Details
-
Bug
-
Resolution: Fixed
-
High
-
4.7.0, 5.0 Maintenance, 5.1 Maintenance, 5.2-dev
-
None
Description
With the introduction security fix to not show relations, it is now required to make Media library readable.
However it should instead use view_embed like done in xmltext field type, see:
if ( $object->attribute( 'can_read' ) || $object->attribute( 'can_view_embed' ) ) { $templateName = $element->nodeName . $tplSuffix; } else { $templateName = $element->nodeName . '_denied'; }
Attachments
Issue Links
- is blocked by
-
EZP-21735 Object relation showing "No relation" when there is a relation
- Closed
- relates to
-
EZP-20388 Missing view_embed policy for Anonymous role
- Closed
-
EZP-21387 As a developer I want a relation view so I can embed relations on my 5.x site
- Closed
-
EZP-21368 Enhance "content|view_embed" policy so that it supports limitation by object states
- Confirmed
-
EZP-22474 Preview Authorization uses wrong policy function
- Closed
- testing discovered
-
EZP-22028 Anonymous role in demo site package contains content/view_embed policy that is too wide
- Closed
-
EZP-22068 Add loadRelatedContent() and loadEmbedContent() to the API
- Backlog