entity_browser 2.9 has JS issue with general user

Hi, we noticed that there are JS problem with entity_browser 2.9 (security upgrade) with general user account.

For user with administrator role, entity_browser works fine.

For user with other role, entity_browser has a JS problem. Entity browser went to blank after user select the target product.

Possible root cause

In developer console, saw this JS error for users without admin role

Uncaught ReferenceError: _ is not defined
    updateEntityIds http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.common.js?v=9.4.4:110
    selectionCompleted http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.common.js?v=9.4.4:60
    jQuery 7
    <anonymous> http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.modal_selection.js?v=9.4.4:15
    <anonymous> http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.modal_selection.js?v=9.4.4:22
entity_browser.common.js:110:5
    updateEntityIds http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.common.js?v=9.4.4:110
    selectionCompleted http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.common.js?v=9.4.4:60
    jQuery 7
    <anonymous> http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.modal_selection.js?v=9.4.4:15
    <anonymous> http://20.apigee-dev-portal.docksal/modules/contrib/entity_browser/js/entity_browser.modal_selection.js?v=9.4.4:22

In entity_browser.common.js:
// Ensure unique entities are selected.
combined_entities = _.unique(combined_entities);

We didn't change any role permission, plus, there are no role permission to control select product to apps.
please advice on how to fix this problem

User interface changes

no change

API changes

no change

Data model changes

no change

Release notes snippet

Comments

drupalgreenhorn created an issue. See original summary.

drupalgreenhorn’s picture

StatusFileSize
new317.41 KB
drupalgreenhorn’s picture

Issue summary: View changes
cilefen’s picture

Project: Drupal core » Entity Browser
Version: 9.4.x-dev » 8.x-2.x-dev
Component: other » Core API
Priority: Critical » Major
Issue summary: View changes
Issue tags: -entity_browser, -User Role

This is an entity browser issue, not Drupal Core.

drupalgreenhorn’s picture

cilefen

roll back from 2.8.0 to 2.6.0 fixed the issue.

composer require 'drupal/entity_browser:2.6.0'

Is entity_browser part of the core? it was automatic upgraded from 2.6 to 2.8 in the recent core security upgrade.

Where to report issue related with entity_browser ?

Holly

cilefen’s picture

Component: Core API » Widget selector plugins

Here, in the entity browser project. I’ve already moved this issue there.

drupalgreenhorn’s picture

Hi,
is this bug fixed?
I still need to stick to 2.6.0 to avoid this problem

keszthelyi’s picture

Hi,

I had very similar issues after updating the module from 2.6 to 2.8. I found that the issues are fixed if I make sure the browser loads the latest js files. I opened another issue that fixes caching of the module's asset files. Please check the patch from there if it fixes these issues.

drupalgreenhorn’s picture

keszthelyi

I tested the patch you referred, it didn't fix the issue

so at this moment, with
Drupal core 9.5.3
we still have same issue with
entity_browser 8.x-2.9 (security update)

we still have to use entity_browser 8.x-2.6 so general user can create a new app with Entity Browser

Did you upgraded to Drupal core 9.5.3 and entity_browser 8.x-2.9 sucessfully?

Thank you

drupalgreenhorn’s picture

Title: JS problem in entity_browser acts differently per user role » JS problem in entity_browser 2.9 acts differently per user role
Version: 8.x-2.x-dev » 8.x-2.9
drupalgreenhorn’s picture

StatusFileSize
new65.46 KB

Hi, I attached a screenshot, which showed:
after general user select the product, the entity browser went to blank, and the javacsript error in developer tool

drupalgreenhorn’s picture

StatusFileSize
new188.44 KB
drupalgreenhorn’s picture

Title: JS problem in entity_browser 2.9 acts differently per user role » entity_browser 2.9 has JS issue with general user
Issue summary: View changes
drupalgreenhorn’s picture

Issue summary: View changes
alok.tiwari’s picture

StatusFileSize
new322 bytes

Underscore was undefined in the entity browser's "common" library.
Added missing underscore core/dependency in the entity browser "common" library in the patch for V. 8.x-2.8 .

drupalgreenhorn’s picture

Alok, Thank you, your patch helped me resolved this issue

so these are all 4 patches I added for
Drupal core 9.5.3
Entity Browser 8.x-2.9
all these patches are needed, either for admin user or general user role

"drupal/entity_browser": {
"Entity browser relies on Node module to determine whether to use the admin theme": "https://www.drupal.org/files/issues/2019-06-24/eb-display-show-admin-the...",
"Avoid Duplicate references": "https://www.drupal.org/files/issues/2021-03-10/entity_browser-avoid_dupl...",
"js option undefined":"https://www.drupal.org/files/issues/2022-07-20/Javascript-error-option-u...",
"underscore-is-undefined error":"https://www.drupal.org/files/issues/2023-02-22/underscore-is-undefined-3..."
},

drupalgreenhorn’s picture

update

we recently upgraded from Drupal core 9.5.11 to Drupal core 10.1.6 and This issue still exists.
"drupal/entity_browser": "^2.9",
and
Drupal core 10.1.6

Seem like patch provided by Alok.
"underscore-is-undefined error":"https://www.drupal.org/files/issues/2023-02-22/underscore-is-undefined-3..."
works in Drupal environment, but not in D10.

After research on this issue, I found out with minor fixing, this patch will apply, but same problem still existed after apply this patch

So in original patch;
change

@@ -3,6 +3,7 @@ common:
to
@@ -3,6 +3,7 @@

this patch can be applied again through composer.
I save it as a local file, and composer applied it.

same problem still existed after apply this patch, same error with EB 2.9 in Drupal 10

drupalgreenhorn’s picture

It turned out that this issue showed up after D10 upgrade is because of
Underscore library is deprecated in D10. At the same time, underscore is still used in one of the js file in Entity browser 2.9.

I generated a patch for Entity browser 2.9 used in Drupal 10. It works with my project, hope it works for you too.

"drupal/entity_browser": "2.9"
Drupal Version: 10.1.6

Reference: https://www.drupal.org/node/3273118

anybody’s picture

Status: Active » Closed (outdated)