Gate Teams ACL rules on core capability; fix item-set update warnings and EM usage - #200
Merged
alexdryden merged 13 commits intoSep 11, 2026
Merged
Conversation
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
…m behavior Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
…I; fix site-form required-team and count() crash bugs Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
…bug denying all non-admin resource updates Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
…cal ACL bug denying all non-admin resource updates" This reverts commit 9d62942. Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
…nd EM->API usage Co-authored-by: alexdryden <47127862+alexdryden@users.noreply.github.com>
alexdryden
added this pull request to stack #201
September 10, 2026 23:56
Copilot created this pull request from a session on behalf of
alexdryden
September 10, 2026 23:56
View session
alexdryden
marked this pull request as ready for review
September 11, 2026 17:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Teams' ACL rule registration could grant a role capabilities that Omeka core never grants that role at all. Confirmed empirically: a
researchermade a team manager with full item permissions could create an item set via the API, even though core'sAclFactorygrantsresearcherzero create/update/delete capability anywhere. Teams must act strictly as a gate in front of core — narrowing what core already permits, never granting beyond it. A user needs the ability in Teams and in core.Additionally fixed two smaller confirmed bugs found while investigating: unguarded array keys in item-set update causing PHP warnings, and a direct entity-manager usage that should go through the API.
Changes
ACL: enforce "Teams AND core" gating (
src/Service/AclRuleManager.php)ROLES_WITHOUT_CORE_CREATE_UPDATE_DELETE(currently['researcher']) — the set of core roles that core never grants create/update/delete to, for any resource Teams controls.coreForbidsEntirely(), checked before registering any Teams rule for a role/resource/privilege combination; when true, Teams registers no rule and defers to core's own default deny. Teams-owned entities (TeamResource,TeamAsset) are exempt since core has no rule for them to begin with.Module.phpitemSetUpdate(): guardsadd_team/remove_teamrequest-content keys with?? [], eliminating undefined-array-key/foreach-on-null warnings when an update omits team changes.userUpdate(): the "-1 sentinel" new-team-creation path now uses$api->create('team', ...)instead of instantiating and persisting the entity directly.Tests (
tests/integration/run.php)researcherteam manager with full item permissions cannot create an item set (core denies outright).editorteam manager with full item permissions can create an item set (both Teams and core permit it).