The clean controller refers to $entity_info['bundle keys'] in two places where ...['entity keys']['bundle'] is correct. This causes failures on create (at least) for entities (like taxonomy terms) which have bundles which are themselves entities (the use case for the 'bundle keys' property).
In addition, I'm not sure that defaulting the bundle to the entity type (as was done in transform_values()) is correct. At any rate, the placement in transform_values also fails for taxonomy terms, because the name of the entity metadata bundle property ('vocabulary') differs from that of the entity key ('vocabulary_machine_name').
I have a test that demonstrates the problem and will include once the new test case at #2059845: Field access bypass, PHP code execution vulnerability lands.
| Comment | File | Size | Author |
|---|---|---|---|
| #1 | 2068463-services_entity-bundle-keys.patch | 2.07 KB | wodenx |
Comments
Comment #1
wodenx commentedPatch attached.
Comment #2
wodenx commentedJust realized this is a duplicate of #1950686: Clean Processor not listing entities with custom bundles. Closing and will repost revised patch there.