diff --git a/core/modules/file/src/FileAccessControlHandler.php b/core/modules/file/src/FileAccessControlHandler.php index 07f9cecc92ed..3c26b1da7f7c 100644 --- a/core/modules/file/src/FileAccessControlHandler.php +++ b/core/modules/file/src/FileAccessControlHandler.php @@ -64,11 +64,11 @@ class FileAccessControlHandler extends EntityAccessControlHandler { if ($operation == 'delete' || $operation == 'update') { $account = $this->prepareUser($account); $file_uid = $entity->get('uid')->getValue(); - // Only the file owner can delete and update the file entity. + // Only the file owner can update or delete the file entity. if ($account->id() == $file_uid[0]['target_id']) { return AccessResult::allowed(); } - return AccessResult::forbidden(); + return AccessResult::forbidden('Only the file owner can update or delete the file entity.'); } // No opinion. diff --git a/core/modules/rest/tests/src/Functional/EntityResource/File/FileResourceTestBase.php b/core/modules/rest/tests/src/Functional/EntityResource/File/FileResourceTestBase.php index 267f45321ea1..0ccf2ecdae1e 100644 --- a/core/modules/rest/tests/src/Functional/EntityResource/File/FileResourceTestBase.php +++ b/core/modules/rest/tests/src/Functional/EntityResource/File/FileResourceTestBase.php @@ -224,8 +224,8 @@ abstract class FileResourceTestBase extends EntityResourceTestBase { if ($method === 'GET') { return "The 'access content' permission is required."; } - if ($method === 'PATCH') { - return 'You are not authorized to update this file entity.'; + if ($method === 'PATCH' || $method === 'DELETE') { + return 'Only the file owner can update or delete the file entity.'; } return parent::getExpectedUnauthorizedAccessMessage($method); }