Steps to reproduce

  1. create an entity type that includes AJAX calls on the node edit form, e.g. node with a link field and a media field, or a field with multiple elements and "add another" links
  2. as a user without the 'link to any page' permission, try to create an instance of that entity
  3. enter an invalid path in the link field, e.g. 'foo'
  4. click on the button that initiates an AJAX request, e.g. file upload, add another

Expected result

An error message should appear about the invalid internal path, but you should be able to proceed with the action

Actual result

It isn't possible to proceed.
The AJAX call responds with a 500 error "The internal path component is invalid. Its path component must have a leading slash" with field widget type "Link".

↵An AJAX HTTP error occurred.↵HTTP Result Code: 500↵Debugging information follows.↵Path: /fr/node/6/edit?element_parents=field_test/widget/0&destination=/admin/content&ajax_form=1↵StatusText: 500 Service unavailable (with message)↵ResponseText: The website encountered an unexpected error. Please try again later.InvalidArgumentException: The internal path component 'test' is invalid. Its path component must have a leading slash, e.g. internal:/foo.

This error generates from \Drupal\Core\Url::fromInternalUri

It happens from \Drupal\link\Plugin\Field\FieldWidget\LinkWidget::formElement
in code
$item->getUrl()->access() (core/modules/link/src/Plugin/Field/FieldWidget/LinkWidget.php:175)

For avoidance of this error we have next element validator where check input values
\Drupal\link\Plugin\Field\FieldWidget\LinkWidget::validateUriElement

So we can't catch this error on common entity save operation.
But we can catch it with any additional ajax buttons, which skip validation with #limit_validation_errors

It appears on all browsers.

In my example "foo" value is incorrect for Link field. We can avoid this error by putting only correct values. But customer can be confused. He doesn't know what values are correct, and he doesn't know why all his AJAX buttons don't work. So we should avoid 500 error with ajax buttons.

I have investigated this issue and found, that we need to add additional check in \Drupal\link\Plugin\Field\FieldWidget\LinkWidget::formElement
I have prepared patch and I will apply it in comment.

Issue fork drupal-2943135

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

kalistos created an issue. See original summary.

kalistos’s picture

StatusFileSize
new5.85 KB
kalistos’s picture

Status: Active » Needs review

Status: Needs review » Needs work

The last submitted patch, 2: drupal-link_ajax_error-2943135-2.patch, failed testing. View results

andypost’s picture

Version: 8.4.x-dev » 8.6.x-dev
zahord’s picture

Hi, I was checking using 8.6.x and couldn't reproduce the issue using a link field and file field with ajax process

Version: 8.6.x-dev » 8.7.x-dev

Drupal 8.6.0-alpha1 will be released the week of July 16, 2018, which means new developments and disruptive changes should now be targeted against the 8.7.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

egruel’s picture

Hi, I couldn't reproduce the issue usin wiht the admin user but i have reproduce this issue with a not admin user, and the patch fix the problem.

mangesh.borukar’s picture

Above patch not working with Drupal 8.6.1, created a new patch to handle this issue.

mangesh.borukar’s picture

mangesh.borukar’s picture

mangesh.borukar’s picture

StatusFileSize
new5.83 KB
mangesh.borukar’s picture

mangesh.borukar’s picture

StatusFileSize
new5.83 KB
mangesh.borukar’s picture

malcomio’s picture

Issue summary: View changes
malcomio’s picture

As far as I can see from a quick test, the patch addresses the issue described, but it also seems to remove the URL validation - with the patch applied, I was able to create a link to a non-existent local path

malcomio’s picture

Issue summary: View changes
malcomio’s picture

I haven't been able to reproduce this issue on a clean 8.6.x install.

However, the issue does exist on our project (which is built from an install profile with numerous contrib and custom modules enabled).

Need to clarify the steps to reproduce.

malcomio’s picture

Issue summary: View changes
malcomio’s picture

In our project, granting the 'link to any page' permission to the relevant user roles seems to prevent this error from occurring, but the underlying error should still be addressed - a missing permission shouldn't cause a 500 error on an AJAX request.

malcomio’s picture

Issue summary: View changes

Version: 8.7.x-dev » 8.8.x-dev

Drupal 8.7.0-alpha1 will be released the week of March 11, 2019, which means new developments and disruptive changes should now be targeted against the 8.8.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.8.x-dev » 8.9.x-dev

