Deprecation: #110863 - Backend route access "public"
See forge#110863
Description
The value
public
of the backend route option
access
has been
deprecated. It only omitted the request token of a route, while the backend
user was still required for all routes not listed in the core. Therefore, the
name did not describe the behaviour.
The new values
anonymous
(no backend user, no request token) and
authenticated- (backend user, but no request token) replace
it, see Feature: #110863 - Improved configuration of public backend routes.
Impact
Routes declaring
'access' => 'public'
are still registered with the
unchanged behaviour of
authenticated-, and a PHP
deprecation is triggered when the route is registered.
Affected installations
Installations with extensions that register backend routes in
Configuration/Backend/Routes.php or
Configuration/Backend/AjaxRoutes.php with
'access' => 'public'
.
Migration
Replace
'access' => 'public'
with
'access' => 'authenticated- to keep the current behaviour,
which requires a backend user, but no request token.
Use
'access' => 'anonymous'
only if the route must be reachable without
a backend user, for example the callback of a single sign-on provider.