Skip to content

[Bug] Clear cached permission definitions on cache:clear - #2067

Merged
kingjia90 merged 2 commits into
2026.3from
fix/user-permission-cache-clearer
Oct 9, 2026
Merged

kingjia90 merged 2 commits into
2026.3from
fix/user-permission-cache-clearer

Conversation

@kingjia90

Copy link
Copy Markdown
Contributor

Problem

After installing a bundle that adds a permission (e.g. pimcore/data-hub + pimcore/data-hub-simple-rest), Studio endpoints guarded by that permission return 403 Access Denied — even for admins — until pimcore:cache:clear is run.

Root cause

UserPermissionVoter caches all keys of users_permission_definitions under studio_backend_user_permissions in the Pimcore cache (no lifetime, no tags) and only supports() attributes in that list. A permission created after the list was cached (e.g. plugin_datahub_config from the data-hub installer) is supported by no voter, so every #[IsGranted(...)] on it is denied.

Symfony's cache:clear — which pimcore:bundle:install runs after every install — does not touch the Pimcore cache pool, so the stale list survived. Only saving a user (UserUpdateService) or pimcore:cache:clear refreshed it.

Fix

Register a kernel.cache_clearer (UserPermissionCacheClearer) that removes the cached list on cache:clear. The bundle-install flow now picks up new permissions; the per-request path of the voter is unchanged.

Verification

Reproduced on a local demo-enterprise install as admin, GET /pimcore-studio/api/bundle/data-hub/config:

before after
Studio login (cache primed) → Definition::create('plugin_datahub_config')->save() (as the installer does) → cache:clear 403 200

Unit test added; PHPStan and php-cs-fixer clean.

Known limitation

Permissions added at runtime without a subsequent cache:clear (e.g. raw-SQL migrations run without a cache clear) are still not picked up until the next cache clear / user save. Closing that would need a cache tag invalidated in core's Permission\Definition save.

🤖 Generated with Claude Code

UserPermissionVoter caches the list of permission keys in the Pimcore cache
without lifetime or tags. Permissions created later by a bundle installer
(e.g. plugin_datahub_config) were therefore never supported by the voter, so
every IsGranted() on them was denied - even for admins - until
pimcore:cache:clear. Symfony's cache:clear (also run after
pimcore:bundle:install) does not touch the Pimcore cache pool.

Register a kernel.cache_clearer that drops the cached list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 07:42
@kingjia90 kingjia90 added this to the 2026.3.1 milestone Oct 2, 2026
@kingjia90 kingjia90 self-assigned this Oct 2, 2026
@kingjia90 kingjia90 added the Bug label Oct 2, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The implementation is sound, but permission authorization behavior warrants final maintainer security review.

Review effort: Balanced
Findings: None

What changed in this PR

Clears stale permission-definition caches during Symfony cache:clear, allowing newly installed bundle permissions to be recognized (src/Security/CacheClearer/UserPermissionCacheClearer.php:34-36).

Changes:

  • Adds an internal cache clearer and registers it with kernel.cache_clearer (config/security.yaml:16-18).
  • Adds a unit test verifying removal of the permission cache key (tests/Unit/Security/CacheClearer/UserPermissionCacheClearerTest.php:26-33).
  • Correctly addresses bundle-install cache clearing, though runtime permission additions remain outside its scope.

The change is appropriately placed, introduces no public API break, and covers all uses of the shared permission cache key. No blocking defects were identified.

File Description
src/​Security/​CacheClearer/​UserPermissionCacheClearer.php Removes cached permission definitions during cache clearing.
config/​security.yaml Registers the new Symfony cache clearer.
tests/​Unit/​Security/​CacheClearer/​UserPermissionCacheClearerTest.php Tests permission-cache invalidation.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jcPimcore jcPimcore modified the milestones: 2026.3.1, 2026.3.2 Oct 6, 2026
@brusch brusch mentioned this pull request Oct 7, 2026
45 of 78 tasks
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@kingjia90
kingjia90 merged commit fb4390b into 2026.3 Oct 9, 2026
20 checks passed
@kingjia90
kingjia90 deleted the fix/user-permission-cache-clearer branch October 9, 2026 10:10
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants