com_resources: restrict /api/resources/list to the caller's access level - #1910
Open
denphi wants to merge 1 commit into
Open
com_resources: restrict /api/resources/list to the caller's access level#1910denphi wants to merge 1 commit into
denphi wants to merge 1 commit into
Conversation
listTask filtered on standalone, published and the publish window only, so GET /api/resources/list returned registered-, protected- and private-level entries to anonymous callers, including their titles, introtext and fulltxt. Apply the same rule the site views use: public for everyone, plus registered-level once authenticated. Component administrators keep the unrestricted view, so the admin `searchable` path in v1.1 is unaffected. Two related fixes in the same task: - `type` is documented as a type name but was compared straight against the numeric column, so only ids ever matched and an alias silently returned everything. Resolve an alias to its id, and let an unknown alias match nothing. - v1.1 referenced Config:: and User:: without importing them. Inside `namespace Components\Resources\Api\Controllers` those resolve to classes in that namespace, so the first call would throw "class not found". v1.0 already used a leading backslash for Config. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
listTask filtered on standalone, published and the publish window only, so GET /api/resources/list returned registered-, protected- and private-level entries to anonymous callers, including their titles, introtext and fulltxt.
Apply the same rule the site views use: public for everyone, plus registered-level once authenticated. Component administrators keep the unrestricted view, so the admin
searchablepath in v1.1 is unaffected.Two related fixes in the same task:
typeis documented as a type name but was compared straight against the numeric column, so only ids ever matched and an alias silently returned everything. Resolve an alias to its id, and let an unknown alias match nothing.v1.1 referenced Config:: and User:: without importing them. Inside
namespace Components\Resources\Api\Controllersthose resolve to classes in that namespace, so the first call would throw "class not found". v1.0 already used a leading backslash for Config.Before you submit this pull request, please make sure:
Thanks!