When a non-admin user edits a node created by a blocked user, the node is unable to be saved.
Steps to reproduce:
1. A user creates a node.
2. The user is blocked.
3. A second user (Who does not have the permission "Administer users") edits the node and tries to save it.
4. The second user gets a “This entity (user:id) cannot be referenced” error, where the id corresponds to the blocked user that created the node.
The second non-admin user should be able to save the node, even if the node creator is blocked.
A user with the "Administer users" permission can save the node without errors.
Comments
Comment #2
darrenwh commentedI can't replicate this:
I created a new user with authenticated status
Added the permissions create Article: Create new content, Article: Edit any content and Article: Edit own content for the authenticated user.
I created a new article with new user, blocked that user, created a new authenticated user and was able to edit and save the article.
Comment #3
letrotteur commentedI've got the same issue on a 8.3.7 site. Any evolution on this issue?
Comment #4
dalinI've got a site that also experiences this. I think what @darrenwh missed when trying to reproduce was that the bug doesn't appear if you have the "Administer users" permission. It's only lower-level user roles (an "editor" or similar) that will experience this bug.
Here's also an updated screenshot.
This is related to (and maybe fixable) in #2849620: Allow blocked users to be filtered from UserSelection for users with 'administer users' permission.
Comment #5
amateescu commented@dalin, what version of Drupal is used on that site? This problem should have been fixed by #2791269: Allow saving pre-existing references to inaccessible items in Drupal 8.4.
Comment #6
dalin@amateescu Ah thanks for pointing that out. This site is on 8.3.x (with backported security patches), so yes #2791269: Allow saving pre-existing references to inaccessible items probably fixes things.