Steps to reproduce:

  1. Create new role with permission 'administer site configuration'.
  2. Create an account and assign to it the newly created role.
  3. Login with that account and navigate to 'admin/config/system/site-information' page.
  4. Submit the form (leave front page field blank).

The following error message will appear:
The path '/user/login' is either invalid or you do not have access to it.

Comments

Chi created an issue. See original summary.

chi’s picture

Status: Active » Needs review
Issue tags: +Needs tests
StatusFileSize
new1.25 KB

Could not find any tests for this form.

chi’s picture

StatusFileSize
new1.25 KB

Small cleanup.

chi’s picture

StatusFileSize
new1.27 KB

another one

The last submitted patch, 2: test_only-2605592-1.patch, failed testing.

The last submitted patch, 3: test_only-2605592-2.patch, failed testing.

Status: Needs review » Needs work

The last submitted patch, 4: test_only-2605592-3.patch, failed testing.

chi’s picture

Status: Needs work » Active
swentel’s picture

Hmm, this probably happens for site_403 and site_404 as well

Anonymous’s picture

Status: Active » Needs review
StatusFileSize
new1.27 KB
new2 KB

This rather confusing validation message is the result of the default fallback to /user/login. By design, an authenticated user gets denied access to that page (see #2288911: Use route name instead of system path in user maintenance mode subscriber). We could work around the issue by changing the fallback to /user as demonstrated in this patch. However, this introduces a redirect for anonymous users on the homepage, so it might not be the best solution.

I also tested 403 and 404, and they seem to work as expected.

The last submitted patch, 10: cannot_submit_site-2605592-10-test-only.patch, failed testing.

Version: 8.0.x-dev » 8.1.x-dev

Drupal 8.0.6 was released on April 6 and is the final bugfix release for the Drupal 8.0.x series. Drupal 8.0.x will not receive any further development aside from security fixes. Drupal 8.1.0-rc1 is now available and sites should prepare to update to 8.1.0.

Bug reports should be targeted against the 8.1.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.2.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.1.x-dev » 8.2.x-dev

Drupal 8.1.9 was released on September 7 and is the final bugfix release for the Drupal 8.1.x series. Drupal 8.1.x will not receive any further development aside from security fixes. Drupal 8.2.0-rc1 is now available and sites should prepare to upgrade to 8.2.0.

Bug reports should be targeted against the 8.2.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.3.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.2.x-dev » 8.3.x-dev

Drupal 8.2.6 was released on February 1, 2017 and is the final full bugfix release for the Drupal 8.2.x series. Drupal 8.2.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.3.0 on April 5, 2017. (Drupal 8.3.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.3.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.4.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.3.x-dev » 8.4.x-dev

Drupal 8.3.6 was released on August 2, 2017 and is the final full bugfix release for the Drupal 8.3.x series. Drupal 8.3.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.4.0 on October 4, 2017. (Drupal 8.4.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.4.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.5.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.4.x-dev » 8.5.x-dev

Drupal 8.4.4 was released on January 3, 2018 and is the final full bugfix release for the Drupal 8.4.x series. Drupal 8.4.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.5.0 on March 7, 2018. (Drupal 8.5.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.5.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.6.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.5.x-dev » 8.6.x-dev

Drupal 8.5.6 was released on August 1, 2018 and is the final bugfix release for the Drupal 8.5.x series. Drupal 8.5.x will not receive any further development aside from security fixes. Sites should prepare to update to 8.6.0 on September 5, 2018. (Drupal 8.6.0-rc1 is available for testing.)

Bug reports should be targeted against the 8.6.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.7.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.6.x-dev » 8.8.x-dev

Drupal 8.6.x will not receive any further development aside from security fixes. Bug reports should be targeted against the 8.8.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.9.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 8.8.x-dev » 8.9.x-dev

Drupal 8.8.7 was released on June 3, 2020 and is the final full bugfix release for the Drupal 8.8.x series. Drupal 8.8.x will not receive any further development aside from security fixes. Sites should prepare to update to Drupal 8.9.0 or Drupal 9.0.0 for ongoing support.

