Access Control: an empty $allowed_actions does not disable "index"

Open Beginner friendly
#907 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
90/100
Issue type
Documentation
Clarity
Clearly specified
Activity status
Active
Tech stack
php
Domain
documentation

Research direction

Start with en/02_Developer_Guides/02_Controllers/03_Access_Control.md at line 73, then compare the wording with RequestHandler::checkAccessAction() and the ControllerTest assertion mentioned in the issue. Done means the documentation accurately explains index access with an empty allowed_actions array and the explicit restrictions that prevent it.

Written by the indexing model from the issue text.

Description

The Controllers "Access Control" page says (branches 5 and 6, en/02_Developer_Guides/02_Controllers/03_Access_Control.md, line 73):

An action named "index" is allowed by default, unless allowed_actions is defined as an empty array, or the action is specifically restricted.

Unless I'm misreading it, the framework does not behave that way. RequestHandler::checkAccessAction() allows index whenever it is not explicitly listed (if (!$isDefined && ($action == 'index' || empty($action))), framework 5 line 498, framework 6 line 505), and ControllerTest asserts exactly this: "Access granted on index with empty $allowed_actions on defining controller".

So with private static $allowed_actions = []; the index action is still reachable. Perhaps the sentence could say that index stays allowed unless it is restricted explicitly (for example 'index' => 'ADMIN' or 'index' => false)? Happy to open a PR if that wording is right.

Dominant language
No language data
Stars
7
Forks
74
Avg merge
1d 14m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from silverstripe/developer-docs

All issues in silverstripe/developer-docs

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.