Problem/Motivation
OgMenuInstance declares admin_permission: 'administer OgMenuInstance entities', but that permission is not defined in og_menu.permissions.yml and cannot be granted to a role.
It has no effect today because OgMenuInstanceAccessControlHandler fully handles access without deferring to the parent implementation. However, the entity definition is misleading and could become significant if the handler later relies on the base access checks.
Proposed resolution
Remove admin_permission from the entity definition. Access is already handled entirely by the custom access control handler, including the site-wide administer og menu bypass.
Remaining tasks
- Remove
admin_permissionfrom the attribute and legacy annotation. - Verify
OgMenuInstanceAccessTeststill passes.
Issue fork og_menu-3624498
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
joelpittetMerged into 2.x.
One note for the record: the summary says the undefined permission had no effect, which is almost true. The only code path that read it was JSON:API's
hook_jsonapi_entity_filter_access(), which calledallowedIfHasPermission()for a permission no user could hold. Filtering "among all" was therefore never granted, so removing the permission produces the same result.The other potential consumers were already unreachable:
OgMenuInstanceAccessControlHandleroverridescheckAccess()andcheckCreateAccess()without calling the parent, and the entity has no collection link forDefaultHtmlRouteProviderto expose.I deliberately did not replace it with
administer og menu, asOgMenudoes. That would grant JSON:API filter access to site administrators, which is a real behaviour change and should have its own issue and test if desired.