The clean controller refers to $entity_info['bundle keys'] in two places where ...['entity keys']['bundle'] is correct. This causes failures on create (at least) for entities (like taxonomy terms) which have bundles which are themselves entities (the use case for the 'bundle keys' property).

In addition, I'm not sure that defaulting the bundle to the entity type (as was done in transform_values()) is correct. At any rate, the placement in transform_values also fails for taxonomy terms, because the name of the entity metadata bundle property ('vocabulary') differs from that of the entity key ('vocabulary_machine_name').

I have a test that demonstrates the problem and will include once the new test case at #2059845: Field access bypass, PHP code execution vulnerability lands.

Comments

wodenx’s picture

Status: Active » Needs review
StatusFileSize
new2.07 KB

Patch attached.

wodenx’s picture

Status: Needs review » Closed (duplicate)

Just realized this is a duplicate of #1950686: Clean Processor not listing entities with custom bundles. Closing and will repost revised patch there.