Closed (fixed)
Project:
Drupal core
Version:
8.0.x-dev
Component:
base system
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
12 Nov 2015 at 13:58 UTC
Updated:
9 Dec 2015 at 13:14 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
webflo commentedComment #3
dawehnerOh wow.
Given that
is used I'm wondering whether we should validate whether something is an actual instance? It would not be able to call non static code at the moment, right?
Comment #4
webflo commentedYeah, actually my patch is wrong. We don't need the class name at all inside of drupalSettings. We should whitelist the properties we need in
machine-name.js.Comment #5
webflo commentedComment #7
webflo commentedComment #9
webflo commentedComment #10
webflo commentedComment #11
jibranI think we can backport this to D7 as well. Can we add some kind of tests for this? Patch itself doesn't touch JS but I think it'd great if JS maintainer can have a look at it so tagging.
Comment #12
webflo commentedComment #13
webflo commentedComment #15
dawehnerLet's drop those 2 lines then? I think its right to use the value object instead of a mock here.
Comment #16
webflo commentedComment #17
dawehnerThank you.
Comment #18
dawehner.
Comment #19
catchFix looks right.
While this changes what's in drupalSettings, it should be impossible for contrib or custom JavaScript to rely on that, so I think it's fine for 8.0.x.
Tagging performance due to the cache entry bloat.
Comment #21
webflo commentedComment #23
webflo commentedComment #24
webflo commentedBack to RTBC.
Comment #25
catchCommitted/pushed to 8.1.x and cherry-picked to 8.0.x, thanks!