Needs work
Project:
Drupal core
Version:
main
Component:
system.module
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
3 Jan 2020 at 08:07 UTC
Updated:
7 Jun 2025 at 12:19 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
hardik_patel_12 commentedKindly review a new patch
Comment #4
hardik_patel_12 commentedkindly follow a new patch.
Comment #6
kishor_kolekar commentedHi @Hardik_Patel_12 test cases are filed can u please look in to it ..
Thanks!
Comment #7
hardik_patel_12 commentedKindly review a new patch
Comment #8
Adev22 commentedI've applied the patch #7 and working on me
Comment #9
kishor_kolekar commentedAlso User logout and user forgot password page should not be set as Default 403 (access denied) page and Default 404 (not found), added new patch and interdiff file,Kindly review the patch.
Comment #10
kishor_kolekar commentedComment #11
kishor_kolekar commentedComment #13
kishor_kolekar commentedComment #14
kishor_kolekar commentedKindly review a new patch #14
Comment #15
kishor_kolekar commentedComment #17
hash6 commentedInstead of updating the value in the
buildForm()I would suggest to add it under thevalidate().Comment #18
longwaveWhy would anyone try to do this? This seems a bit of a pointless thing to protect against, there are many things an administrator can do to stop their Drupal site working properly and we don't stop them doing those either.
Comment #19
hash6 commentedSince I have already created a patch, will add it incase someone needs it.
Comment #20
hardik_patel_12 commentedIt's better to stop if admin try to do unusual thing like this case, and core has already applied condition for user login page so we can add extra condition for user registration and forgot password page also.
Comment #21
hardik_patel_12 commentedComment #22
avpadernoThere are many pages that should not be set as front page. Why should we worry about the user logout page, and the page to request a new password? The worst that can happen is that the user is logged-out, but that just make me think the logout page should ask confirmation to the user about logging out.
Comment #23
avpadernoInstead of handling two specific cases out of all the possible ones, I think that a generic way to mark a route as not suited for front page, 404, and 403 pages would be preferable. For example, a property in the route could tell Drupal not to use a route for those pages.
Comment #24
longwave#23 is a better idea if we have to do this at all. Also, any changes here will need tests.
Comment #25
avpadernoJust to make clear my previous comment, I am thinking of a property a form validation handler could use to accept a route.
Comment #33
mstrelan commentedAdded the issue template. Agree with #23 and #24, but don't really think it's worth the effort.
Comment #34
avpaderno