Previously it was possible for a controller based on ImageStyleDownloadController to allow delivery for any scheme, either provided by core or contrib, without regard for the routes intended use.
The Drupal\image\Controller\ImageStyleDownloadController::deliver() method now requires a string parameter $required_derivative_scheme which indicates the scheme the controller expects for the the derivative image to be generated in. Modules that are reusing this controller method will need to add the new argument in their routing configuration.
If the $required_derivative_scheme provided is not the same as the scheme calculated by the ImageStyle::buildUri() of the source image, an AccessDeniedHttpException will be thrown to prevent bypassing access control policy for a path.
This is a security improvement that prevents routes intended for use by one scheme being used by another scheme potentially bypassing configured security checks.
Drupal Core Controllers and the associated routes are not considered API. No backwards compatibility has been provided.
Old routing entry before this change:
image.style_private:
path: '/system/files/styles/{image_style}/{scheme}'
defaults:
_controller: '\Drupal\image\Controller\ImageStyleDownloadController::deliver'
requirements:
_access: 'TRUE'
New routing entry:
image.style_private:
path: '/system/files/styles/{image_style}/{scheme}'
defaults:
_controller: '\Drupal\image\Controller\ImageStyleDownloadController::deliver'
required_derivative_scheme: 'private'
requirements:
_access: 'TRUE'