Description

- This module allows the users having configured role to Login with Email address only.
- Useful for sites where the User roles don't have any administrative permissions so they don't have to remember username and password and simply Login with Email id.
- Administrator role is excluded from the functionality of this module

Sample Use Case

- Suppose you want more users to Login to your website so you don't want your users to remember passwords
as well as you are giving them just ability to download some documents(i.e. Not critical rights)
and also you don't mind user login is being impersonated
So,in such case you can very well use this module.

Warning

  • This Module has Security implications as it allows to login just on Email id.
  • Anyone can Login as another user by just knowing Email id.

Similar Projects and Difference

- Passwordless : Passwordless sends Login link through mail whereas Role based Email Login allows user to login directly without sending email.
- Email Registration : Email Registration allows users to login with email address and password whereas Role based Email Login allows users with configured role to login with email address only.

Sandbox URL

Project page: https://www.drupal.org/sandbox/nlohar/2397155

Git Access

git clone --branch 7.x-1.x http://git.drupal.org/sandbox/nlohar/2397155.git role_based_email_login

Automated Review

http://pareview.sh/pareview/httpgitdrupalorgsandboxnlohar2397155git

Reviews of other projects

- https://www.drupal.org/node/2398741#comment-9468061
- https://www.drupal.org/node/2392273#comment-9472833
- https://www.drupal.org/node/2385131#comment-9476665
- https://www.drupal.org/node/2338365#comment-9476885
- https://www.drupal.org/node/2411257#comment-9538917
- https://www.drupal.org/node/2407057#comment-9541445
- https://www.drupal.org/node/2407203#comment-9538413

Comments

PA robot’s picture

We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)

Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).

I'm a robot and this is an automated message from Project Applications Scraper.

valentine94’s picture

Status: Needs review » Needs work

Would be good to provide a some Simpletests or PHPUnit tests.

klausi’s picture

Status: Needs work » Needs review

Writing tests is not a requirement - anything else you found during your manual review or should this be RTBC instead?

valentine94’s picture

Status: Needs review » Reviewed & tested by the community
nileshlohar’s picture

Hi Valentine94 and klausi,
Thank you for your efforts and time.

nileshlohar’s picture

Issue summary: View changes
Issue tags: +PAreview: review bonus
klausi’s picture

Issue summary: View changes
Issue tags: -PAreview: review bonus

Removing review bonus tag, you have not done all manual reviews, you just posted the output of an automated review tool. Make sure to read through the source code of the other projects, as requested on the review bonus page.

nileshlohar’s picture

Issue summary: View changes
Issue tags: +PAreview: review bonus
pushpinderchauhan’s picture

Assigned: Unassigned » pushpinderchauhan

Assigning to myself for next review.

pushpinderchauhan’s picture

Assigned: pushpinderchauhan » Unassigned
Status: Reviewed & tested by the community » Needs work
StatusFileSize
new14.07 KB
new12.63 KB
new8.04 KB

Automated Review

Best practice issues identified by pareview.sh / drupalcs / coder. None

Review of the 7.x-1.x branch (commit 2636750):

  • No automated test cases were found, did you consider writing Simpletests or PHPUnit tests? This is not a requirement but encouraged for professional software development.

This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.

Manual Review

Individual user account
Yes: Follows the guidelines for individual user accounts.
No duplication
Yes: Does not cause module duplication and/or fragmentation.
Master Branch
Yes: Follows the guidelines for master branch.
Licensing
Yes: Follows the licensing requirements.
3rd party assets/code
Yes: Does not follow the guidelines for 3rd party assets/code.
README.txt/README.md
Yes: Follows the guidelines for in-project documentation and/or the README Template.
Code long/complex enough for review
Yes: Follows the guidelines for project length and complexity.
Secure code
Yes: Follows the security guidelines.
Coding style & Drupal API usage
List of identified issues.
  1. (*) role_based_email_login_settings_form(): doc block is wrong, this is not a hook. Same for role_based_email_login_form. See https://www.drupal.org/coding-standards/docs#forms on how to document for building functions.
  2. (*) "variable_set('role_based_email_login_roles',
    $form_state['values']['role_based_email_login_roles']);": all variables defined by your module need to be removed in hook_uninstall().
  3. (*) role_based_email_login_form_validate(): doc block is wrong, this is not a hook. Same for role_based_email_login_form_submit(). See https://www.drupal.org/coding-standards/docs#forms
  4. (+) role_based_email_login_settings_form_submit(): I don't think that the submit handler is needed if you have system_settings_form().
  5. (+) If there is no role in system then form appearance looks awkward rather display some meaningful message.


