Active
Project:
Drupal core
Version:
main
Component:
views.module
Priority:
Major
Category:
Plan
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
13 Dec 2014 at 16:56 UTC
Updated:
5 Jul 2025 at 05:00 UTC
Jump to comment: Most recent
In #2341357: Views entity area config is not deployable and missing dependencies, we identified the fact that no validation is done on the entity ID configuration field. This problem likely exists in numerous Views plugins. When an invalid value is entered, there is no validation error, and the area is silently empty with no indication of why it's not working.
Only 8 Views plugins implement the validation method, PluginBase::validateOptionsForm(). The related submit handler, submitOptionsForm(), has 13 usages, but since many plugins don't need to explicitly implement the submit method, there are likely many places that the validation method should be added.
| Issue category | Bug because we are not validating input and not failing explicitly for invalid configuration. |
|---|---|
| Issue priority | Major because the bug likely several plugins in Views, negatively impacts the usability of the Views UI, and makes some View configuration errors rather difficult to debug. Not critical because the problem exists in contrib in D7 as well. |
| Prioritized changes | These are prioritized changes because the main goal of this meta issue is bugfixes and usability improvements. |
| Disruption |
|
PluginBase::validateOptionsForm() in plugins that need input validation.
Comments
Comment #1
xjmComment #2
xjmComment #3
xjmComment #4
xjmComment #5
xjmComment #6
xjmComment #7
xjmComment #9
xjm@alexpott, @dawehner, @tim.plunkett, and I discussed this issue at DrupalCon New Orleans. Others that this issue, in itself, does not have a specific scope (or the scope is enormous). However, a lack of input validation is a major bug in general. So, we agreed to convert this issue to a plan, keeping it major for visibility. Individual child issues may be major or normal bugs depending on their severity.
The next step is to go over views plugins in core and determine what input validation they might be lacking, and file issues for it. It could make sense to make a list of all the plugins in core and go through them by plugin type. Once we have that information, we can see if there are any patterns for filing child issues.
Comment #22
lendudeSince most of Views is config, #2869792: [meta] Add constraints to all config entity types should, one day, provide this I hope
Comment #26
xjmAdding triage credit from #9.