Description
Entity Editor has been broken for a long time.
Also, the entity editor is unsecured.
Propose fixing this bug by retrofitting onto a "ajax-direct" pipeline keyed of the /ajax pipeline mapping
Also assign a security behavior to the ajax valve to give it RBAC security, locking out all AJAX calls not authorized by a list of trusted roles