Fix: validate item type and rights in lifecycle actions - #213
Conversation
| $olditem = new $type(); | ||
| $olditem->getFromDB($olditem_id); | ||
| if (!$olditem->getFromDB($olditem_id) || !$olditem->can($olditem_id, UPDATE)) { | ||
| continue; |
There was a problem hiding this comment.
New rights checks continue silently when an item fails, leaving the caller with no visibility into partial failures. $count is already incremented before the check (line 110), so the progress output counts skipped items as processed, and front/action.php unconditionally outputs "Replacement successful" after the call returns. A user replacing 10 items where 3 are denied gets the same feedback as a fully successful run.
The mass-action handler in inc/uninstall.class.php correctly uses MassiveAction::ACTION_NORIGHT; the replace() method should at minimum track and display skipped items in its HTML table, or return a count of failures to the caller.
| $model->getConfig($_REQUEST["model_id"]); | ||
|
|
||
| //Case of a uninstallation initiated from the object form | ||
| if (isset($_REQUEST["uninstall"])) { |
There was a problem hiding this comment.
Miisng check for action "uninstall" (like L60)
| ); | ||
| Html::footer(); | ||
| } | ||
| } elseif ($model->fields['types_id'] == PluginUninstallModel::TYPE_MODEL_UNINSTALL) { |
There was a problem hiding this comment.
Miisng check for action "uninstall" (like L60)
Checklist before requesting a review
Please delete options that are not relevant.
(no automated test suite exists in this plugin)
Description
Screenshots (if appropriate):