Module currently uses "view revision" permission for all operations (view, revert and delete revision) which is a security issue. We need to fix that and add proper permissions.

  • Add revert, delete all media revisions permission
  • Add revert, delete {media_type} revisions permissions
  • Add checks for permissions to src/Access/MediaRevisionAccessCheck.php
  • Write tests

Comments

benjamincizej created an issue. See original summary.

nejcramsak’s picture

StatusFileSize
new15.83 KB

Added permissions and permission check and wrote tests.

nejcramsak’s picture

Status: Active » Needs review
nejcramsak’s picture

StatusFileSize
new3.87 KB
new17.58 KB

Fixed access check permissions.

bcizej’s picture

StatusFileSize
new24.1 KB
new19.4 KB

Thanks @nejcramsak but the access permissions do not check if the view/update/delete media item permission is set along with the view/update/delete revision permissions. I've added a patch for this and I refactored the tests.

kbrodej’s picture

StatusFileSize
new19.41 KB
new663 bytes

Hi. Reviewed the patch from #5. Tested the permission combinations and run the tests. Works as expected.

However I did find an minor CS issue with t() function. Patch attached.

bcizej’s picture

Status: Needs review » Fixed

Reviewed and commited, thanks everyone.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.