Dear All, I'm working in a project for anonymous draft submissions based on an authcode by $_GET: https://www.drupal.org/project/webform_draft_authlink any feedback is welcome!
The webform module does not allow to alter the SID in hook_webform_draft_alter for anonymous users and I think it is a good feature to have.
Checking code this are the lines affected:
// Check if this user has a draft for this webform.
$resume_draft = FALSE;
if (($node->webform['allow_draft'] || $node->webform['auto_save']) && $user->uid != 0) {
// Draft found - display form with draft data for further editing.
if ($draft_sid = _webform_fetch_draft_sid($node->nid, $user->uid)) {
...
}
}
to Removing the $uid != 0 protection as this part of code only calls _webform_fetch_draft_sid where it will be handled
// Check if this user has a draft for this webform.
$resume_draft = FALSE;
if (($node->webform['allow_draft'] || $node->webform['auto_save'])) {
...
}
}
In the _webform_fetch_draft_sid only query database with uid != 0 but call the hook_webform_draft_alter in any case
Comments
Comment #2
gedur commentedAttaching patch, please review!
Comment #3
gedur commentedComment #4
gedur commentedComment #5
gedur commentedComment #6
mingsongIt works.
Thanks.
Comment #7
msark commentedIt works. Thank you
Comment #8
jaskaran.nagra commentedInstead of modifying the webform core module which many other projects are dependent on, May I suggest the following:
Then in webform draft authlink module (or any other module for that matter) can alter the draft access just like:
And if no such module is installed, the core webform functionality remains unaltered :)
Kudos on the webform draft authlink module though :) Really helps me. I am writing a patch for compatibility with 7.3 version of webform :)
Comment #9
gedur commentedHi! Not sure about your approach, I think you are creating a new drupal alter hook, doesn't it? Could you create a patch for this?
The previous patch #2 uses a hook that already exists and only let you modify SID even if the user that access is the anonymous user. If no other modules changes de SID there is no harm.
https://www.drupal.org/project/webform_draft_authlink checks an authlink query param to match a previous SID draft webform, simple and useful.
I think is a safe patch to apply and gives a lot of flexibility.
I've seen that there are people working in a SESSION solution for anonymous users which I don't like so much as other people could use your same browser and sometimes webforms is used to store critical data. I think it should be added as an additional feature not the default one, and with this patch it could be done also.
Comment #10
mattshoafPatch works for me, I like the idea of creating a hook from #8 for modules to use.
Comment #11
lcdservices commented+1 to accept this patch. It doesn't change the standard behavior. It just allows module developers more flexibility with the alter hook.
Comment #12
chris matthews commentedThe 3 year old patch in #2 to webform.module still applies cleanly to the latest 7.x-4.x-dev.
Comment #13
bulldozer2003To provide the most usefulness for extending the module, the drupal_alter() call should go immediately before
return $sid;. This would be outside of any if/else conditionals. Module developers should know what they're doing and tread carefully with using alter hooks.Comment #14
anna deussing commentedRerolled against latest 7.x-4.x-dev
Comment #17
tkcent commentedDue to changes required for SA-CONTRIB-2019-096, the patch in #2 no longer applies cleanly.
Comment #18
tondeuse commentedThe workings of webform_draft_authlink is vital to one of my projects that is still live with the same custom codebase since 2016. This patch needs to keep working with the latest secure version of Webform. Here is my attempt at restoring the functionality for anonymous users without altering the experience for other logged in users.
Comment #19
andrewko commentedI was having a hard time getting any of these patches to work with the latest stable version of webform (7.x-4.23). So I manually applied the original patch from #2 and got it to work. Here's the reroll.
Comment #20
tondeuse commentedPatch rerolled to apply to version 7.x-4.25.
Comment #21
liam morlandThanks for the patch. The patch introduces some coding standards issues. Please fix.
Comment #22
liam morlandDrupal 7 is no longer supported. If this applies to a supported version, please re-open.