Problem/Motivation

3.0.x mixes two permission models. The Drupal 7 umbrella permissions access localization community and browse translations gate the community pages and blocks, while the entity permissions view l10n server project and view l10n server release gate the project and release pages. Neither implies the other: the explore projects list opens with the community permission and links to project pages that need the entity permission, so a role with one but not the other sees links to 403 pages. On the administration side one Drupal 7 permission became ten (administer localization server plus one per entity type) that all have to be granted to reach every page. The current site configuration copes by granting everything to everyone, including administer localization server to anonymous users.

Proposed resolution

Every "may see this" check uses an entity view permission; the working permissions (submit, moderate own, decline own, moderate others, import, export, start over packages) stay, since they are actions, and groups keep adding them per language through the existing hook.

  1. Add view l10n server translation and move every browse translations check to it: the translate page, the reset form, the source and translation details, the pick and go form, the group permission. It is also the entity view permission of translations, strings, status flags, translation history and lines (the string usage shown in the details), while files and errors, shown on the release page, get view l10n server release. The release data views get that permission for their block displays. browse translations is removed.
  2. Retire access localization community: the welcome, explore languages, language overview, explore projects, Drupal core status and downloads pages, the profile contributions section and the ten blocks use view l10n server translation or view l10n server project.
  3. administer localization server becomes the admin permission of every l10n_server and l10n_packager entity type, and the update, delete and create checks accept it, so one grant reaches every administration page; the per-type administer permissions stay as narrower options.

Mapping for existing roles, site and group: access localization community becomes view l10n server project, view l10n server release and view l10n server translation; browse translations becomes view l10n server translation. No update path, 3.0.x sites are new installs; the localize.drupal.org configuration is updated alongside.

Tests: the functional tests run with the new permissions; the group decoration test proves a group role granting view l10n server translation opens the translation pages for members only.

LLM disclosure

LLM was used to find, diagnose explain and fix this issue. With human review.

Comments

gábor hojtsy created an issue. See original summary.

  • 59f351ba committed on 3.0.x
    fix #3621348: Use entity view permissions instead of the Drupal 7...

  • 115fedfe committed on 3.0.x
    fix #3621348: Use entity view permissions instead of the Drupal 7...

  • dd76bd09 committed on 3.0.x
    fix #3621348: Use entity view permissions instead of the Drupal 7...
gábor hojtsy’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.