{"data":{"id":"MDVA-41628","source":"qpt","sourceRef":"magento/quality-patches@1.1.84","title":"Fixes the issue where existing restricted admin users get access to the new resources when new modules are added.","categories":["Admin"],"components":["magento/module-authorization"],"origin":"adobe-commerce-support","documentation":{"url":"https://experienceleague.adobe.com/en/docs/commerce-operations/tools/quality-patches-tool/patches-available-in-qpt/v1-1-12/mdva-41628-restricted-admin-user-gets-access-to-new-resources","path":"help/tools/quality-patches-tool/patches-available-in-qpt/v1-1-12/mdva-41628-restricted-admin-user-gets-access-to-new-resources.md","blobSha":"7c48590ed62e7ccee4cf54d9c2ddbf337f942345","description":"Restricted admin users can get access to the new resources when new modules are added.","stepsToReproduce":"1. Create a new admin user role with restricted resources. 1. Create a new admin user under the role created in step one. 1. Install and enable the custom module that creates a new set of menu items along with ACL resources. 1. Log in using the newly created admin user.","introducedInQpt":"1.1.12","createdFor":["2.4.2-p1"],"documentedRange":"2.4.0 - 2.4.3-p1","scheduledFixRelease":"2.4.5"},"files":[{"package":"magento/magento2-base","constraint":">=2.4.0 <2.4.5","path":"patches/os/MDVA-41628_2.4.2-p1.patch","blobSha":"9a93da6c3e682af7b56477a0e13b8b5a77f5be6d","url":"https://raw.githubusercontent.com/magento/quality-patches/11d565bdde197b9c7bac859a5698e99098b48457/patches/os/MDVA-41628_2.4.2-p1.patch","thirdParty":false,"modifies":[{"path":"vendor/magento/module-authorization/Model/Acl/Loader/Rule.php","change":"modified","package":"magento/module-authorization"}],"packages":["magento/module-authorization"],"hasTests":false,"applicableVersions":{"magento-community":["2.4.4-p18","2.4.4-p17","2.4.4-p16","2.4.4-p15","2.4.4-p14","2.4.4-p13","2.4.4-p12","2.4.4-p11","2.4.4-p10","2.4.4-p9","2.4.4-p8","2.4.4-p7","2.4.4-p6","2.4.4-p5","2.4.4-p4","2.4.4-p3","2.4.4-p2","2.4.4-p1","2.4.4","2.4.3-p3","2.4.3-p2","2.4.3-p1","2.4.3","2.4.2-p2","2.4.2-p1","2.4.2","2.4.1-p1","2.4.1","2.4.0-p1","2.4.0"],"magento-commerce":["2.4.4-p18","2.4.4-p17","2.4.4-p16","2.4.4-p15","2.4.4-p14","2.4.4-p13","2.4.4-p12","2.4.4-p11","2.4.4-p10","2.4.4-p9","2.4.4-p8","2.4.4-p7","2.4.4-p6","2.4.4-p5","2.4.4-p4","2.4.4-p3","2.4.4-p2","2.4.4-p1","2.4.4","2.4.3-p3","2.4.3-p2","2.4.3-p1","2.4.3","2.4.2-p2","2.4.2-p1","2.4.2","2.4.1-p1","2.4.1","2.4.0-p1","2.4.0"],"mage-os":[]},"unknownVersions":[],"requires":[],"replacedWith":null,"deprecated":false}],"applicableVersions":{"magento-community":["2.4.4-p18","2.4.4-p17","2.4.4-p16","2.4.4-p15","2.4.4-p14","2.4.4-p13","2.4.4-p12","2.4.4-p11","2.4.4-p10","2.4.4-p9","2.4.4-p8","2.4.4-p7","2.4.4-p6","2.4.4-p5","2.4.4-p4","2.4.4-p3","2.4.4-p2","2.4.4-p1","2.4.4","2.4.3-p3","2.4.3-p2","2.4.3-p1","2.4.3","2.4.2-p2","2.4.2-p1","2.4.2","2.4.1-p1","2.4.1","2.4.0-p1","2.4.0"],"magento-commerce":["2.4.4-p18","2.4.4-p17","2.4.4-p16","2.4.4-p15","2.4.4-p14","2.4.4-p13","2.4.4-p12","2.4.4-p11","2.4.4-p10","2.4.4-p9","2.4.4-p8","2.4.4-p7","2.4.4-p6","2.4.4-p5","2.4.4-p4","2.4.4-p3","2.4.4-p2","2.4.4-p1","2.4.4","2.4.3-p3","2.4.3-p2","2.4.3-p1","2.4.3","2.4.2-p2","2.4.2-p1","2.4.2","2.4.1-p1","2.4.1","2.4.0-p1","2.4.0"],"mage-os":[]},"conditions":null,"requirements":null},"_documentation":"https://magento.watch/api","_description":"Quality patch MDVA-41628 details"}