filefield_paths 7.x-1.2
List of changes since 7.x-1.1
See also File (Field) Paths - Not critical - Access bypass - SA-CONTRIB-2022-065
List of changes since 7.x-1.1
See also File (Field) Paths - Not critical - Access bypass - SA-CONTRIB-2022-065
List of included changes since 8.x-1.0-beta5
Partially addresses File (Field) Paths - Not critical - Access bypass - SA-CONTRIB-2022-065
Security release.
Sites that allow non-administrative users to manage registrations because the users can update the registration host entity and have "update own registration" permission for a given registration type, may need to give those users the "administer own registration" permission for them to retain the ability to manage registrations after installing this upgrade.
Resolves Entity Registration - Moderately critical - Access bypass - SA-CONTRIB-2022-063
This release covers:
Social Base - Moderately critical - Access bypass - SA-CONTRIB-2022-060
This release covers:
Social Base - Moderately critical - Access bypass - SA-CONTRIB-2022-060
This is a security release for the 7.x-1.x branch of the module. Information about the update can be found in the security announcement.
Changes since 7.x-1.7:
Revert "Issue #2357533 by alberto56: Improve registration_administer_registrations_access() function so one can check access for other accounts (not the current one)"