Skip to content

Conversation

@wouterj
Copy link
Member

@wouterj wouterj commented Jul 20, 2020

Q A
Branch? master
Bug fix? no
New feature? yes
Deprecations? no
Tickets Fix #37523
License MIT
Doc PR tbd

This allows voters to grant access to unauthenticated users. E.g. some objects can be viewed by anyone, in this case the voter has to be able to grant access to unauthenticated users.

This does break the interface PHPdoc of TokenInterface: getUser() returns null instead of string|UserInterface. This is only true when using the new system, so not a real BC break. I think the only thing we can do to "guide" users is to add some custom handling for type errors related to null and UserInterface methods ("Did you forgot to check for null in the Voter?"). Is this something I should add to this PR?

This allows to e.g. have some objects that can be viewed by anyone (even unauthenticated users).
@wouterj wouterj force-pushed the security/null-token branch from b9f3c41 to e370915 Compare July 20, 2020 19:47
@nicolas-grekas nicolas-grekas added this to the next milestone Jul 22, 2020
@fabpot
Copy link
Member

fabpot commented Jul 31, 2020

Thank you @wouterj.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security][new system] Voter can not vote anymore on "anonymous"

4 participants