Fix <DataTable> calls useCanAccess even when bulk delete is disabled - #11352
Merged
fzaninotto merged 2 commits intoSep 1, 2026
Merged
Conversation
fzaninotto
requested changes
Sep 1, 2026
| const { canAccess: canDelete } = useCanAccess({ | ||
| resource: resourceFromContext, | ||
| action: 'delete', | ||
| enabled: props.bulkActionButtons !== false, |
Member
There was a problem hiding this comment.
this will force enabled=true if bulk action buttons aren't explicitly disabled, which will break apps with no authProvider. Check the useCanAccess implementation: the query is only enabled if the auth provider exists.
Author
There was a problem hiding this comment.
Fixed in f631bf9. The enabled option is now included only when bulk actions are explicitly disabled, so useCanAccess keeps its auth-provider guard otherwise. I also added a regression test for DataTable without an auth provider; the full DataTable suite passes (29/29).
fzaninotto
approved these changes
Sep 1, 2026
Member
|
thanks! |
<DataTable> calls useCanAccess even when bulk delete is disabled
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
DataTable always requests delete permission, even when bulkActionButtons is explicitly false. This causes an unnecessary authProvider.canAccess call and can pass a record from an unrelated context to the permission check.
Solution
Disable the delete permission query when bulk actions are disabled. The default behavior and custom bulk action behavior remain unchanged.
How To Test
Run the DataTable unit test suite. The added test renders DataTable with bulkActionButtons={false} and verifies that the auth provider is not called.
Additional Checks
Fixes #11346