Problem/Motivation
Varbase 11 used to obtain six front-end libraries by running recipes/varbase_starter/scripts/drupal-libraries-sync.js, a Node script that copied files out of node_modules/ into web/libraries/, driven by a drupal-libraries block, six npm dependencies and a postinstall hook in package.json. That is replaced by Composer packages on Packagist, each required by the module or the varbase_* recipe that actually loads it.
vardot/aos2.3.4 (new)vardot/jquery.fancytree2.38.5 (new)vardot/ckeditor5-media-embed-drupal47.6.2 (new)vardot/ace1.44.0 (refreshed from a 2017 fork)vardot/dropzone5.9.3 (refreshed from a 2017 fork)swagger-api/swagger-ui, already required bydrupal/openapi_ui_swagger; it only needed an installer path.
All are type: drupal-library except swagger-api/swagger-ui, which is type: library.
Defect: licensing
The npm constraint "@ckeditor/ckeditor5-media-embed": "^47.6.0" was resolving to 47.7.2, which is the CKEditor 5 Long Term Support edition, commercial licence only with no GPL option, inside a GPL-2.0-or-later distribution. 47.6.2 is the last GPL dual-licensed release of that line, and it is exactly what Drupal 11.4 core bundles. A CKEditor 5 plugin must match core's CKEditor 5 version or the editor fails with ckeditor-duplicated-modules.
Defect: broken library
dropzonejs.libraries.yml loads /libraries/dropzone/dropzone-min.js, but no Dropzone 5 release ever shipped that filename: v5 ships dist/min/dropzone.min.js, and the flat name is Dropzone 6, in beta since 2021. So syncing dropzone@5 from npm could never satisfy it and the file was simply absent. vardot/dropzone 5.9.3 ships the stable minified build under the names the module declares; the status report now reads dropzonejs_library: OK.
Defect: duplicate download
swagger-api/swagger-ui was already required by drupal/openapi_ui_swagger and landed in vendor/ where nothing can serve it, while swagger-ui-dist was fetched a second time from npm. It is type: library, not drupal-library, and oomphinc/composer-installers-extender cannot place it, because adding library to installer-types makes composer/installers claim every library-type package and die with Package type "library" is not supported. mnsami/composer-custom-directory-installer, which the openapi_ui_swagger README documents, works.
Steps to reproduce
- Create a project from the
11.0.xVarbase Project template. - Inspect
web/libraries/and the Status report. - The libraries only appear if the
postinstallyarn hook ran and copied them out ofnode_modules/;/libraries/dropzone/dropzone-min.jsnever appears at all, andswagger-uiis downloaded twice while the Composer copy sits unusable invendor/.
Environment: Drupal core 11.4.5, Varbase 11.0.x, PHP 8.4, MariaDB, DDEV.
Proposed resolution
package.json: remove thedependenciesanddrupal-librariesblocks and thedrupal-libraries-syncandpostinstallscripts.composer.json: remove the wholedrupal-libraries-syncscript chain and thepost-create-project-cmdhook that called it.composer.json: requiremnsami/composer-custom-directory-installerand add the two installer paths a genericweb/libraries/{$name}rule cannot place, namelyweb/libraries/swagger-uiforswagger-api/swagger-ui, and the nestedweb/libraries/ckeditor5/plugins/media-embedthatdrupal/ckeditor_media_embedloads from.- Correct the four CI comments that described the postinstall sync.
Verified on a freshly installed Varbase 11.4.5 site in DDEV, with every package resolved from Packagist and no VCS repositories:
- 14/14 declared library files present on disk; 10/10 assets return HTTP 200.
- 7/7 Drupal libraries discovered, every asset resolving, all 7 rendering the Composer paths.
- Status report green:
ace_editorOK,dropzonejs_libraryOK,taxonomy_managerOK, media-embed installed at 47.6.2 matching core 47.6.2. ace_editorPHPUnit: 69 tests, 709 assertions, 0 failures.phpcsclean on every changed PHP file.yarn installsucceeds with none of the six npm library packages present.
Remaining tasks
- ✅ Release varbase_project-11.0.7
- ✅ File an issue
- ✅ Addition/Change/Update/Fix
- ✅ Testing to ensure no regression
- ➖ Automated unit/functional testing coverage
- ✅ Developer Documentation support
- ➖ User Guide Documentation support
- ➖ UX/UI designer responsibilities
- ➖ Accessibility and Readability
- ❌ Reviewed by a human
- ❌ Code review by maintainers
- ❌ Full testing and approval
- ❌ Credit contributors
- ❌ Review with the product owner
- ❌ Update Release Notes
- ❌ Release
User interface changes
- N/A
API changes
- N/A
Data model changes
- N/A
Release notes snippet
- The front-end libraries now install with Composer from Packagist. The
drupal-libraries-syncNode script, itspackage.jsondependencies and thepostinstallhook are removed.
Issue fork varbase_project-3620350
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
rajab natshahComment #5
rajab natshahComment #7
rajab natshah