Bug reports should be targeted against the 8.9.x-dev branch from now on, and new development or disruptive changes should be targeted against the 9.1.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

raman.b’s picture

Version: 8.9.x-dev » 9.2.x-dev
StatusFileSize
new2.07 KB
new2.65 KB

Re-rolling for the current dev branch

raman.b’s picture

Issue tags: -Needs tests
StatusFileSize
new1.33 KB
new2.07 KB
new882 bytes

The issue seems to exist in the current dev branch as well.

Re-uploading test only patch, resolving a few deprecations.

The last submitted patch, 21: 2605592-21-test-only.patch, failed testing. View results

ranjith_kumar_k_u’s picture

StatusFileSize
new415.72 KB
new378.04 KB

I have tested the last patch,it works fine .

Before Patch
before patch

After Patch
after patch

alexpott’s picture

Status: Needs review » Needs work
+++ b/core/modules/system/src/Form/SiteInformationForm.php
@@ -162,7 +162,7 @@ public function validateForm(array &$form, FormStateInterface $form_state) {
       // Set to default "user/login".
-      $form_state->setValueForElement($form['front_page']['site_frontpage'], '/user/login');
+      $form_state->setValueForElement($form['front_page']['site_frontpage'], '/user');

I don't understand why we're changing this when it is blank. If this is the fix then the comment // Set to default "user/login". needs updating.

I think we need to reassess this patch. How is this ever blank? Ah I see... $front_page = $site_config->get('page.front') != '/user/login' ? $this->aliasManager->getAliasByPath($site_config->get('page.front')) : ''; is odd code.

I think we should be using the getUrlIfValidWithoutAccessCheck() check and not check access on these links. It's not relevant.

raman.b’s picture

Status: Needs work » Needs review
StatusFileSize
new2.29 KB
new1.24 KB

Using getUrlIfValidWithoutAccessCheck() solves the reported issue

Should we open a follow up to better handle the default value?

raman.b’s picture

StatusFileSize
new3.36 KB
new1.53 KB

We'll also need to update the error message

Version: 9.2.x-dev » 9.3.x-dev

Drupal 9.2.0-alpha1 will be released the week of May 3, 2021, which means new developments and disruptive changes should now be targeted for the 9.3.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

longwave’s picture

Status: Needs review » Reviewed & tested by the community

Works for me, removes the strange error message.

longwave’s picture

Status: Reviewed & tested by the community » Needs work
Issue tags: +Needs reroll

Needs reroll for 9.3.x though.

dhirendra.mishra’s picture

Status: Needs work » Needs review
StatusFileSize
new3.36 KB

Re-rolled it.
Kindly review it.

longwave’s picture

Status: Needs review » Needs work
Issue tags: -Needs reroll
+++ b/core/modules/system/tests/src/Functional/System/FrontPageTest.php
@@ -72,7 +72,7 @@ public function testDrupalFrontPage() {
-    $this->assertSession()->pageTextContains("Either the path '" . $edit['site_frontpage'] . "' is invalid or you do not have access to it.");
+    $this->assertText("The path '" . $edit['site_frontpage'] . "' is invalid.");

We now need to use $this->assertSession()->pageTextContains() here.

ankithashetty’s picture

Status: Needs work » Needs review
StatusFileSize
new3.38 KB
new776 bytes

Fixed test failure errors as suggested in #31, thanks!

longwave’s picture

Status: Needs review » Reviewed & tested by the community

Thanks! RTBC if bot agrees.

alexpott’s picture

Status: Reviewed & tested by the community » Needs work

Let's not add a whole new test to maintain especially when we have \Drupal\Tests\system\Functional\System\FrontPageTest::testDrupalFrontPage already that uses this form and tests this logic already.

We could add to the bottom of \Drupal\Tests\system\Functional\System\FrontPageTest::testDrupalFrontPage - this test describes itself as

* Tests front page functionality and administration.


    // Ensure the user can revert the front page to the default of 'user/login'
    // even when they don't have access.
    $this->assertFalse(\Drupal::service('path.validator')->isValid('user/login'));
    $this->drupalGet('admin/config/system/site-information');
    $edit = ['site_frontpage' => ''];
    $this->submitForm($edit, 'Save configuration');
    $this->assertSession()->pageTextContains('The configuration options have been saved.');
    $this->drupalGet('');
    // We will we redirected to the user's account page.
    $this->assertSession()->addressEquals('user/2');
    $this->assertSession()->pageTextNotContains('On front page.');
    $this->drupalLogout();
    $this->assertSession()->addressEquals('user/login');
    $this->assertSession()->pageTextContains('On front page.');
vakulrai’s picture

Status: Needs work » Needs review
StatusFileSize
new2.22 KB
new3.96 KB

Hi , I have modified #32 as per #34 suggestions, adding the interdict and patch for the same.

