Proposed resolution

  • Emit a permission per generated endpoint, in a generated permissions file, with a description naming the bundle it exposes.
  • Default a new endpoint to closed rather than open: a generated endpoint that nobody granted answers 403, so generating cannot publish content by accident.
  • Entity access checked per entity in the base classes, including for entities reached through a card or a paragraph, and asserted for an unpublished target.
  • Report on the status page which generated endpoints are reachable anonymously — the question a site owner needs answered before switching a generation on.
  • Write endpoints — counters, submissions — additionally covered by the module's flood control.

Remaining tasks

Everything.

Issue fork myrest-3622035

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

sergeydruua created an issue. See original summary.

  • sergeydruua committed 166b7528 on 1.0.x
    Issue #3622035: Generate the permissions and the access checks of...
sergeydruua’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

sergeydruua’s picture

Status: Fixed » Closed (fixed)