Background information
This is a followup to SA-CORE-2025-001.
- security.drupal.org private issue: https://security.drupal.org/node/181932
(included for reference. Please do not report access denied as an error.)
Problem/Motivation
We should add tests to prevent regressions for this vulnerability.
Steps to reproduce
Proposed resolution
Remaining tasks
User interface changes
Introduced terminology
API changes
Data model changes
Release notes snippet
Issue fork drupal-3593777
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
- 3593777-add-tests-for
changes, plain diff MR !15993
Comments
Comment #3
prudloff commentedThe test comes from the private issue so people who worked on it should be credited.
Comment #4
smustgrave commentedReverted https://git.drupalcode.org/project/drupal/-/commit/2da6570278ca3f584e089...
Ran the test and got which shows the issue.
Comment #9
catchCommitted/pushed to main, 11.x and 11.4.x, thanks! Moved credits over from the private security issue, hopefully correctly.