 'update' condition. This seems wrong in some way. I can think of scenarios where you are allowed to create content but not edit what you just have created. Or you are only allowed to edit content, not create it. The code as it is written now implies anyone with 'edit any' permissions is able to create content, since the 'create' permission is overruled.
switch ($op) {
case 'create':
$access = AccessResult::allowedIfHasPermission($account, 'create ' . $type . ' content');
case 'update':
$access = AccessResult::allowedIfHasPermission($account, 'edit any ' . $type . ' content');
if (!$access->isAllowed() && $account->hasPermission('edit own ' . $type . ' content')) {
$access = $access->orIf(AccessResult::allowedIf($account->id() == $node->getOwnerId())->cachePerUser()->addCacheableDependency($node));
}
break;
Comments
Comment #2
kriboogh commentedComment #3
init90Hi, @kriboogh
It really looks like a mistake and certainly 'create' case hunk should have 'break' statement but in the current case, all not so obvious because we have #2348203: hook_node_access() no longer fires for the 'create' operation according to it the 'create' operation never fires in
hook_node_access.Hence the problem described here not fully actual, but certainly, the behavior should be clear and how I see #2348203: hook_node_access() no longer fires for the 'create' operation will bring needed clarification.
So I think the issue can be closed in favor of #2348203: hook_node_access() no longer fires for the 'create' operation.
Comment #5
init90#2348203: hook_node_access() no longer fires for the 'create' operation was committed so the issue not actual anymore and can be closed.