    Select Role
  6. (+) If user want to enable this feature for multiple roles (generally required) then this module is useless, rather it manage this for multiple roles.


    Select Role
  7. (+) If user get logged in, Role based Email login Block still appears with same UI that again looks weird. IMHO, It should behave like other login blocks.


    Select Role
  8. A hook_help() would be nice.
  9. Please improve your project page. Also add the differences to existing projects to the project page and follow the tips for a great project page: https://drupal.org/node/997024

The starred items (*) are fairly big issues and warrant going back to Needs Work. Items marked with a plus sign (+) are important and should be addressed before a stable project release. The rest of the comments in the code walkthrough are recommendations.

nileshlohar’s picture

Thanks er.pushpinderrana for you review.

All the Issues are now resolved.

nileshlohar’s picture

Status: Needs work » Needs review
moserk’s picture

Status: Needs review » Needs work

Automated Review

Review of the 7.x-1.x branch (commit 2397ea5):

  • No automated test cases were found, did you consider writing Simpletests or PHPUnit tests? This is not a requirement but encouraged for professional software development.

This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.

Source: http://pareview.sh/ - PAReview.sh online service

Manual Review

Individual user account
Yes: Follows the guidelines for individual user accounts.
No duplication
Yes: Does not cause module duplication and/or fragmentation.
Master Branch
Yes: Follows the guidelines for master branch.
Licensing
Yes: Follows the licensing requirements.
3rd party assets/code
Yes: Follows the guidelines for 3rd party assets/code.
README.txt/README.md
Yes: Follows the guidelines for in-project documentation and/or the README Template.
Code long/complex enough for review
Yes: Follows the guidelines for project length and complexity.
Secure code
Yes: Meets the security requirements.
Coding style & Drupal API usage
List of identified issues:
  1. (*) If a user has a role selected and this role is different to the selected roles in the configuration, the user can still login instead that it is refused.
nileshlohar’s picture

Thanks moserk.
Issue was because variable_set() stores zero valued array if you set and unset the configuration.

Anyways that code is now Fixed.

nileshlohar’s picture

Status: Needs work » Needs review
klausi’s picture

Assigned: Unassigned » klausi
klausi’s picture

Assigned: klausi » Unassigned
Status: Needs review » Needs work
Issue tags: -PAreview: review bonus

manual review:

  1. please add the differences to https://www.drupal.org/project/email_registration top the project page.
  2. What is the use case of this module? Why would you allow users to login without password? That means anyone can access other accounts, they just need to know the email address? This allows attackers to easily impersonate other users, so there are pretty heavy security implications of this. Please explain on the project page. There should be a big warning on the project page that this module has security implications.
  3. role_based_email_login_help(): why the check_markup() here? You are not printing user provided text here but only the trusted README file? Do you just want to insert newlines with nl2br()?
  4. role_based_email_login_settings_form(): @see references in the doc block are wrong?

So the project page is a blocker right now, users should be really aware that this module can be very dangerous. Removing review bonus tag, you can add it again if you have done another 3 reviews of other projects.

nileshlohar’s picture

Status: Needs work » Needs review

Hi Klausi,
Thanks for your review.

I have updated project page (Role based Email Login) and code.

for 1. --> I have added it on project page.

for 2 --> I have added use case and warning on project page.
if users don't have any sensitive rights to require password. as well as don't want extra iteration of email login link
and you are okay with it that users can impersonate then you can use this module.

for 3 & 4 --> I have corrected code.

nileshlohar’s picture

Issue summary: View changes
Issue tags: +PAreview: review bonus
naveenvalecha’s picture

Status: Needs review » Reviewed & tested by the community

All the above metion issues has been addressed. Setting this to RTBC :)

klausi’s picture

Status: Reviewed & tested by the community » Fixed

manual review:

  1. "Code Fixes" is not a useful git commit message, see https://www.drupal.org/node/52287
  2. role_based_email_login_block_view(): no need to call drupal_render() here, just assign the array to $block['content'] and Drupal will render it later automatically for you.
  3. role_based_email_login_get_user_roles(): instead of the foreach() loop you can use ->fetchAllKeyed() on the query result.

Not major blockers, so ...

Thanks for your contribution, nileshlohar!

I updated your account so you can promote this to a full project and also create new projects as either a sandbox or a "full" project.

Here are some recommended readings to help with excellent maintainership:

You can find lots more contributors chatting on IRC in #drupal-contribute. So, come hang out and stay involved!

Thanks, also, for your patience with the review process. Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.

Thanks to the dedicated reviewer(s) as well.

nileshlohar’s picture

Thanks klausi
Thanks naveenvalecha

Thanks everyone for your reviews !!!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.