The patch in #1389238: Autocomplete widget improvements improved the validation for the autocomplete widget so that invalid input presented an error message rather than just emptying the field. However, it appears this was only done for the "Simple" selection mode handled by EntityReference_SelectionHandler_Generic.class.php.

In EntityReference_SelectionHandler_Views.class.php the validation function simply returns a NULL, so the original problem still exists for the "Views" selection mode.

This allows users to save empty values in a required field, potentially breaking other code that depends on the field being populated. All the user has to do is type in a value that doesn't match any entities and then submit the form.

Comments

__cj’s picture

In both the EntityReference_SelectionHandler_Generic and the EntityReference_SelectionHandler_Views classes the options are created by EntityReferenceHandler::getReferencableEntities(). In EntityReference_SelectionHandler_Generic the validate function uses getReferencableEntities to validate the options.

So the solution can be used in both classes. (They don't extend a common class, possible refactor?).

Patch attached.

__cj’s picture

Status: Active » Needs review

Oops.

Status: Needs review » Needs work

The last submitted patch, autocomplete_validation_views-1819618-1.patch, failed testing.

__cj’s picture

Status: Needs work » Needs review
basvredeling’s picture

Patch tested correctly but there is an problem with cached results. I've made another issue a year ago and now added a patch there including the patch from #1. See: #1658174: Cached views cause validation error
I'd suggest a solution for both in one patch. (ie merging the issues)

enboig’s picture

Issue summary: View changes
StatusFileSize
new1.71 KB

What is the state of this issue? To solve this I checked the patch, but also modified entityreference_plugin_display.inc to handle "=" operator, so when validating input string, it not just works with "CONTAINS" or "START_WITH".

stella’s picture

Following on from the commit in http://cgit.drupalcode.org/entityreference/commit/plugins/selection/Enti... the above patch broke, similar to its sister issue for the EntityReference_SelectionHandler_Generic.class.php at #1389238: Autocomplete widget improvements (see comments 42 and 43).

The attached patch is just a reroll with a fix for this issue.

dooug’s picture

I tested the patch from comment #7. So far so good, the validation avoids the form being submitted without a valid entity selected from the views autocomplete.

While testing, I did notice an AJAX pop error that opens if the form is submitted before the AJAX request is completed, but that seems to be a known drupal core issue: #1232416: Drupal alerts "An AJAX HTTP request terminated abnormally" during normal site operation, confusing site visitors/editors

dooug’s picture

I improved upon the patch by including the field title in the error message for clarity, especially if there were multiple fields in error. Patch & interdiff attached.

I also feel that the different error messages for ">1 but less than 5" and ">5" are a bit superfluous, but I left them anyway.

Also, please ignore the name of my patch file! "file_entity" should read "entityreference", I just got mixed up!

ikeigenwijs’s picture

Form was submited twice ->double post

ikeigenwijs’s picture

Status: Needs review » Needs work

applied the patch in #9

but the validate function in entityReference_SelectionHandler_Views.class.php is never hit:
public function validateAutocompleteInput($input, &$element, &$form_state, $form) {

The following validation function is hit in entityreference.module

function entityreference_field_validate($entity_type, $entity, $field, $instance, $langcode, $items, &$errors) {
edit

Added the sister issue for non view autocompleet entity reference

But same problem

aaronbauman’s picture

There's a bug in entityreference_field_validate():
If no valid ids are provided, the field will pass validation.
Currently, validation only works if at least one valid id is provided.

Try the patch in #2516716-1: Entity selection target bundle settings are not enforced in lieu of the patches in this thread.

pcambra’s picture

Status: Needs work » Needs review

I was having the same issues than reported and the patch fixed them, setting to needs review so we can see

I don't think we should associate this with other issue as suggested in #5

rmedard’s picture

I applied the patch in #9, it works perfect for me.

bigjim’s picture

Status: Needs review » Reviewed & tested by the community

Tested the patch in #9, works as expected.

runephilosof’s picture

Status: Reviewed & tested by the community » Closed (duplicate)
Related issues: +#1702172: Saving allowed even when input is not valid in autocomplete results

Marking as duplicate of #1702172: Saving allowed even when input is not valid in autocomplete results.

The added fix by enboig in #6 should be fixed in another issue (I haven't searched for existing issues for this).

runephilosof’s picture

The error message clarifications from dooug in #9 should either be added to #1702172: Saving allowed even when input is not valid in autocomplete results, or in a separate issue (and then also be added to the validation function in the Generic selection handler.