Problem/Motivation

Found as part of #2507831: Harden redirect responses to make external URIs opt in (was SA-CORE-2015-002 foward-port), but will not be fixed there.

If ?destinations is empty, no Url should be returned, so the calling code can know. In HEAD, it returns a Url representing the front page.

If there are multiple non-route destinations, they will not be appended properly.

Proposed resolution

Fix

Remaining tasks

N/A

User interface changes

N/A

API changes

\Drupal\field_ui\FieldUI::getNextDestination() can now return NULL, not just a Url object.

Data model changes

N/A

Beta phase evaluation

Reference: https://www.drupal.org/core/beta-changes
Issue category Bug because functionality is broken.
Issue priority Normal, because its just a normal bug.
Prioritized changes The main goal of this issue is fixing broken behavior.
Disruption Not disruptive unless any module relied on an empty destination leading to the front page. There are easy ways to fix that and the code is likely broken that relied on that in other regards.
CommentFileSizeAuthor
#1 2508679-field_ui-1.patch3.56 KBtim.plunkett

Comments

tim.plunkett’s picture

Status: Active » Needs review
StatusFileSize
new3.56 KB
dawehner’s picture

Status: Needs review » Reviewed & tested by the community

Looks great for me!

fabianx’s picture

Issue summary: View changes

RTBC +1, added beta eval

  • xjm committed 6b7039c on 8.0.x
    Issue #2508679 by tim.plunkett, Fabianx: Fix empty redirects and...
xjm’s picture

Status: Reviewed & tested by the community » Fixed

I didn't even realize that we could use multiple destinations like this! Also, nice test coverage.

This issue is a normal bug fix, and the impact outweighs any disruptive changes, so it is allowed per https://www.drupal.org/core/beta-changes. Thanks for adding the beta evaluation and explaining the potential disruption. Committed and pushed to 8.0.x.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.