Problem/Motivation
Anonymous users can view the main project browser route. As this may potentially expose version information or allow triggering of installs, it should be permissions in the same way as the main "extend" page is.
Steps to reproduce
Spin up with the module. Ensure you are signed out. Visit /admin/modules/browse
Proposed resolution
Add permissions in project_browser.routing.yml
Remaining tasks
- ✅ File an issue about this project
- ✅ Addition/Change/Update/Fix to this project
- ✅ Testing to ensure no regression
- ✅ Automated unit/functional testing coverage
- ☐ Developer Documentation support on feature change/addition
- ☐ User Guide Documentation support on feature change/addition
- ☐ Code review from 1 Drupal core team member
- ☐ Full testing and approval
- ☐ Credit contributors
- ☐ Review with the product owner
- ☐ Release
User interface changes
none (unless we decide to add permissions)
API changes
none
Data model changes
none
Release notes snippet
Adds permissions to the routes associated with Project Browser.
Comments
Comment #2
gaurav.kapoor commentedComment #3
gaurav.kapoor commentedComment #6
gábor hojtsyThe test also needs to set up the user with proper permissions.
Comment #7
hmendes commentedI tested the MR and it worked for me.
Steps:
Changing this to RTBC.
Comment #9
chrisfromredfinThanks everyone!