UPSTREAM FIX

magento2-38279: The Reload Data button shows for admin users without the statistics permission

Community fix magento2-38279 merged into magento/magento2 on 2024-10-18, released in 2.4.8; applies cleanly to 23 releases from 2.4.6 to 2.4.7-p8.

The Reload Data button shows for admin users without the statistics permission edited

Pull request title
add permission check for "reload data" data button
Pull request
magento/magento2#38279
Issues
#38283 pr-derived
Author
@brosenberger
Merged
2024-10-18
Fixed in
2.4.8
Reported on
—
Categories
Admin, Reports
Components
magento/module-backend

Labels

Area
Admin UI
Component
Reports
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Steps to reproduce

1. create a new user role, without the permission Magento_Reports::statistics
2. create a new user with that role

Expected:
3. no "Reload Data" button is shown, as there is no permission for that

Actual:
3. the "Reload Data" button is shown and clickable
4. on click of the "Reload Data" button a "not permitted"-page is shown to the user

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 conflict 2.4.6-p15 conflict
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 conflict 2.4.7-p10 conflict
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflictcontains the fix 2.4.8-p1 conflictcontains the fix 2.4.8-p2 conflictcontains the fix 2.4.8-p3 conflictcontains the fix 2.4.8-p4 conflictcontains the fix 2.4.8-p5 conflictcontains the fix
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 94.9%. Probability it is security relevant: 89.3%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 94.6%, feature 2.0%, refactor 1.8%, tests_only 0.6%, docs_only 0.5%, dependency 0.5%87.4%
Areaadminadmin 93.3%, frontend 1.8%, other 1.6%85.2%
Reported versionunspecifiedunspecified 18.6%, 2.4.6 3.5%, 2.4.6-p1 2.2%3.3%
Scope0.54 of 20 52.5%, 1 40.6%, 2 6.9%16.7%
Risk0.29 of 20 73.1%, 1 24.5%, 2 2.5%39.1%
Worth backporting1.47 of 22 59.2%, 1 28.6%, 0 12.3%17.0%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38279/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-backend
Bundle README (what the ZIP ships)
# magento2-38279

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/38279
Issue: https://github.com/magento/magento2/issues/38283
Author: @brosenberger
Source commit: d3dc8c7b223a27ea82b0c1d8c34d719f23b11b96
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.