Problem/Motivation

Drupal core currently is forced to be in the core directory inside of the webroot. This means that an admin is forced to use Composer Installers if they want to install Drupal core with composer. This also presents a potential security hazard as all of Drupal core's code must be in the web-root.

Proposed resolution

Make Drupal core folder agnostic like Symfony and Laravel Framework. This allows admins to use Drupal core as if it were any other dependency of their project. Thereby giving Drupal admins and immense amount of flexability to mix-and-match Drupal core with other dependencies.

Remaining tasks

We'll need to deal with the front-end assets, since we don't want to serve those directly from vendor. Perhaps the various caching layers can take care of this for us.

API changes

Every part of Drupal that is "aware" of the folder it is in, will need to be re-worked to not be. Since we are already using Composer's Autoloader, some of this has already been done, but there's still a lot of legacy systems that are required to be in the core directory and must be aware of the web-root.

Also, this might require some sort of "Kernal" to load contrib modules, or we could force contrib to use Composer. :)

Comments

davidwbarratt’s picture

Category: Bug report » Task
mile23’s picture

catch’s picture

Version: 9.x-dev » 8.3.x-dev
Issue tags: +Needs issue summary update

Work on this can be done in 8.3.x. We might not get there, but don't know until you try. This issue needs a more concrete issue summary though.

Version: 8.3.x-dev » 8.4.x-dev

Drupal 8.3.0-alpha1 will be released the week of January 30, 2017, which means new developments and disruptive changes should now be targeted against the 8.4.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.4.x-dev » 8.5.x-dev

Drupal 8.4.0-alpha1 will be released the week of July 31, 2017, which means new developments and disruptive changes should now be targeted against the 8.5.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.5.x-dev » 8.6.x-dev

Drupal 8.5.0-alpha1 will be released the week of January 17, 2018, which means new developments and disruptive changes should now be targeted against the 8.6.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

mile23’s picture

fgm’s picture

FWIW, Assetic used to be present in core at some point before 8.0 but got removed before release. It would be interesting to find the issue(s) which led to its insertion, then removal, to inform this issue.

andypost’s picture

mile23’s picture

There was also a ton of work on this issue, but it was CWF: #1762204-191: Introduce Assetic compatibility layer for core's internal handling of assets

So the reason we're talking about assetic is because we don't want to serve files directly from vendor.

I'm not well-versed in it, but it seems like our various caching and asset aggregation systems could take care of that for us. We generally have a policy of caching everything, so we could enforce that for a build-as-needed-and-cache approach.

Version: 8.6.x-dev » 8.7.x-dev

Drupal 8.6.0-alpha1 will be released the week of July 16, 2018, which means new developments and disruptive changes should now be targeted against the 8.7.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

dww’s picture

Issue summary: View changes

Cleaned summary of references to assetic and added Mile23's point that the caching / aggregation layers might solve that already (more or less).

Also, +1 following! ;)

Cheers,
-Derek

Version: 8.7.x-dev » 8.8.x-dev

Drupal 8.7.0-alpha1 will be released the week of March 11, 2019, which means new developments and disruptive changes should now be targeted against the 8.8.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.8.x-dev » 8.9.x-dev

Drupal 8.8.0-alpha1 will be released the week of October 14th, 2019, which means new developments and disruptive changes should now be targeted against the 8.9.x-dev branch. (Any changes to 8.9.x will also be committed to 9.0.x in preparation for Drupal 9’s release, but some changes like significant feature additions will be deferred to 9.1.x.). For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

mile23’s picture

Category: Task » Plan
Issue summary: View changes
Issue tags: -Needs issue summary update +Needs followup

This is really a plan issue.

Adding NF because we have to plan how contrib will work. That issue might already exist; I didn't look too hard.

Removing NISU because the summary is still accurate for the plan. @catch #4 is correct: We need concrete proposals.

Version: 8.9.x-dev » 9.1.x-dev

Drupal 8.9.0-beta1 was released on March 20, 2020. 8.9.x is the final, long-term support (LTS) minor release of Drupal 8, which means new developments and disruptive changes should now be targeted against the 9.1.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 9.1.x-dev » 9.2.x-dev

Drupal 9.1.0-alpha1 will be released the week of October 19, 2020, which means new developments and disruptive changes should now be targeted for the 9.2.x-dev branch. For more information see the Drupal 9 minor version schedule and the Allowed changes during the Drupal 9 release cycle.

joachim’s picture

Version: 9.2.x-dev » 9.3.x-dev

Drupal 9.2.0-alpha1 will be released the week of May 3, 2021, which means new developments and disruptive changes should now be targeted for the 9.3.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.3.x-dev » 9.4.x-dev

Drupal 9.3.0-rc1 was released on November 26, 2021, which means new developments and disruptive changes should now be targeted for the 9.4.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.4.x-dev » 9.5.x-dev

Drupal 9.4.0-alpha1 was released on May 6, 2022, which means new developments and disruptive changes should now be targeted for the 9.5.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.5.x-dev » 10.1.x-dev

Drupal 9.5.0-beta2 and Drupal 10.0.0-beta2 were released on September 29, 2022, which means new developments and disruptive changes should now be targeted for the 10.1.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 10.1.x-dev » 11.x-dev

Drupal core is moving towards using a “main” branch. As an interim step, a new 11.x branch has been opened, as Drupal.org infrastructure cannot currently fully support a branch named main. New developments and disruptive changes should now be targeted for the 11.x branch, which currently accepts only minor-version allowed changes. For more information, see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

joachim’s picture

Version: 11.x-dev » main

Drupal core is now using the main branch as the primary development branch. New developments and disruptive changes should now be targeted to the main branch.

Read more in the announcement.