[4.4] Align the access checks for the unpublished articles in frontend category #42694
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This aligns the access checks for the
published
state and thepublish_up/down
checks to both use the givenfilter.published
.Pull Request for Issue #42452.
Summary of Changes
The main
CategoryModel
model has the right access checks injoomla-cms/components/com_content/src/Model/CategoryModel.php
Lines 154 to 159 in 302ce23
Here, the access to the single category in question is checked the right way (i.e. by including the category id in the asset name).
But the category model does not filter the articles itself. For this, it calls into
ArticlesModel
:joomla-cms/components/com_content/src/Model/CategoryModel.php
Lines 233 to 238 in 302ce23
and passes on the
filter.published
state.But in
ArticlesModel::getItems()
, the access check is repeated with a generic asset tag (i.e.com_content
w/o any category information), but only for thepublish_up/down
case. In the simplepublished
case, no additional access check is performed, and just the value offilter.published
is used.joomla-cms/components/com_content/src/Model/ArticlesModel.php
Lines 492 to 496 in 302ce23
This patch essentially aligns the access checks for the published state and the publish_up/down checks to both use the given
filter.published
.Testing Instructions
Actual result BEFORE applying this Pull Request
Expected result AFTER applying this Pull Request
Link to documentations
Please select:
Documentation link for docs.joomla.org:
No documentation changes for docs.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed