Closed (fixed)
Project:
Drupal.org security advisory coverage applications
Component:
module
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
14 Nov 2015 at 09:35 UTC
Updated:
7 Jun 2016 at 19:44 UTC
Jump to comment: Most recent
Comments
Comment #2
PA robot commentedThere are some errors reported by automated review tools, did you already check them? See http://pareview.sh/pareview/httpgitdrupalorgsandboxshkiper2615378git
Fixed the git clone URL in the issue summary for non-maintainer users.
We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)
Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #3
PA robot commentedProject 1: https://www.drupal.org/node/2615442
Project 2: https://www.drupal.org/node/2615390
As successful completion of the project application process results in the applicant being granted the 'Create Full Projects' permission, there is no need to take multiple applications through the process. Once the first application has been successfully approved, then the applicant can promote other projects without review. Because of this, posting multiple applications is not necessary, and results in additional workload for reviewers ... which in turn results in longer wait times for everyone in the queue. With this in mind, your secondary applications have been marked as 'closed(duplicate)', with only one application left open (chosen at random).
If you prefer that we proceed through this review process with a different application than the one which was left open, then feel free to close the 'open' application as a duplicate, and re-open one of the project applications which had been closed.
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #4
shkiper commentedComment #5
legolasboAutomated Review
Review results:
Manual Review
The README.txt describes the main purpose of the module, but could do with more detailed installation/configuration instructions and a listing of the dependencies.
+Around line 175 a term is created like so:
In this case filter_xss is used too early. The term name should be filtered on output.
The starred items (*) are fairly big issues and warrant going back to Needs Work. Items marked with a plus sign (+) are important and should be addressed before a stable project release. The rest of the comments in the code walkthrough are recommendations.
If added, please don't remove the security tag, we keep that for statistics and to show examples of security problems.
This review uses the Project Application Review Template.
Comment #6
adam_ commentedI like this, it's easy and simplifies term creation. As a personal suggestion I would recommend adding an option for a confirmation or notification when new terms are being created to prevent misspellings of existing terms from being added, but it's great as is.
Individual account, check. Formatting and spacing looks good. Overall code quality is fine.
I don't see anything that should hold it up, marking as RTBC.
Comment #7
shkiper commentedComment #8
klausimanual review:
The filter_xss() usage is a blocker right now, you need to know when to use it and when not. Removing review bonus tag, you can add it again if you have done another 3 reviews of other projects.
Comment #9
shkiper commentedHi @klausi thank you for your review. I updated module description page and fixed bugs according to your comments.
Comment #10
shkiper commentedComment #11
harish b commentedHi shkiper ,
I downloaded the module, looks good. It will create automatic new term on creating new entity types.
1. Why to use auto-complete fields, when it create new term always?
2. It creates new term, What if taxonomy vocabulary have extra fields other then name and body?
I suggest to keep inline taxonomy term form same like inline entity form module works which will be more useful and user friendly.
Comment #12
harish b commentedComment #13
dman commentedIt does seem like there is a large amount of cross-over with inline_entity_form - it would be good to add a link to that and description of the differences on your project page to help people choose what suits them. EG, on (my) entityreference_autocreate page, I describe several other "modules in this space" to suggest what you should use if you want more or less functionality.
Given the other modules that do this - primarily the 'autocomplete/tags' UI itself - or the excellent "Chosen" widget
... I think the margin of utility left for this module is extremely narrow.
I would endorse investigating a few of these a little closer, and join forces with whatever almost meets your use case. Becoming a trusted co-maintainer of a worthwhile module is another (and good) path to full project management rights.
The code itself looks robust. Though I do get the feeling it's duplication functionality that already exists in places like taxonomy_autocomplete(). I do note that term_reference_autocreate_autocomplete() is a very different structure from what core does, so it's interesting. As best I can see visually, it's pretty good though, and shows good use of Drupal structure. It does feel a bit dense in the guts of _term_reference_autocreate_potential_references_standard() there, as what's actually going on in the code there (and more importantly, why) is non-obvious.
Comment #14
shkiper commentedHi @dman, thank you for your feedback. I updated description for my module and I hope that it will help users to choose proper solution for their needs.
Comment #15
klausiReview of the 7.x-1.x branch (commit e21144f):
This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.
Otherwise looks good to me. Since this was RTBC already and the only blocker I found is resolved and dman confirmed that it looks robust I think we can directly approve you.
Thanks for your contribution, shkiper!
I updated your account so you can promote this to a full project and also create new projects as either a sandbox or a "full" project.
Here are some recommended readings to help with excellent maintainership:
You can find lots more contributors chatting on IRC in #drupal-contribute. So, come hang out and stay involved!
Thanks, also, for your patience with the review process. Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.
Thanks to the dedicated reviewer(s) as well.