Problem/Motivation
The Drupal 8 version has a permission: bypass maxlength, however it is not implemented anywhere in the code. Users with this permission still cannot bypass maxlength limits.
Steps to reproduce
- Create a text field.
- Go to form display and set a maxlength in the widget settings for that field.
- Create the entity that the field is on so that you are on the form add/edit page.
- Whilst signed in as an administrator or a user with the
bypass maxlength permission, try and exceed the maxlength limit you have set.
This bug means you cannot exceed the maxlength limit you set, despite having the bypass maxlength permission.
Proposed resolution
The best solution is to fix this bug. Otherwise, the permission should be removed to avoid confusion.
I have attached a patch that stops the maxlength from being implemented if the user has the bypass permission.
Comments
Comment #2
cedeweyComment #3
cedeweyI tried applying the patch but got this error,
Hunk #1 FAILED at 267.
Comment #4
cedeweyComment #5
murilohp commentedI'm also unable to apply the patch, I was just able to reproduce the issue, so for this scenario I'm uploading a new patch, this new patch checks for the user permission at the "prerender" function. This solution solves the issue for me, I'm also used PHPCs inside the MaxLengthCallbacks.php and made some minor fixes just to keep the code consistent.
I added a new tag for tests, I think this is the kind of scenario that is basic and it's a good idea to cover it with functional tests, what do you think?
Moving the issue to "needs review" if you agree with the tests, you can rollback to "needs work", and if you have any questions, please let me know.
Thanks!
Comment #6
cedeweyHi Murilo,
Thanks so much for submitting a patch for this. It's the one major bug we have for the project.
I tested it and it's working well for the most part, but there are a few remaining issues.
For users with the Bypass maxlength setting the character count does not show. However, on summary and plain text fields the user is prevented from exceeding the maxelngth limit set, if the Force truncate option is set. For the body field, the user can bypass the limit as expected.
Comment #7
murilohp commentedHi! Thanks for the response! And good catch, I made a new patch adding a validation of maxlength, this validation fixed the scenario you pointed.
Some fields have a maxlength attribute when we create, for example, a plain text field has the maxlength attribute set to 255 by default, the patch will respect the elements that have this attribute, if you set the maxlength attribute to 255, the patch will respect that instead of the value used in the form_display. For the fields that don't have this attribute, the patch will set the maxlength to -1.
The code bellow was the main change in the patch:
I'm uploading the patch, an interdiff and moving to needs review again.
Thanks!
Comment #8
cedeweyYour changes did the trick. This is all working as expected. Thanks so much! This will get committed in the next release of the module.
Comment #10
cedewey