Drupal Version
9.3.9
Domain module version
8.x-1.0-beta6
Expected Behavior
When performing a view operation for a domain entity - the result should depend on user permissions with proper caching.
Actual Behavior
When performing a view operation for a domain entity - returning result is a result from the first view operation.
Steps to reproduce
I've reproduced it using JSON:API module and executing GET requests to jsonapi/domain/domain end-point:
1. Make sure that anonymous users have no "view domain list" permission and authenticated users do.
2. Make sure you have cleared the cache.
3. Go to /jsonapi/domain/domain end-point as an anonymous user. You will get the correct result (no info about domains).
4. Got to /jsonapi/domain/domain end-point as an authenticated user. You still get no info about domains because the result is cached from the first operation.
You can perform 3 and 4 points in reverse order and in this case - an anonymous user will get all info about domain entities without having an appropriate permission set.
Proposed solution
Cache DomainAccessControlHandler and DomainAccessCheck results per permissions.
| Comment | File | Size | Author |
|---|---|---|---|
| #6 | 3279230-caching-of-domains.patch | 2.81 KB | _tarik_ |
Issue fork domain-3279230
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
quadrexdevI've prepared a merge request that fixes this issue. Tried it in my project and seems to work fine.
It would be great if someone else can test it.
Comment #4
quadrexdevComment #5
agentrickardInteresting.
Any idea how we can test this?
Comment #6
_tarik_ commentedI created a patch for the new version of the module (8.x-1.0-beta8)
Comment #7
mably commentedCould we have this rebased on 2.0.x please?
Comment #8
mably commentedComment #9
mably commentedRebase done.
Comment #10
mably commentedAdded a few comments in the MR.
Comment #11
mably commentedComment #13
mably commented