Drupal 8.8.0-alpha1 will be released the week of October 14th, 2019, which means new developments and disruptive changes should now be targeted against the 8.9.x-dev branch. (Any changes to 8.9.x will also be committed to 9.0.x in preparation for Drupal 9’s release, but some changes like significant feature additions will be deferred to 9.1.x.). For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 8.9.x-dev » 9.1.x-dev

Drupal 8.9.0-beta1 was released on March 20, 2020. 8.9.x is the final, long-term support (LTS) minor release of Drupal 8, which means new developments and disruptive changes should now be targeted against the 9.1.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

Version: 9.1.x-dev » 9.2.x-dev

Drupal 9.1.0-alpha1 will be released the week of October 19, 2020, which means new developments and disruptive changes should now be targeted for the 9.2.x-dev branch. For more information see the Drupal 9 minor version schedule and the Allowed changes during the Drupal 9 release cycle.

Version: 9.2.x-dev » 9.3.x-dev

Drupal 9.2.0-alpha1 will be released the week of May 3, 2021, which means new developments and disruptive changes should now be targeted for the 9.3.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

siemen_hermans’s picture

StatusFileSize
new6.18 KB

Providing a patch for Drupal 9.2.x

dhirendra.mishra’s picture

Status: Needs work » Needs review
StatusFileSize
new6.18 KB

uploading against 9.3.x

Status: Needs review » Needs work

The last submitted patch, 29: 2943135-29.patch, failed testing. View results

bgreco’s picture

StatusFileSize
new7.19 KB

Modified the failing test so it passes with patch #29

bgreco’s picture

Status: Needs work » Needs review

Version: 9.3.x-dev » 9.4.x-dev

Drupal 9.3.0-rc1 was released on November 26, 2021, which means new developments and disruptive changes should now be targeted for the 9.4.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.4.x-dev » 9.5.x-dev

Drupal 9.4.0-alpha1 was released on May 6, 2022, which means new developments and disruptive changes should now be targeted for the 9.5.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

smustgrave’s picture

Status: Needs review » Postponed (maintainer needs more info)

Tested this without the patch following the issue summary steps

Created a user without the "Link to any page" permission
Added a link field to a content type with unlimited setting
Logged in as said user
Created a node by adding foo into the url
Clicking Add another did not generate a 500 but just highlight the url field as error.

If you're still seeing the issue can you provide an updated issue summary and testing steps about where you are seeing it please.

Version: 9.5.x-dev » 10.1.x-dev

Drupal 9.5.0-beta2 and Drupal 10.0.0-beta2 were released on September 29, 2022, which means new developments and disruptive changes should now be targeted for the 10.1.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

stefan.korn’s picture

Status: Postponed (maintainer needs more info) » Needs review
StatusFileSize
new1.48 KB

So, maybe this issue can not be triggered directly via Drupal core, but there are cases where the issue occurs (see related issues).

and absolutely agree with #21

... a missing permission shouldn't cause a 500 error on an AJAX request.

Proposing a patch that roughly does the same as the previous patches but only operates in the LinkWidget class. not sure why the LinkAccessConstraintValidator class was touched in the previous patches. Does not seem necessary to fix the problem given in this issue.

Status: Needs review » Needs work
stefan.korn’s picture

Status: Needs work » Needs review
StatusFileSize
new1.53 KB
stefan.korn’s picture

Status: Needs review » Needs work
stefan.korn’s picture

Status: Needs work » Needs review
StatusFileSize
new1.55 KB
Manoj Raj.R’s picture

smustgrave’s picture

Status: Needs review » Needs work
Issue tags: +Needs tests

Tried retesting and still not seeing the error.

Tagging for tests as we will need a scenario that shows this issue.

Version: 10.1.x-dev » 11.x-dev

Drupal core is moving towards using a “main” branch. As an interim step, a new 11.x branch has been opened, as Drupal.org infrastructure cannot currently fully support a branch named main. New developments and disruptive changes should now be targeted for the 11.x branch, which currently accepts only minor-version allowed changes. For more information, see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

nlisgo’s picture

Assigned: Unassigned » nlisgo

I'm going to attempt to add a test for this.

nlisgo’s picture

I'm trying to recreate the issue on 11.x and I have been unable to. Please can someone who can recreate it provide clearer instructions please.

andypost’s picture

Sometimes it's easier to create new MR from previous diff

nlisgo’s picture

Assigned: nlisgo » Unassigned
bwaindwain’s picture

I think this has been fixed in 10.2.1. See https://www.drupal.org/project/drupal/issues/3340154.

malcomio’s picture

byParlon changed the visibility of the branch 2943135-link-error-the to hidden.

byParlon changed the visibility of the branch 2943135-link-error-the to active.