Change record status: 
Introduced in branch: 
2.1.x, 3.0.x, 3.1.x
Introduced in version: 
3.1.7, 3.0.15, 2.1.24
Description: 

When more than one ECA model reacts to the same access event,
setAccessResult() used to overwrite whatever a previous model had
decided. The verdict of the last model to execute - that is, the one with the
highest weight - won outright.

Both the endpoint access event
(Drupal\eca_endpoint\Event\EndpointAccessEvent) and the Views access
event (Drupal\eca_views\Event\Access) now accumulate results with
AccessResultInterface::orIf() instead.

Before

$this->accessResult = $result;

After

$this->accessResult = $this->accessResult === NULL ? $result : $this->accessResult->orIf($result);

This brings both events in line with the behavior ECA already had elsewhere:
EntityAccess, CreateAccess and
FileDownload have always accumulated. Endpoint and Views were the
outliers.

What you need to check

Only relevant if more than one model reacts to the same access
event.
With a single model, nothing changes.

With several, execution order no longer decides the outcome. A forbidden
result from any reacting model now wins, no matter which model produced it or in
what order. This is the point of the change: the verdict no longer depends on
model weight.

The pattern that breaks is override-by-weight - a low-weight model that
forbids broadly, followed by a higher-weight model that allows for a privileged
group. That used to grant access; it now forbids it. Rewrite such pairs so that
the models decide jointly, for example by having the broad model only forbid
when the exception does not apply, or by collapsing both into a single model
with a condition.

Impacts: 
Site builders, administrators, editors