Needs review
Project:
Subscriptions
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
25 Dec 2013 at 02:05 UTC
Updated:
25 Dec 2013 at 02:43 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
brad.bulger commentedthis moves both the node and content type link code inside the respective permission checks.
Comment #2
salvisHow can we reproduce this issue from the GUI side?
Please follow the instructions that were displayed when you created this issue.
Comment #3
brad.bulger commentedIt's not a GUI issue. If anything, the GUI has the opposite problem, not allowing content-type subscription options to display if the user does not have node subscription permission. But that's apparently a deliberate choice, and a side-issue in any case.
It's about what
module_invoke_all('subscriptions', 'node_options', $account, $node);returns. I would think that it should return correct and valid options.Comment #4
salvisBut in #3 you seem to say that the GUI keeps the bad links from showing up, right?
I would say that makes sense, and you seem to agree.
Without investigating this to the bottom let me tell you about comment.module: it does exactly what you suggest, with the result that a user who is moderator in a certain module (but does not have 'administer comments') is not getting the edit and delete links from comment.module. Creating those links is quite a pain.
The Subscriptions links are much more complex, and it seems wise to return them all, just in case that some other module wants to do something with them.
This is in line with core's use of the '#access' key to suppress form elements that should not be available, rather than removing them. I tend to think of this as a feature rather than a bug...