Dear All, I'm working in a project for anonymous draft submissions based on an authcode by $_GET: https://www.drupal.org/project/webform_draft_authlink any feedback is welcome!

The webform module does not allow to alter the SID in hook_webform_draft_alter for anonymous users and I think it is a good feature to have.

Checking code this are the lines affected:

// Check if this user has a draft for this webform.
  $resume_draft = FALSE;
  if (($node->webform['allow_draft'] || $node->webform['auto_save']) && $user->uid != 0) {
    // Draft found - display form with draft data for further editing.
    if ($draft_sid = _webform_fetch_draft_sid($node->nid, $user->uid)) {
      ...
    }
  }

to Removing the $uid != 0 protection as this part of code only calls _webform_fetch_draft_sid where it will be handled

// Check if this user has a draft for this webform.
  $resume_draft = FALSE;
  if (($node->webform['allow_draft'] || $node->webform['auto_save'])) {
    ...
    }
  }

In the _webform_fetch_draft_sid only query database with uid != 0 but call the hook_webform_draft_alter in any case

Comments

GeduR created an issue. See original summary.

gedur’s picture

Attaching patch, please review!

gedur’s picture

Status: Active » Needs review
gedur’s picture

Issue summary: View changes
gedur’s picture

Issue summary: View changes
mingsong’s picture

It works.
Thanks.

msark’s picture

It works. Thank you

jaskaran.nagra’s picture

Instead of modifying the webform core module which many other projects are dependent on, May I suggest the following:

$draft_access = ($node->webform['allow_draft'] || $node->webform['auto_save']) && $user->uid != 0;
  drupal_alter('webform_draft_acess',$draft_access, $node, $user, $draft_sid);
  if ($draft_access) {
 // Draft found - display form with draft data for further editing.
    if ($draft_sid = _webform_fetch_draft_sid($node->nid, $user->uid)) 
...........................

Then in webform draft authlink module (or any other module for that matter) can alter the draft access just like:

function webform_draft_authlink_webform_draft_acess_alter(&$draft_access, $node, $user, $draft_sid){
  $draft_access = $node->webform['allow_draft'] || $node->webform['auto_save'];
}

And if no such module is installed, the core webform functionality remains unaltered :)

Kudos on the webform draft authlink module though :) Really helps me. I am writing a patch for compatibility with 7.3 version of webform :)

gedur’s picture

Hi! Not sure about your approach, I think you are creating a new drupal alter hook, doesn't it? Could you create a patch for this?

The previous patch #2 uses a hook that already exists and only let you modify SID even if the user that access is the anonymous user. If no other modules changes de SID there is no harm.

https://www.drupal.org/project/webform_draft_authlink checks an authlink query param to match a previous SID draft webform, simple and useful.

I think is a safe patch to apply and gives a lot of flexibility.

I've seen that there are people working in a SESSION solution for anonymous users which I don't like so much as other people could use your same browser and sometimes webforms is used to store critical data. I think it should be added as an additional feature not the default one, and with this patch it could be done also.

mattshoaf’s picture

Patch works for me, I like the idea of creating a hook from #8 for modules to use.

lcdservices’s picture

+1 to accept this patch. It doesn't change the standard behavior. It just allows module developers more flexibility with the alter hook.

chris matthews’s picture

The 3 year old patch in #2 to webform.module still applies cleanly to the latest 7.x-4.x-dev.

bulldozer2003’s picture

To provide the most usefulness for extending the module, the drupal_alter() call should go immediately before return $sid;. This would be outside of any if/else conditionals. Module developers should know what they're doing and tread carefully with using alter hooks.

anna deussing’s picture

Rerolled against latest 7.x-4.x-dev

tkcent’s picture

Due to changes required for SA-CONTRIB-2019-096, the patch in #2 no longer applies cleanly.

tondeuse’s picture

The workings of webform_draft_authlink is vital to one of my projects that is still live with the same custom codebase since 2016. This patch needs to keep working with the latest secure version of Webform. Here is my attempt at restoring the functionality for anonymous users without altering the experience for other logged in users.

andrewko’s picture

I was having a hard time getting any of these patches to work with the latest stable version of webform (7.x-4.23). So I manually applied the original patch from #2 and got it to work. Here's the reroll.

tondeuse’s picture

liam morland’s picture

Status: Needs review » Needs work

Thanks for the patch. The patch introduces some coding standards issues. Please fix.

liam morland’s picture

Status: Needs work » Closed (outdated)

Drupal 7 is no longer supported. If this applies to a supported version, please re-open.

Now that this issue is closed, please review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, please credit people who helped resolve this issue.