Problem

I'm getting this error when I'm trying to delete a user with its content.

An AJAX HTTP error occurred.
HTTP Result Code: 200
Debugging information follows.
Path: /batch?id=21&op=do_nojs&op=do
StatusText: OK
ResponseText:

Steps to reproduce the error:

  1. Create a new user.
  2. Create a node with the previous user.
  3. Lock the node with the previous user.
  4. Edit the previous node with another user (different to the node's owner)
  5. With an admin user delete the content owner user. Choosing the option to delete the user and its content
Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

schlaukopf created an issue. See original summary.

schlaukopf’s picture

Issue summary: View changes
schlaukopf’s picture

This is not a solution, this is a temporal fix, it will break the locks from the associated content of the user that is being deleted, but it affects the default behavior of the module that prevents content to be deleted when it has active locks.

fabiansierra5191’s picture

According to the previous "temporal fix" I think that is not the final code solution but if a user wants to delete a content that is locked and the user has the permission, it should be. Imagine that you want to delete and the user with its content and that user has 10 nodes (5 locked) and the admin wants to delete all of them, until now the admin have to unblock all of them one by one but with the following proposed patch that is basically as the comment above but validating permission, if the user wants to delete the blocked content and has the permission to unlock content, they can.

I attached two files one for the alpha version that has a small change in the drupal_set_message function with the word "alpha" in the file name and the other one for the latest version.

azussman’s picture

Based on the previous patch, I have adjusted it to work with the latest version 8.x-2.x

anairamzap made their first commit to this issue’s fork.

anairamzap’s picture

Status: Active » Needs review

Setting to needs review.

anairamzap’s picture

Version: 8.x-1.0-alpha8 » 8.x-2.x-dev

Sorry for the multiple edits, but forgot to update the base branch version to latest dev :S

astonvictor’s picture

Version: 8.x-2.x-dev » 3.x-dev

astonvictor changed the visibility of the branch 2957931-del-user-locked-content to hidden.

astonvictor changed the visibility of the branch 2957931-an-ajax-http to hidden.

astonvictor’s picture

I think it's ok to allow users to remove content with the break content lock permission because it's the same as doing it via the 'Unlock' action.
FYI EntityBreakLockForm::access() method has the check by the permission.

I guess It won't fix a case when a user has access to cancel another user and its content but doesn't have permission to break the lock.

It should be handled in another way. e.g. check if the user tries to remove it via UI or in the background.
for example, all ::load() methods don't have validations if the user can load entities.

astonvictor’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.