Closed (fixed)
Project:
ActivityPub
Version:
1.0.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
20 Mar 2026 at 08:46 UTC
Updated:
5 Apr 2026 at 16:25 UTC
Jump to comment: Most recent
As I updated to the latest alpha yesterday, the security scan this morning grabbed the 4 views that come with it to be not access controlled. This should be added as a measure of caution, even if those views only come with blocks and don't have canonical routes.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
swentel commentedMakes sense, especially if people start adding pages themselves, and it's easy to forget setting access control on views. They are rendered by a controller at this point which does the access checking (the previous user overview didn't have a permission set either).
I'll set set some sensible defaults. The admin overviews will be easy as I have a dedicated permission for those. For the user, I'll probably have to write a views access plugin, but that's fine.
Comment #4
swentel commentedComment #5
swentel commentedComment #7
swentel commentedAll views have access control now. activitypub_update_8033() will reinstall those views (the code activitypub_update_8028() has been removed so it isn't installed twice for users still on alpha21)