Problem/Motivation

We configured SCN to send an email when a new comment has been posted.
After a migration to Drupal 10.0.10, using PHP 8.1.20, and SCN 2.0.2, we were having the following error :
Drupal\Core\Entity\Query\QueryException : Entity queries must explicitly set whether the query should be access checked or not. See Drupal\Core\Entity\Query\QueryInterface::accessCheck(). dans Drupal\Core\Entity\Query\Sql\Query->prepare() (ligne 141 de /opt/bitnami/drupal/core/lib/Drupal/Core/Entity/Query/Sql/Query.php).

I identified that SCN was using an EntityQuery to get all the user to be able to filter on the configured roles and get the email addresses to send a mail to.

Since Drupal 10 (deprecated in v9.2), it is required to explicitly call the access check function.

Proposed resolution

I added the call to the function accessCheck in scn_entity_insert function of scn.module file.

Regards,
Romain

Issue fork scn-3373682

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

rveillard created an issue. See original summary.

rveillard’s picture

Issue summary: View changes
StatusFileSize
new455 bytes
rveillard’s picture

Status: Active » Needs review
rveillard’s picture

Note: you have the same issue in your other module : https://git.drupalcode.org/project/entity_notify/-/blob/1.0.x/entity_not... :)

keshavv’s picture

Status: Needs review » Reviewed & tested by the community

Mr looks good to me, A single access check is added in the query. We can merge it because this is recommended in Drupal 10.

ivnish’s picture

Thanks

  • ivnish committed feae640e on 2.0.x authored by rveillard
    Issue #3373682 by rveillard, keshav.k, ivnish: Missing access check on...
ivnish’s picture

Status: Reviewed & tested by the community » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.