Skip to content

Extract CRUD permission checks into a reusable service - #7805

Open
ERuban wants to merge 1 commit into
EasyCorp:5.xfrom
ERuban:extract_crud_permission_checker
Open

ERuban wants to merge 1 commit into
EasyCorp:5.xfrom
ERuban:extract_crud_permission_checker

Conversation

@ERuban

@ERuban ERuban commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Since 5.0.10, AssociationConfigurator checks the target controller's Crud::setEntityPermission() and Actions::setPermission() before rendering the link to the related entity. That logic is private, so third-party configurators that render links or embedded blocks pointing to another CRUD controller can't reuse it and end up copying it or duplicating permission names on the field.

This PR extracts it into a public service, CrudPermissionCheckerInterface::isGranted($context, $crudControllerFqcn, $action, ?$entityDto), used by AssociationConfigurator itself and available to any custom configurator. The per-request cache and its kernel.reset tag move along with it. No behaviour change for AssociationField.

Also adds a section to doc/security.rst and a functional test on SecuredApp for the association-link permission check (it had only unit coverage before).

@ERuban
ERuban force-pushed the extract_crud_permission_checker branch from d3bd8c2 to c5243fa Compare September 17, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant