Closed (fixed)
Project:
Drupal.org security advisory coverage applications
Component:
module
Priority:
Normal
Category:
Task
Assigned:
Issue tags:
Reporter:
Created:
26 Feb 2017 at 20:22 UTC
Updated:
19 May 2018 at 22:19 UTC
Jump to comment: Most recent
Comments
Comment #2
djalxs commentedI've reviewed and all code looks good however, I would change:
to
The reason being you have set a top level admin menu link and the local action tab doesn't fit with this.
Alternatively, you could create a second menu item and use
MENU_DEFAULT_LOCAL_ACTION.Comment #3
Drupal8 commentedThank you @djalxs I use both to better allow our users to navigate through custom menus. This seems confusing without our custom implementation so I have removed the MENU_LOCAL_TASK as you advised.
Comment #4
PA robot commentedWe are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)
Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #5
jeetendrakumar commentedComment #6
qzmenkoAutomated Review
No automated test cases were found, did you consider writing Simpletests or PHPUnit tests? This is not a requirement but encouraged for professional software development.Manual Review
file_type_loadFILE_TYPE_NONESQLSTATE[23000]: Integrity constraint violation: 1048 Column 'type' cannot be null. See monfis.module:384hook_uninstallfor removing variables and tables.t()for 'monfis : Sync'monfis_preprocess_tablemonfis_themeno need to declare an empty array.This review uses the Project Application Review Template.
Comment #7
Drupal8 commentedThank you for your time. I have review what you find:
1)file_type_load is a function from the file_entity module.(Required by Monfis)
2) Change the Constant to solve the issue 1,2,3
3) This error comes from the missing file_entity module. Also the Constant now will solve the issue as a second layer of protection.
4) This not required as for Drupal 7!
5) This is not necessary but i have include the t function.
6) this is not necessary but i would try to come up with a better way detected that the Monfis form has been triggered.
7) ok
8) I change the name
9) Not necessary.
Thank you again!
Comment #8
Drupal8 commentedComment #9
Drupal8 commentedComment #10
Drupal8 commentedComment #11
Drupal8 commentedComment #12
khurrami commentedHi,
I tried to install the module and found following errors
PHP Fatal error: Uncaught Error: Unsupported operand types in /includes/theme.inc:637\nStack trace:\n#0 /includes/theme.inc(689): _theme_process_registry(Array, 'monfis', 'module', 'monfis', 'sites/all/modul...')\n#1 /includes/theme.inc(325): _theme_build_registry(Object(stdClass), Array, 'phptemplate')\n#2 /includes/theme.inc(277): _theme_load_registry(Object(stdClass), Array, 'phptemplate')\n#3 /includes/theme.inc(411): theme_get_registry()\n#4 /includes/theme.inc(395): ThemeRegistry->initializeRegistry()\n#5 /includes/theme.inc(335): ThemeRegistry->__construct('theme_registry:...', 'cache')\n#6 /includes/theme.inc(277): _theme_load_regist in /includes/theme.inc on line 637, referer: /admin/modules
Comment #13
Drupal8 commented@khurrami. I have made a commit with a fix. You can tested with a git pull. To use it after the install run the cron ( to collect files and start showing their status)
Comment #14
Drupal8 commentedI understand the little time everyone have, but I hope someone can review this module.
Comment #15
manolios commentedAutomating tools found this https://pareview.sh/node/1230
Manual review:
I don't found anything wrong. With new drupal install 7.X worked fine.
Comment #16
mehul.shah commentedHi Drupal8,
Please change the url of config in your monfis.info file to
configure = admin/monfis
the current url -> admin/config/content/monfis does not exist in the monfis_menu.
Along with this comment, the status of the module remains "Needs work"
Comment #17
Drupal8 commentedHello mehul.shah, nice catch!
I have push a fix. Thank you again.
Comment #18
3ssom commentedHello Drupal8,
Automated Review
Looks good ,, no errors found :)
Manual Review
(+) Please see the README guidelines .. it looks good but you can do better there.- (*) In you hook_menu() .. I can see you are using a callback as your custom permission in hook_permission() monfis_access_callback then user_access to call it.. I know it will work just fine but its unnecessary code since you can just use array('administer monfis') using 'page arguments' it will look like this:
- (*) This is similar to the above note .. why not using the hook_menu() to call the drupal_get_form use this in the hook_menu()?:
- (*) In your .module file line:167 ,, I see you are using user_access('administer files') .. which is undefined? can you explain this?
- (+) In you .module line:365 .. please use t() in watchdog.
- (+) Not sure about this but in your hook_cron() it runs monfis_run() .. which is a db_insert() .. into your schema .. what if that for somehow fails? are you sure this will not ruin the site running your module? I don't see conditions which control that whether in cron schedule or in the query!
- (+) Move your hook_help() to the top of your code in .module
- (+) I'd put my css file in separate folder(e.g: css/monfis.css).
instead of this:
then remove the access callback ..
instead of this:
Then using the same thing in extra code?:
The starred items (*) are fairly big issues and warrant going back to Needs Work. Items marked with a plus sign (+) are important and should be addressed before a stable project release. The rest of the comments in the code walkthrough are recommendations.
If added, please don't remove the security tag, we keep that for statistics and to show examples of security problems.
This review uses the Project Application Review Template.
Comment #19
Drupal8 commentedHi 3ssom,
thank you for the time you gave to review this module. I have made a new commit to fixes the issues and recommendations you gave. I have some objections to the first two points. My thought was and still is to keep this two in a separate function to better control the way this can handle not only now but in the next commits that will be coming as soon, I have time to commit them. I like and i found correct to break the css to appropriate folder.
Also the user_access it was unnecessary as this was running in the original module for a customer and not for this public module. The point about the watchdog was giving and error in phpcs (The second argument to watchdog() should not be enclosed with t()). A workaround was implemented that solve this issue.
The disaster in the db_insert probably will not be affect anything as this work a stand alone and will not break anything in the site part. But I like what you write and I would try to make some check.
Thank you and I would like your opinions :)
Comment #20
3ssom commentedHello Drupal8,
I've pulled your fixes and I think this a RTBC :)
but I still have some points I'd like to mention here but they are NOT blockers:
I'm putting this as RTBC.
Thank you
Comment #21
Drupal8 commentedHi 3ssom,
The .vscode should have been ignored by .gitignore. I have pushed the gitignore file. Also I removed the LICENSE.txt.
My first approach was with
base_path()but this will return the url without the http[s]://[..] so this is why I stack with $GLOBALS['base_url'].The empty default case is there so in the next release must be populated. If this was just one case I could just make an if statement but in the next few commit this will start making more sense as more help comments will be added.
Thank you again for the time :)
Comment #22
avpadernoThank you for your contribution!
I am going to update your account so you can opt into security advisory coverage now.
These are some recommended readings to help with excellent maintainership:
You can find more contributors chatting on the IRC #drupal-contribute channel. So, come hang out and stay involved.
Thank you, also, for your patience with the review process.
Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.
I thank all the dedicated reviewers as well.
Comment #23
avpaderno