Skip to content

[2026.3][Class] Require objects permission for the custom layout editor collection route - #2079

Merged
jcPimcore merged 3 commits into
2026.3from
fix/pv597-grant-data-object-access
Oct 7, 2026
Merged

jcPimcore merged 3 commits into
2026.3from
fix/pv597-grant-data-object-access

Conversation

@jcPimcore

Copy link
Copy Markdown
Contributor

Resolves pimcore/platform-version#597

Problem

Since 2026.3.0, users with the objects permission but without classes get a 403 on GET /class/custom-layout/editor/collection/{objectId} whenever they open a data object, so the editor shows repeated "no permission" dialogs.

Cause

EditorCollectionController was switched to CLASS_DEFINITION together with the custom layout admin routes. It is not an admin route: the data object editor calls it on every object open to determine the available layouts.

Fix

EditorCollectionController requires DATA_OBJECTS again. This is safe because the route is read-only and CustomLayoutService::getCustomLayoutEditorCollection() already:

  • loads the object via getDataObjectElement(), which requires view permission on the object, and
  • filters layouts to the user's allowed layouts for non-admins.

All other custom layout controllers keep requiring CLASS_DEFINITION.

Tests

  • CustomLayoutControllerPermissionTest: EditorCollectionController removed from the CLASS_DEFINITION provider and covered by a separate DATA_OBJECTS assertion; the other controllers are still asserted as CLASS_DEFINITION.
  • Ran in Docker (php8.4): the test failed before the fix (classes vs objects); the full Unit suite passes (1269 tests) after it.
  • Not run locally: php-cs-fixer / PHPStan (left to CI). No functional API test was added, because the existing Postman collections don't cover custom layouts.

Notes

  • BC: none. Only the permission on an @internal controller changes; the response is unchanged.
  • Needs forward-merging to 2026.x.
  • Follow-up outside this PR: the UI reports the error on every render in useCustomLayouts (studio-ui-bundle), which multiplies the dialogs.

🤖 Generated with Claude Code

…or collection route

The data object editor calls this read-only route whenever an object is
opened. Requiring the classes permission made it return 403 for every user
holding objects but not classes. View permission on the object and the
user's allowed layouts are enforced in CustomLayoutService.

Refs pimcore/platform-version#597

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:00
@jcPimcore jcPimcore added this to the 2026.3.2 milestone Oct 7, 2026
@jcPimcore jcPimcore self-assigned this Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The focused fix appears correct, but changing an authorization boundary warrants final maintainer security review.

Review effort: Balanced
Findings: None

What changed in this PR

Verdict: Request review. No blocking code issues found.

Restores data-object editor access to custom layouts for users without class-management permission.

Changes:

  • Requires DATA_OBJECTS for the read-only editor collection route.
  • Adds a focused permission regression test.
  • Retains CLASS_DEFINITION on administrative custom-layout routes.

Assessment:

  • Fixes the root cause at the route authorization boundary; object-view and layout filtering remain enforced by the service.
  • No missed call sites or backward-compatibility breaks found.
  • Test coverage targets the narrowest relevant seam.
  • No documentation or changelog update is included; remaining risk is the security-sensitive permission change requiring maintainer validation.

Findings

None.

File Description
src/​Class/​Controller/​CustomLayout/​EditorCollectionController.php Restores DATA_OBJECTS authorization for editor layout discovery.
tests/​Unit/​Class/​Controller/​CustomLayout/​CustomLayoutControllerPermissionTest.php Separately verifies editor and administrative route permissions.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

…collection

The route only requires the objects permission, so cover that the service
rejects users without view permission on the object and filters layouts for
non-admin users.

Refs pimcore/platform-version#597

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new service test must use the branch’s current POCL license header before approval.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@jcPimcore
jcPimcore merged commit 83c5688 into 2026.3 Oct 7, 2026
20 checks passed
@jcPimcore
jcPimcore deleted the fix/pv597-grant-data-object-access branch October 7, 2026 14:49
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 7, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants