Skip to content

Enforce the engagement object permission on the questionnaire answer view - #15666

Merged
devGregA merged 2 commits into
devfrom
fix/questionnaire-answer-authz
Oct 8, 2026
Merged

devGregA merged 2 commits into
devfrom
fix/questionnaire-answer-authz

Conversation

@svader0

@svader0 svader0 commented Aug 14, 2026

Copy link
Copy Markdown
Collaborator

Hardening / consistency improvement to the engagement-scoped questionnaire views. Aligns the answer view with its siblings so it always applies the object-level edit permission check, and adds a regression test. No functional change for correctly-permissioned users.

…view

Align answer_questionnaire with the other engagement-scoped questionnaire
views by always applying the object-level edit check. Adds a regression test.

@Maffooch Maffooch left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a feature to allow surveys to be answered without a login if configured to be available

@github-actions

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@svader0 svader0 closed this Aug 20, 2026
@svader0 svader0 reopened this Aug 20, 2026
Base automatically changed from bugfix to dev September 8, 2026 14:36
@Maffooch
Maffooch changed the base branch from dev to bugfix September 8, 2026 16:33
@github-actions

Copy link
Copy Markdown
Contributor

Conflicts have been resolved. A maintainer will review the pull request shortly.

@svader0
svader0 requested a review from Maffooch September 28, 2026 18:31
@svader0

svader0 commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

It is a feature to allow surveys to be answered without a login if configured to be available

@Maffooch It's been a while, so I forget it we ever talked about this PR elsewhere, but this it should only be minor hardening on questionnaires inside of an engagement which the docs say do not allow anonymous answers even with the setting enabled. It's not particularly important so if I am mistaken then I have no problem throwing this away.

@svader0 svader0 added this to the 3.4.100 milestone Sep 28, 2026
@Maffooch Maffooch modified the milestones: 3.4.100, 3.4.0 Sep 29, 2026
@Maffooch

Maffooch commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

It seems like the docs are wrong from my perspective. The feature is intended to allow anonymous submissions

@Maffooch Maffooch modified the milestones: 3.4.0, 3.4.100 Oct 5, 2026
@Maffooch
Maffooch changed the base branch from bugfix to dev October 5, 2026 17:15
@devGregA
devGregA added this pull request to the merge queue Oct 8, 2026
Merged via the queue into dev with commit 8e26cfa Oct 8, 2026
49 checks passed
@devGregA
devGregA deleted the fix/questionnaire-answer-authz branch October 8, 2026 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants