Active
Project:
Drupal core
Version:
main
Component:
media system
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
28 Mar 2022 at 13:55 UTC
Updated:
8 Jun 2022 at 16:08 UTC
Jump to comment: Most recent
The 'view media' permission is necessary to allow users to see the content of media fields. However it also grants access to the canonical media entity route, which on most sites doesn't really make sense for anonymous and/or authenticated users to be able to see.
It would be useful to split the permission somehow if we can, so that you can grant access to 'embedded' media but not the route itself.
Comments
Comment #2
maacl commentedI am also interested in this, but this has been discussed and closed in #3081741: Allow media to expose a standalone URL on a per-bundle basis as far I can tell.
Comment #3
catchThat's talking about moving the configuration around, not a permission.
Comment #4
maacl commentedThanks for clarification! So when "Standalone media URL" is checked, we could generate the permissions "View @bundle Entities on own Page" in "MediaPermissions.php" and extend "MediaAccessControlHandler.php" to check those permissions, if a canonical route of a Media entity is visited? Or is there a better approach to this?
This lets me think I do not see the full picture yet.
Comment #5
catch@maacl I was thinking of deprecating the configuration and controlling access to the route purely by permissions.