Our userbase has a high turnover, and the concept of re-usable media assets has proven difficult to cement. To avoid users inadvertently impacting other users' pages we want to remove the ability to edit existing assets inline.

This functionality, coupled with the patch in the related issue, would provide a useful barrier to accidental alteration of assets. (Users can still update and even remove the assets via other methods.)

This patch (inbound shortly) creates a new setting which controls the display of the edit button. The setting does not apply to newly created entities -- they can be edited inline up until the node is saved and the entity is created in the DB.

#3143422: Allow to hide the Edit button in Complex widget
#2833972: Widget setting to allow or disallow deleting entities from the system

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

Jimaginary created an issue. See original summary.

jrsouth’s picture

Patch based heavily on @jsbalsera's work in in issue #2833972

yasmeensalah’s picture

jrsouth’s picture

Thanks Yasmeen -- is that patch against beta1? (I haven't really been keeping an eye on this :) )

nkoporec’s picture

Status: Active » Needs review
StatusFileSize
new2.82 KB

Rerolled the patch because of warning when you apply the patch, also setting Needs review so other people can test it.

useernamee’s picture

Status: Needs review » Reviewed & tested by the community

Patch #5 applies nicely. I have quickly manually tested it and it works. Changing status to RTbC.

maico de jong’s picture

StatusFileSize
new2.58 KB

Rerolled pattch #5

andrtroe’s picture

StatusFileSize
new55.08 KB
new21.77 KB

Hello,
The #7 patch applied correctly and working as expected.
+1 for RTBC.
Tested on dev branch.
But it has conflicts with https://www.drupal.org/project/inline_entity_form/issues/2979075 so I applied all changes manually, but both patches work well together.
Also there are extra spaces in line
+ if (empty($entity_id) || ( $this->getSetting('allow_edit') && $entity->access('update') ) ) {
near brackets it should be removed.
Patch should be rerolled after https://www.drupal.org/project/inline_entity_form/issues/2979075 is commited.

andrtroe’s picture

Issue tags: +IEF Release 8.x-1.0
chris matthews’s picture

geek-merlin’s picture

#2974544: Convert tests from Simpletest to FunctionalJavascript is in now. I guess this should have a test.

geek-merlin’s picture

Issue tags: +Needs tests
geek-merlin’s picture

Status: Reviewed & tested by the community » Needs work

NW for tests.

xavier.masson’s picture

StatusFileSize
new2.46 KB
new2.58 KB

Reroll the patch

tonytheferg’s picture

Wonderful Idea! #14 applied in core 9.0.3

spokje’s picture

Assigned: Unassigned » spokje

Let's see if I can get up with some tests for this one.

spokje’s picture

Assigned: spokje » Unassigned

Meh, got an unexpected other assignment, going to have to postpone my work on this one.

clairemistry’s picture

I applied #14 to D9 and then extended it to include the restriction on deletion functionality again that was available in the original patch as we needed that functionality for our site

kopeboy’s picture

+1 for this on Drupal 10

kopeboy’s picture

Oh, now that I check, changing the permission to edit the entity already covers my requirement (with inline_entity_form 8.x-1.0-rc14 and Drupal 10)

jrsouth’s picture

Rerolled to apply against RC15, however that version seems to introduce a related control (removed_reference) which renders this patch partly redundant.

Needs unpicking, but this should keep anyone currently using this patch running for the time being.

dcam’s picture

I suggest closing this issue as a "won't fix." This is a permission issue, not a reason to add more bloat to the field widget's settings. As noted in #20, Drupal Core includes granular permissions which may be configured to only allow access to edit or delete a user's own Media entities. In my opinion, this would need an explanation of how the permissions are insufficient enough to justify additional burden on maintainers and frankly every site builder who has to set up the widget.

jrsouth’s picture

I disagree, this suggested change directly addresses a common requirement of sites with large (and changing) user bases.

No matter how good the training is, users make mistakes. This is exacerbated by a changing population of users, e.g. as staff leave and arrive at an organisation. As site builders/admins, if we can easily prevent a mistake from being made, we should, and this change enables us to do so.

The classic example is a user creating a page containing a media item customised to that page. They then later create a separate new page and re-use the media item, editing it inline to be more suitable for this new page, without realising that it's now unsuitable for the original page.

You could argue that this is simply user error, but the suggested change allows site maintainers to easily prevent this common mistake from being made, which directly improves the user experience.

And yes, the permissions around editing/deleting a user's own media items are insufficient, as demonstrated by the example above — the unintended consequences are due to editing the user's own media entity. (And we certainly don't want to prevent editing wholesale, because that's still needed.)

There would be no burden on site builders, since it defaults to the current behaviour, making it purely opt-in.

The burden on maintainers is very likely to be minimal given the essentially static nature of this patch for the last 5+ years.

dww’s picture

Version: 8.x-1.x-dev » 3.x-dev
Issue tags: -IEF Release 8.x-1.0

Yeah, I can see the benefit of allowing users to be able to edit their own entities (via other UI paths) but *not* to do so via IEF. I'm +1 to having these be widget settings. But for this to not be a maintenance burden, this feature *definitely* needs solid test coverage before it can be considered. Also, it should target the forthcoming 3.1.x series, since 3.0.0 is deep into RCs and IMHO it's too late to be adding new features there...

adr_p’s picture

Title: Add a setting to enable/disable inline editing of existing entities » Add a setting to enable/disable inline editing and deletion of existing entities
StatusFileSize
new7.2 KB

Rerolled against rc19 and:

  • Replaced empty($entity_id) calls (that don't work for entities with machine names) with $entity->isNew().
  • On the widget configuration form, dynamically hide "Keep or delete unreferenced..." if the "Allow users to delete existing..." checkbox is unchecked.
  • Don't display the "Keep or delete..." setting in the widget configuration summary if configured not to allow deleting existing entities.

rajab natshah made their first commit to this issue’s fork.

rajab natshah’s picture

rajab natshah’s picture

Title: Add a setting to enable/disable inline editing and deletion of existing entities » Add a setting to enable/disable inline editing existing entities

Deleting existing entities can be in a new issue.
like #2833972: Widget setting to allow or disallow deleting entities from the system

rajab natshah’s picture

Title: Add a setting to enable/disable inline editing existing entities » Add a setting to enable/disable inline editing for existing entities
rajab natshah’s picture

rajab natshah’s picture

Issue summary: View changes

rajab natshah changed the visibility of the branch 2913571-add-a-setting to hidden.

rajab natshah’s picture

Attached a static inline_entity_form--2024-12-27--2913571--mr-127.patch file, from the MR127 up to this point.
to be used with Composer Patches

loze made their first commit to this issue’s fork.

loze’s picture

Status: Needs work » Needs review
StatusFileSize
new7.05 KB

I tried this out but the new setting was not saving on the display form. I made a small change to the MR. Here is a patch for composer.

ahmad khader made their first commit to this issue’s fork.

ahmad khader’s picture

StatusFileSize
new7.34 KB

Added allow_edit to schema yml