Financial Type ACLs don't work on soft credits
To replicate:
- Create a soft credit on any contribution. Note the financial type.
- Enable Financial ACLs.
- Log in as a user who doesn't have permission to view the financial type noted above.
- If you're using
civicrm-buildkit
, any non-administrative user who can view CiviCRM (e.g. withCiviCRM Webtest User
role) qualifies. - View the contact with the soft credit.
Expected Result
- The soft credit is not visible.
Actual Result
- The soft credit is visible. Clicking
View
to view the original contribution returns a "permission denied", which is correct (but bad UX).