Thanks!

longwave’s picture

Status: Needs review » Needs work

We need to explicitly set site_frontpage to an empty string for this test, we don't need to set the other settings here, and I think we should add a comment to explain the case we are testing.

vakulrai’s picture

Status: Needs work » Needs review
StatusFileSize
new963 bytes
new2.57 KB

Thanks @longwave for pointing out , I have modified the tests and added a description.

Please review.

Version: 9.3.x-dev » 9.4.x-dev

Drupal 9.3.0-rc1 was released on November 26, 2021, which means new developments and disruptive changes should now be targeted for the 9.4.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

joachim’s picture

Status: Needs review » Reviewed & tested by the community

LGTM.

alexpott’s picture

Status: Reviewed & tested by the community » Needs work
Issue tags: +Needs reroll

The patch does not apply to 9.4.x and hasn't for a few months.

ankithashetty’s picture

Status: Needs work » Needs review
Issue tags: -Needs reroll
StatusFileSize
new2.6 KB
new1.34 KB

Rerolled the patch, thanks!

Version: 9.4.x-dev » 9.5.x-dev

Drupal 9.4.0-alpha1 was released on May 6, 2022, which means new developments and disruptive changes should now be targeted for the 9.5.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.5.x-dev » 10.1.x-dev

Drupal 9.5.0-beta2 and Drupal 10.0.0-beta2 were released on September 29, 2022, which means new developments and disruptive changes should now be targeted for the 10.1.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

smustgrave’s picture

Status: Needs review » Reviewed & tested by the community
Issue tags: +Needs Review Queue Initiative

This issue is being reviewed by the kind folks in Slack, #needs-review-queue-initiative. We are working to keep the size of Needs Review queue [2700+ issues] to around 400 (1 month or less), following Review a patch or merge request as a guide.

Reroll looks good and issue is still addressed.

quietone’s picture

Status: Reviewed & tested by the community » Needs work
Issue tags: +Needs issue summary update

The issue summary is a statement of the problem. There is no indication of the proposed resolution.

I then went to apply the patch. I see that is against 9.4, which is in security support. The patch applied to 10.1.x so I tested it using the steps in the issue summary.

With the patch, it is now possible to save the basic sites settings page with an empty field for the default front page. I then looked at the system.site configuration.

$ ddev drush cget system.site
_core:
  default_config_hash: VDJxTZtQR21qB4lvOq8zszJZLvLKrSPQpdn2E3T71Ww
langcode: en
uuid: 76eacedf-7cf4-4707-86c7-c478fe9ef9f6
name: dev2-web
mail: v@example.com
slogan: ''
page:
  403: ''
  404: ''
  front: /user/login
admin_compact_mode: false
weight_select_max: 100
default_langcode: en

The front page path has not changed and we have the UI showing incorrect information. I then used the UI to change the the front page configuration to an empty string. I confirmed the change with drush front: ''. On navigating to the front page, I get a 404.

I don't know if that is the intended behavior. But having the UI and the stored configuration out of sync is wrong.

I am adding a tag for an issue summary update and setting back to needs work.

prem suthar’s picture

StatusFileSize
new2.59 KB

Re-Roll the Patch For 10.1 by #41.

smustgrave’s picture

#46 was unnecessary as patch 41 still applied to D10 hiding patch.

Also please include an interdiff with all patches

longwave’s picture

I forgot that I commented on this issue before. I propose simplifying this setting and making the field required over in #2671174: Make default front page setting required and remove special case of /user/login - this would mean this issue is no longer required.

Version: 10.1.x-dev » 11.x-dev

Drupal core is moving towards using a “main” branch. As an interim step, a new 11.x branch has been opened, as Drupal.org infrastructure cannot currently fully support a branch named main. New developments and disruptive changes should now be targeted for the 11.x branch, which currently accepts only minor-version allowed changes. For more information, see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

mstrelan’s picture

Status: Needs work » Closed (outdated)

As per #48 this is no longer required