This module crawl the drupal org contribute module list page. After install module we can select those links from module list page (admin/modules/easy-installer) and install them by clicking install. Back end we are running bash script with drush dl.

Project page
https://www.drupal.org/sandbox/sajithathukorala/2580303

Git clone command
git clone --branch 7.x-1.x http://git.drupal.org/sandbox/SajithAthukorala/2580303.git easy_module_installer
cd easy_module_installer

Comments

SajithAthukorala created an issue. See original summary.

sajithathukorala’s picture

Issue summary: View changes
PA robot’s picture

We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)

Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).

I'm a robot and this is an automated message from Project Applications Scraper.

Anatolii88’s picture

Status: Needs review » Needs work

Hi @SajithAthukorala. Thank you for contribution. there are some minor issues on automated test service.

http://pareview.sh/pareview/httpgitdrupalorgsandboxsajithathukorala25803...

It should be easy to fix.

Manual Review

Individual user account
Yes: Follows the guidelines for individual user accounts.
No duplication
Yes: Does not cause module duplication and/or fragmentation.
Master Branch
Yes: Follows the guidelines for master branch.
Licensing
Yes: Follows the licensing requirements.
3rd party assets/code
Yes: Follows the guidelines for 3rd party assets/code.
README.txt/README.md
Yes: Follows the guidelines for in-project documentation and/or the README Template.
Code long/complex enough for review
Yes: Follows the guidelines for project length and complexity.
Secure code
Yes: Meets the security requirements.
Coding style & Drupal API usage

List of identified issues:
- Can you implement hook_help() for your module so it would be easy for the users to find help page for your module.
Also integrate your README.txt file in hook_help().
- It would be good to use hook_permission() too.
- There are some errors in .js file, those are not a reason to block the project application but it would be better to fix.
- Is there some configuration page to your module? admin/modules/easy-installer - this link doesn't work on my local site.

Thank you!

This review uses the Project Application Review Template.

rahulbaisanemca’s picture

Hi SajithAthukorala, Thanks for contribution to community, kindly add hook_help in this format.
https://www.drupal.org/node/161085

sajithathukorala’s picture

Status: Needs work » Needs review

Hi @anatolii88,
Thank you for reviewing module. I just updated the code with your issues
-Added hook_help and integrate README.txt with it.
-Added hook_permission with new permission.
-Solved all the js errors which showed by eslint on pareview.sh.
-There are no configuration page for this module, when you access "/admin/modules/easy-installer" page it will crawl the drupal.org contribute module page and display them on data tables. This process take 15-20 seconds for the first time.Can you please check with the cache

Thank You !!!

rakesh.gectcr’s picture

Manual Review:

@SajithAthukorala
Thanks for the module . Looks ok for me.

  • I would like to see configuration link, You can add the following in module.info file
    configure = /admin/modules/easy-installer
  • If you like to improve, you can improve the look and feel
sajithathukorala’s picture

@rahulbaisanemca - thank you for your reply

@rakesh.gectcr -

  • Actually this is "/admin/modules/easy-installer" not the configuration page as you can see , that's the main page to view contribute module list,You can see this menu item in Mainmenu-> Modules->Easy module installer. we normally add configuration page in .info file isn't it ?
  • Yehh I'm planing to improve design and more options in next versions :) .. like , Users can directly install and enable module with it's dependency modules (this is easy because we are using drush command from back-end) .

Thank you for your reply and ideas. really appreciate it.

prashant.c’s picture

@SajithAthukorala

Avoid using files from remote URLs:

drupal_add_js('https://code.jquery.com/jquery-1.11.3.min.js', 'external');
drupal_add_js('https://cdn.datatables.net/1.10.9/js/jquery.dataTables.min.js', 'external');
drupal_add_js('https://cdnjs.cloudflare.com/ajax/libs/pace/1.0.2/pace.js', 'external');
drupal_add_js('https://maxcdn.bootstrapcdn.com/bootstrap/3.3.5/js/bootstrap.min.js', 'external');
drupal_add_css('http://cdn.datatables.net/1.10.9/css/jquery.dataTables.min.css', 'external');

sajithathukorala’s picture

Hi @prashant.c

Thank you for reviewing module. I removed all the remote URLs . Now module requires jquery update module,and users have to add data table package and pace.js manually into module (more info added in README.txt).

Thank You.

mimran’s picture

Status: Needs review » Reviewed & tested by the community

Hi looks fine for me

sajithathukorala’s picture

Status: Reviewed & tested by the community » Needs review
sajithathukorala’s picture

Status: Needs review » Reviewed & tested by the community

Sorry My mistake , I have mistakenly update the issue , Revert back to previous state,

tessa bakker’s picture

Status: Reviewed & tested by the community » Needs work

Hi SajithAthukorala,

I can see why you developed this module, but after looking into your code this shouldn't be promoted to a project.

The reason for that is, that your module could be fun for prototyping a website, but has many security issues.

If you look at the Drupal core's Update Module, you can see that there is a special 'access callback' named 'update_manager_access' to check if someone can install a new module, also there are many more functions in Update to make sure nothing goes wrong while installing a new module.

Also many servers don't allow the function 'exec' because of many security risks. Using this with Drush (also not possible on many servers for user: www-data) this isn't the way to go.

To make this module work I would suggest the following:

Instead of downloading en installing a module in the most unsecure way, let the Update Module do this for you.

Find a way to send the modules Tar url to the Update form, let the user than decide to start the installation process and this could be a very handy module.

Also make use of the same 'access callback' as the Update Module for your pages.

sajithathukorala’s picture

Hi Tessa,
Thank you for reviewing my module and your suggestions, I really appreciate it, I will look into that solution and will update the code , Thanks again.

PA robot’s picture

Status: Needs work » Closed (won't fix)

Closing due to lack of activity. If you are still working on this application, you should fix all known problems and then set the status to "Needs review". (See also the project application workflow).

I'm a robot and this is an automated message from Project Applications Scraper.

klausi’s picture

Issue tags: +PAreview: security

Adding the security tag to indicate that a security issue was found here. And please don't remove the security tag, we keep that for statistics and to show examples of security problems.